Skip to main content
Version: 2.2.1-preview

AD-CFG-07 - Default query policy should be retrievable

Overview​

The default query policy sets baseline resource constraints for LDAP operations. If defaults are overly permissive, AD can be more vulnerable to availability attacks and performance degradation from:

  • Large/inefficient LDAP searches
  • High-frequency query patterns
  • Legitimate admin/service queries running with insufficient guardrails

Proper limits reduce the impact of both misuse and mistakes, improving DC resilience during incidents.

Security Recommendation​

  • Review the default query policy and ensure it matches your organization’s acceptable performance envelope.
  • Keep defaults conservative, then selectively allow exceptions only where required.
  • Re-validate defaults after upgrades, migrations, or schema/config changes.

How the Test Works​

This test retrieves the default LDAP query policy values and reports them as an analyzable metric so administrators can confirm baseline limits are configured as intended.

  • Test-MtAdLdapQueryPolicyCount - Ensures query policy coverage/consistency across partitions.

Test Metadata​

FieldValue
Test IDAD-CFG-07
SeverityInfo
SuiteActive Directory
CategoryAD.Config
PowerShell testTest-MtAdDefaultQueryPolicy
TagsAD, AD-CFG-07, AD.Config

Source​

  • Pester test: tests/ad/config/Test-MtAdDefaultQueryPolicy.Tests.ps1
  • PowerShell source: powershell/public/ad/config/Test-MtAdDefaultQueryPolicy.ps1