Test-MtAdTrustNonQuarantinedDetails
SYNOPSIS
Lists details of trusts with weak SID filtering in Active Directory.
SYNTAX
Test-MtAdTrustNonQuarantinedDetails [-ProgressAction <ActionPreference>] [<CommonParameters>]
DESCRIPTION
This test retrieves detailed information about external and forest trusts that have weak SID filtering. For external trusts, weakness means the QUARANTINED_DOMAIN bit (0x4) is not set. For forest trusts, weakness means the TREAT_AS_EXTERNAL bit (0x40) is set (SID history enabled). Intra-forest (parent-child) trusts are excluded because they do not support quarantine. MIT Kerberos realm trusts are also excluded as SID filtering does not apply to them.
Trust classification is derived from the trustAttributes LDAP attribute and trustType.
EXAMPLES
EXAMPLE 1
Test-MtAdTrustNonQuarantinedDetails
Returns $true if all evaluated trusts have strong SID filtering, $false if any are weak. The test result includes details of trusts with weak SID filtering.
PARAMETERS
-ProgressAction
Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.
Type: ActionPreference
Parameter Sets: (All)
Aliases: proga
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
INPUTS
OUTPUTS
System.Boolean
NOTES
RELATED LINKS
https://maester.dev/docs/commands/Test-MtAdTrustNonQuarantinedDetails