AD-COMP-05 - Computer SID History count should be retrievable
Overviewโ
SID History is an attribute used during domain migrations to maintain access to resources in the source domain. While necessary during migrations, persistent SID History on computer accounts can indicate:
- Incomplete migrations: Computers that were migrated but never fully transitioned
- Security risks: SIDs from untrusted or less-secure domains may grant unintended access
- Directory bloat: Unnecessary data in the directory that complicates troubleshooting
- Audit complexity: Makes it harder to determine effective permissions
Security Recommendationโ
- Review computers with SID History to determine if the migration is complete
- Remove SID History attributes once systems are fully migrated and resource access is verified
- Be cautious of SID History containing SIDs from external or untrusted domains
- Document any computers that legitimately require long-term SID History
How the Test Worksโ
This test counts computer objects where the SIDHistory attribute is populated. This attribute typically contains one or more SIDs from the computer's previous domain(s).
Related Testsโ
Test-MtAdComputerNonStandardGroup- Identifies other migration or configuration anomaliesTest-MtAdComputerDormantCount- Finds stale accounts that may be migration remnants
Related linksโ
- Microsoft Defender for Identity: Unsecure SID History attributes
- ANSSI Active Directory checkpoints: Accounts or groups with SID history set
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-COMP-05 |
| Severity | Medium |
| Suite | Active Directory |
| Category | AD.Computer |
| PowerShell test | Test-MtAdComputerSidHistoryCount |
| Tags | AD, AD-COMP-05, AD.Computer |
Sourceโ
- Pester test:
tests/ad/computer/Test-MtAdComputerSidHistoryCount.Tests.ps1 - PowerShell source:
powershell/public/ad/computer/Test-MtAdComputerSidHistoryCount.ps1


