AD-CFG-02 - dSHeuristics count should be retrievable
Overviewβ
dSHeuristics is an AD configuration setting that controls behavior for advanced directory features and legacy compatibility. Because it influences protocol-level behavior (including areas such as LDAP security expectations and feature gating), an incorrect or unexpected dSHeuristics value can:
- Leave AD behaving in a more legacy/less secure mode
- Cause authentication and directory access inconsistencies across clients
- Increase the likelihood of unsafe fallback behaviors when clients interact with AD
Security Recommendationβ
- Confirm dSHeuristics is set according to your domainβs hardening baseline (and any guidance for your forest/domain functional level).
- Avoid βtrial-and-errorβ changes; instead, validate configuration changes in a controlled test window.
- Prioritize alignment with modern security requirements (including enforcing secure LDAP behavior where applicable).
How the Test Worksβ
This test queries AD configuration for the dSHeuristics setting(s) and reports a count-style metric indicating how many relevant dSHeuristics values are present/active so you can assess whether the environment matches your expected security baseline.
Related Testsβ
Test-MtAdLdapQueryPolicyCount- Helps ensure LDAP is protected by sane query limits.
Related linksβ
- Microsoft Learn: dSHeuristics attribute (MS-ADTS)
- ANSSI Active Directory checkpoints: Dangerous dsHeuristics settings
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-CFG-02 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdDsHeuristicsCount |
| Tags | AD, AD-CFG-02, AD.Config |
Sourceβ
- Pester test:
tests/ad/config/Test-MtAdDsHeuristicsCount.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdDsHeuristicsCount.ps1


