Skip to main content
Version: 2.2.1-preview

AD-COMP-04 - Computer non-standard primary group count should be retrievable

Overview​

Computer accounts should use standard primary group IDs. Non-standard primary groups may indicate:

  • Misconfiguration: Computers accidentally assigned to incorrect groups
  • Custom security configurations: Potential deviations from security baselines
  • Legacy issues: Remnants of previous domain configurations or migrations
  • Privilege escalation risks: Computers in inappropriate groups may have excessive permissions

The standard primary groups for computers are:

  • 515 - Domain Computers (standard workstations and member servers)
  • 516 - Domain Controllers (DC computer accounts)
  • 521 - Read-only Domain Controllers (RODC computer accounts)

Security Recommendation​

  • Review computers with non-standard primary groups to understand why they deviate
  • Ensure custom primary groups are intentional and properly documented
  • Verify that computers are not accidentally placed in groups that grant excessive privileges
  • Consider standardizing on the default groups unless there's a specific security requirement

How the Test Works​

This test examines the primaryGroupId attribute of all enabled computer accounts and identifies those where the value is not 515, 516, or 521.

  • Test-MtAdComputerSidHistoryCount - Identifies computers with migration artifacts
  • Test-MtAdComputerOUCount - Shows the distribution of computers across OUs

Test Metadata​

FieldValue
Test IDAD-COMP-04
SeverityInfo
SuiteActive Directory
CategoryAD.Computer
PowerShell testTest-MtAdComputerNonStandardGroup
TagsAD, AD-COMP-04, AD.Computer

Source​

  • Pester test: tests/ad/computer/Test-MtAdComputerNonStandardGroup.Tests.ps1
  • PowerShell source: powershell/public/ad/computer/Test-MtAdComputerNonStandardGroup.ps1