AD-CFG-09 - AD activation objects count should be retrievable
Overviewβ
AD-based activation objects are used by Windows for volume activation and related discovery workflows. If these objects are created, deleted, or altered without authorization, it can indicate licensing/tampering activity and may also reflect broader Active Directory compromise or unauthorized configuration changes.
Security Recommendationβ
- Treat activation-object changes as security-relevant change-management events.
- Restrict who can create/modify activation objects (least privilege) and remove unnecessary write permissions.
- Establish a known-good baseline for the number of activation objects per environment/forest and alert on deviations.
- Review recent directory change/audit events to identify the initiating account and purpose.
How the Test Worksβ
- Enumerates activation-related objects stored in Active Directory.
- Counts the objects discovered in the activation container(s).
- Compares the count to an environment baseline and flags unexpected increases/decreases.
Related Testsβ
- Test-MtAdWellKnownSecurityPrincipalsCount: Detects unexpected identity/config changes that may accompany tampering.
- Test-MtAdRegisteredDhcpServersCount: Detects unauthorized network services registered in AD.
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-CFG-09 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdAdActivationObjectsCount |
| Tags | AD, AD-CFG-09, AD.Config |
Sourceβ
- Pester test:
tests/ad/config/Test-MtAdAdActivationObjectsCount.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdAdActivationObjectsCount.ps1

