Skip to main content
Version: 2.2.1-preview

AD-CFG-09 - AD activation objects count should be retrievable

Overview​

AD-based activation objects are used by Windows for volume activation and related discovery workflows. If these objects are created, deleted, or altered without authorization, it can indicate licensing/tampering activity and may also reflect broader Active Directory compromise or unauthorized configuration changes.

Security Recommendation​

  • Treat activation-object changes as security-relevant change-management events.
  • Restrict who can create/modify activation objects (least privilege) and remove unnecessary write permissions.
  • Establish a known-good baseline for the number of activation objects per environment/forest and alert on deviations.
  • Review recent directory change/audit events to identify the initiating account and purpose.

How the Test Works​

  • Enumerates activation-related objects stored in Active Directory.
  • Counts the objects discovered in the activation container(s).
  • Compares the count to an environment baseline and flags unexpected increases/decreases.

Test Metadata​

FieldValue
Test IDAD-CFG-09
SeverityInfo
SuiteActive Directory
CategoryAD.Config
PowerShell testTest-MtAdAdActivationObjectsCount
TagsAD, AD-CFG-09, AD.Config

Source​

  • Pester test: tests/ad/config/Test-MtAdAdActivationObjectsCount.Tests.ps1
  • PowerShell source: powershell/public/ad/config/Test-MtAdAdActivationObjectsCount.ps1