Skip to main content
Version: 2.3.1-preview

Test-MtAdTrustNonQuarantinedDetails

SYNOPSIS​

Lists details of trusts with weak SID filtering in Active Directory.

SYNTAX​

Test-MtAdTrustNonQuarantinedDetails [-ProgressAction <ActionPreference>] [<CommonParameters>]

DESCRIPTION​

This test retrieves detailed information about external and forest trusts that have weak SID filtering. For external trusts, weakness means the QUARANTINED_DOMAIN bit (0x4) is not set. For forest trusts, weakness means the TREAT_AS_EXTERNAL bit (0x40) is set (SID history enabled). Intra-forest (parent-child) trusts are excluded because they do not support quarantine. MIT Kerberos realm trusts are also excluded as SID filtering does not apply to them.

Trust classification is derived from the trustAttributes LDAP attribute and trustType.

EXAMPLES​

EXAMPLE 1​

Test-MtAdTrustNonQuarantinedDetails

Returns $true if all evaluated trusts have strong SID filtering, $false if any are weak. The test result includes details of trusts with weak SID filtering.

PARAMETERS​

-ProgressAction​

Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.

Type: ActionPreference
Parameter Sets: (All)
Aliases: proga

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters​

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS​

OUTPUTS​

System.Boolean​

NOTES​

https://maester.dev/docs/commands/Test-MtAdTrustNonQuarantinedDetails