TECHNOLOGIES: IVANTI CONNECT SECURE

Ivanti Connect Secure Penetration Testing

Connect Secure’s admin roles, realms and resource policies decide who reaches your network. We test that configuration directly, from role mapping to Host Checker enforcement and the console. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Ivanti Connect Secure Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
REALM

An authentication realm is Connect Secure’s binding of an authentication server, a directory server, an authentication policy and role mapping rules into the one decision that grants a session its role.

Why Connect Secure risk concentrates on realms, roles and the console you can reach

An authentication realm ties together an authentication server, an optional directory server, an authentication policy and role mapping rules, and Ivanti’s own authentication realms documentation defines role mapping rules as conditions evaluated against username, user attribute, certificate attribute, group membership or a custom expression. We test how each realm is wired and which condition actually decides a user’s role, not what the deployment diagram assumed.

Connect Secure separates super administrators, who hold the .Administrators role and full control through the admin console, from read-only administrators and any number of custom system or security administrator roles scoped to specific realms, resource policies and pages. We test whether every admin account, including ones created for a single project, still holds only the access that role needs.

Host Checker runs its endpoint posture checks, predefined signatures alongside any custom rules you define, at either the role or the realm level before a session is granted access, and resource policies then decide what an authenticated session can actually reach. We confirm the Connect Secure release actually running against Ivanti’s current administration guidance during scoping, the same configuration-hygiene check we run on every appliance in this scope.

SCOPE

What we pen test on an Ivanti Connect Secure device

IV-01

Administrator Roles and Delegated Permissions

Connect Secure separates super administrators, who hold the .Administrators role and full control, from read-only administrators and any number of custom system or security administrator roles scoped to specific realms and resource policies. We test whether every admin account holds only the role its job actually needs.

IV-02

Authentication Realms and AAA Servers

An authentication realm ties an authentication server, an optional directory server and an authentication policy together, and Connect Secure supports local, LDAP, RADIUS, Active Directory, SAML and certificate-based AAA servers. We test how each realm is wired to its servers and whether the authentication policy in front of it matches what the realm is meant to protect.

IV-03

Role Mapping Rules

Role mapping rules decide which user role a session receives, evaluated against username, user attribute, certificate attribute, group membership or a custom expression drawn from the realm’s directory server. We test every rule’s conditions and evaluation order, since role mapping is what turns a verified identity into a set of resource permissions.

IV-04

Sign-In Policies for Users and Administrators

Connect Secure runs two separate types of sign-in policy, one for users and one for administrators, each binding a URL and a sign-in page to one or more realms, so an administrator URL such as */admin can sit alongside ordinary user URLs on the same device. We test which realms and pages every configured URL actually resolves to, including wildcard entries.

IV-05

Host Checker Endpoint Posture Policies

Host Checker is Connect Secure’s client-side agent, checking predefined signatures such as antivirus, antispyware, OS version and disk encryption status alongside any custom rules you define, and it can be invoked at either the role or the realm level. We test which roles and realms actually enforce a Host Checker policy and what happens to a session when a check fails.

IV-06

Resource Policies and Access Control

Web, file, Secure Application Manager, Terminal Services and VPN Tunneling resource policies each define which resources a role can reach, evaluated in order until the first match, and a fresh installation ships its initial web and file access policies in a Deny state by default. We test whether that default-deny posture has been preserved or loosened as policies were added.

IV-07

Admin Web Console vs Serial Port Console

Alongside the browser-based admin console, Connect Secure exposes a serial port console for initial setup and recovery, from which an administrator can create a new super administrator account, view access logs, or trigger a factory reset, and the console itself can be password-protected so that only super administrators can use it. We test whether that password protection is enabled and whether admin sign-in is restricted to the ports it needs.

IV-08

Delegated Administrator Restrictions

The system blocks delegated administrator roles from writing to pages that could let them change their own privileges, such as Import/Export, Push Config and Local Backups, reserving those to the built-in Administrators and Read-Only Administrators roles. We test every delegated role against that boundary to confirm no custom role has been granted access it should not have.

IV-09

Admin Access Session Logging

The Admin Access log records every administrator sign-in, sign-out, licence change and configuration change, separately from the User Access log, though the local viewer displays only the most recent 5,000 entries. We test whether Admin Access logging is enabled and forwarded to a syslog server before that local display limit rolls entries off.

IV-10

Supported Version and Advisory Risk

Ivanti publishes administration guides and security advisories against specific Connect Secure releases, and a device running outside that supported version range stops receiving the fixes those advisories assume are already applied. We confirm the release actually running against Ivanti’s current guidance during scoping, the same check we run on any other device in this scope.

OUR PROCESS

Ivanti Connect Secure Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree the realms, admin roles and resource policies in scope, plus admin accounts across every role type you use.

02

Configuration and Realm Mapping

We map every realm’s authentication and role mapping setup, resource policies, Host Checker enforcement and the ports admin sign-in is allowed on.

03

Manual Testing

A CREST-certified tester manually tests role boundaries, sign-in policies, resource policy enforcement and Host Checker behaviour by hand.

04

Attestation and Retest

You get a technical report with CVSS scores, a walkthrough call, a free retest, and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Ivanti Connect Secure pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Ivanti Connect Secure Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,460–£3,620
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£5,780–£8,810
4 to 6 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Ivanti Connect Secure Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Ivanti Connect Secure device?

We need admin accounts across the role types you use, including at least one with the .Administrators role, so we can compare what every account can actually do against what its role should allow. Read-only or delegated accounts are useful too, since testing role boundaries needs an account on each side of them.

How long does an Ivanti Connect Secure penetration test take?

A single appliance sits in our 2-day single-device scope, with a report typically landing around 5 working days after kickoff.

Does the test touch live user traffic, or could it disrupt remote access?

Configuration review, admin console testing and resource policy checks run without needing to intercept live VPN sessions. Where we do test authenticated user paths, such as Host Checker enforcement or role mapping, we agree test accounts and a testing window with you first so genuine remote-access users are not affected.

Do you test a high-availability cluster pair or just one appliance?

Our single-device scope covers one Connect Secure instance. Ivanti’s own clustering documentation recommends standalone nodes or a maximum of two-node clusters behind a load balancer, so where you run an active/active or active/passive cluster pair we scope both nodes, since configuration can drift between them.

What’s out of scope for an Ivanti Connect Secure engagement?

We do not run denial-of-service or resiliency testing against the appliance, and we do not test backend systems reachable only after Host Checker or role mapping grants access unless you add them to scope. Anything beyond the Connect Secure device itself, such as the identity provider behind an authentication realm, is scoped as a separate engagement.

Does Ivanti have a customer penetration-testing policy we need to follow?

Ivanti’s Vulnerability Disclosure Policy covers researchers reporting issues in Ivanti’s own products and infrastructure, and it explicitly excludes testing an Ivanti product hosted by a customer on the customer’s own network without prior approval, which is the deployment model most Connect Secure appliances use. We confirm current terms for your specific licence and deployment during scoping.

Can Host Checker and resource policy testing lock out real users?

We test Host Checker rules and resource policy behaviour using accounts and roles agreed with you in advance, rather than roles carrying live user sessions. Any change we make during testing is reverted, and we agree a rollback point with you before altering realm or role configuration.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Ivanti Connect Secure device

Connect Secure’s admin roles, realms and resource policies decide who reaches your network. We test that configuration directly, from role mapping to Host Checker enforcement and the console. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.