AD-CFG-08 - AuthN policy container count should be retrievable
Overviewβ
Authentication policies control how clients can authenticate to and interact with domain controllers for certain operations (depending on configuration and policy scope). Inadequate or unexpected authentication policy configuration can:
- Increase exposure of DC authentication endpoints
- Allow broader authentication patterns than intended
- Complicate incident investigations by enabling inconsistent authentication behavior
Because authentication to domain controllers is a critical trust boundary, this test focuses on ensuring policies are explicitly configured and managed.
Security Recommendationβ
- Ensure authentication policies are configured to restrict DC access to authorized systems and approved authentication behaviors.
- Use change control: treat authentication policy changes as security-critical.
- Validate that policy configuration aligns with your domainβs intended security baseline and any application/service requirements.
How the Test Worksβ
This test inspects AD authentication policy configuration and reports a count/visibility metric so administrators can confirm whether authentication policies are present and aligned with expectations.
Related Testsβ
Test-MtAdDsHeuristicsCount- Helps validate advanced directory behavior settings that can influence authentication-related behaviors.
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-CFG-08 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdAuthNPolicyConfigCount |
| Tags | AD, AD-CFG-08, AD.Config |
Sourceβ
- Pester test:
tests/ad/config/Test-MtAdAuthNPolicyConfigCount.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdAuthNPolicyConfigCount.ps1

