Skip to main content
Version: 2.1.1-preview

Test-MtAdGroupAdminCount

SYNOPSIS

Counts groups with AdminCount set in Active Directory.

SYNTAX

Test-MtAdGroupAdminCount [-ProgressAction <ActionPreference>] [<CommonParameters>]

DESCRIPTION

This test identifies groups that have the AdminCount attribute set to a non-null or non-zero value. The AdminCount attribute is automatically set by Active Directory on privileged accounts and groups that are members of protected groups (like Domain Admins, Enterprise Admins, etc.). Groups with AdminCount set receive special security protections to prevent delegation of administrative privileges.

EXAMPLES

EXAMPLE 1

Test-MtAdGroupAdminCount

Returns $true if group data is accessible, $false otherwise. The test result includes the count of groups with AdminCount set.

PARAMETERS

-ProgressAction

Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.

Type: ActionPreference
Parameter Sets: (All)
Aliases: proga

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

OUTPUTS

System.Boolean

NOTES

https://maester.dev/docs/commands/Test-MtAdGroupAdminCount