Skip to main content
Version: 2.2.1-preview

AD-CFG-16 - Trusted root CA count should be retrievable

Overviewโ€‹

Trusted root CAs act as the trust anchors for an entire PKI trust chain. If an attacker (or a misconfiguration) introduces an unauthorized trusted root CA, they may be able to construct certificates that validate through the trust chain, enabling broad compromise of authentication, TLS validation, and signed trust decisions.

Security Recommendationโ€‹

  • Maintain an allowlist of trusted root CAs and require strong change control for trust additions/removals.
  • Restrict permissions on PKI trust anchor configuration to only PKI administrators.
  • After any change, verify certificate thumbprints/subjects, revocation publication, and distribution behavior.
  • Alert on unexpected changes in the number of trusted root CAs.

How the Test Worksโ€‹

  • Enumerates trusted root CA entries published in Active Directory (trust anchor objects).
  • Counts the number of trusted root CAs.
  • Compares the observed count to an environment baseline and flags unexpected increases/decreases.

Test Metadataโ€‹

FieldValue
Test IDAD-CFG-16
SeverityInfo
SuiteActive Directory
CategoryAD.Config
PowerShell testTest-MtAdTrustedRootCaCount
TagsAD, AD-CFG-16, AD.Config

Sourceโ€‹

  • Pester test: tests/ad/config/Test-MtAdTrustedRootCaCount.Tests.ps1
  • PowerShell source: powershell/public/ad/config/Test-MtAdTrustedRootCaCount.ps1