AD-CFG-12 - Enterprise CA count should be retrievable
Overviewβ
Enterprise Certification Authorities (CAs) issue certificates for domain authentication and other PKI-dependent services. An unauthorized or newly introduced Enterprise CA can issue valid certificates that authenticate users/computers, enabling impersonation, man-in-the-middle attacks, and potential privilege escalation.
Security Recommendationβ
- Maintain an allowlist of approved Enterprise CAs and treat CA additions as high-risk change events.
- Ensure only designated PKI administrators can create/modify CA objects.
- Validate CA certificate chains and revocation configuration after any CA change.
- Monitor and alert on deviations in the number of Enterprise CAs.
How the Test Worksβ
- Enumerates Enterprise CA objects in Active Directory (enrollment-capable CA configuration objects).
- Counts how many Enterprise CAs are configured.
- Compares the observed count against the environment baseline and flags unexpected values.
Related Testsβ
- Test-MtAdEnrollmentCaCertificateDetails: Reviews CA certificate validity periods and integrity.
- Test-MtAdCertificateTemplatesCount: Ensures template exposure isnβt expanded beyond approved policies.
- Test-MtAdTrustedRootCaCount: Verifies trusted PKI trust anchors.
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-CFG-12 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdEnterpriseCaCount |
| Tags | AD, AD-CFG-12, AD.Config |
Sourceβ
- Pester test:
tests/ad/config/Test-MtAdEnterpriseCaCount.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdEnterpriseCaCount.ps1

