Skip to main content
Version: 2.3.1-preview

Test-MtAdTrustQuarantinedCount

SYNOPSIS​

Counts the number of trusts with strong SID filtering in Active Directory.

SYNTAX​

Test-MtAdTrustQuarantinedCount [-ProgressAction <ActionPreference>] [<CommonParameters>]

DESCRIPTION​

This test retrieves the count of external and forest trusts that have strong SID filtering. For external trusts, strength means the QUARANTINED_DOMAIN bit (0x4) is set. For forest trusts, strength means the TREAT_AS_EXTERNAL bit (0x40) is not set (SID history disabled). Intra-forest (parent-child) trusts are excluded because they do not support quarantine. MIT Kerberos realm trusts are also excluded as SID filtering does not apply to them.

Trust classification is derived from the trustAttributes LDAP attribute and trustType.

EXAMPLES​

EXAMPLE 1​

Test-MtAdTrustQuarantinedCount

Returns $true if trust data is accessible, $false otherwise. The test result includes the count of trusts with strong SID filtering.

PARAMETERS​

-ProgressAction​

Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.

Type: ActionPreference
Parameter Sets: (All)
Aliases: proga

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters​

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS​

OUTPUTS​

System.Boolean​

NOTES​

https://maester.dev/docs/commands/Test-MtAdTrustQuarantinedCount