AD-CFG-16 - Trusted root CA count should be retrievable
Overviewโ
Trusted root CAs act as the trust anchors for an entire PKI trust chain. If an attacker (or a misconfiguration) introduces an unauthorized trusted root CA, they may be able to construct certificates that validate through the trust chain, enabling broad compromise of authentication, TLS validation, and signed trust decisions.
Security Recommendationโ
- Maintain an allowlist of trusted root CAs and require strong change control for trust additions/removals.
- Restrict permissions on PKI trust anchor configuration to only PKI administrators.
- After any change, verify certificate thumbprints/subjects, revocation publication, and distribution behavior.
- Alert on unexpected changes in the number of trusted root CAs.
How the Test Worksโ
- Enumerates trusted root CA entries published in Active Directory (trust anchor objects).
- Counts the number of trusted root CAs.
- Compares the observed count to an environment baseline and flags unexpected increases/decreases.
Related Testsโ
- Test-MtAdEnrollmentCaCertificateDetails: Validates CA certificate validity and identity details.
- Test-MtAdEnterpriseCaCount: Confirms which CAs are configured for enrollment across the environment.
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-CFG-16 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdTrustedRootCaCount |
| Tags | AD, AD-CFG-16, AD.Config |
Sourceโ
- Pester test:
tests/ad/config/Test-MtAdTrustedRootCaCount.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdTrustedRootCaCount.ps1

