AD-COMP-04 - Computer non-standard primary group count should be retrievable
Overviewβ
Computer accounts should use standard primary group IDs. Non-standard primary groups may indicate:
- Misconfiguration: Computers accidentally assigned to incorrect groups
- Custom security configurations: Potential deviations from security baselines
- Legacy issues: Remnants of previous domain configurations or migrations
- Privilege escalation risks: Computers in inappropriate groups may have excessive permissions
The standard primary groups for computers are:
- 515 - Domain Computers (standard workstations and member servers)
- 516 - Domain Controllers (DC computer accounts)
- 521 - Read-only Domain Controllers (RODC computer accounts)
Security Recommendationβ
- Review computers with non-standard primary groups to understand why they deviate
- Ensure custom primary groups are intentional and properly documented
- Verify that computers are not accidentally placed in groups that grant excessive privileges
- Consider standardizing on the default groups unless there's a specific security requirement
How the Test Worksβ
This test examines the primaryGroupId attribute of all enabled computer accounts and identifies those where the value is not 515, 516, or 521.
Related Testsβ
Test-MtAdComputerSidHistoryCount- Identifies computers with migration artifactsTest-MtAdComputerOUCount- Shows the distribution of computers across OUs
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-COMP-04 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Computer |
| PowerShell test | Test-MtAdComputerNonStandardGroup |
| Tags | AD, AD-COMP-04, AD.Computer |
Sourceβ
- Pester test:
tests/ad/computer/Test-MtAdComputerNonStandardGroup.Tests.ps1 - PowerShell source:
powershell/public/ad/computer/Test-MtAdComputerNonStandardGroup.ps1

