AD-COMP-07 - Computer OU count should be retrievable
Overviewβ
The organizational structure of computer accounts reflects your Active Directory management maturity:
- Management efficiency: Well-structured OUs enable targeted Group Policy and administrative delegation
- Security boundaries: OUs can represent security zones with different policy requirements
- Operational clarity: Clear structure makes troubleshooting and auditing easier
- Compliance alignment: Many frameworks require logical organization of directory objects
A single flat structure (few OUs) or excessive fragmentation (many OUs with few computers) both indicate potential management challenges.
Security Recommendationβ
- Design an OU structure that supports:
- Geographic distribution (if applicable)
- Functional separation (workstations, servers, administrative tiers)
- Security policy boundaries
- Avoid placing computers directly in the domain root
- Ensure the structure supports your Group Policy design
- Regularly review and consolidate underutilized OUs
How the Test Worksβ
This test analyzes all enabled computer accounts and counts the distinct organizational units (containers) where computers are located. It provides insight into the breadth of your OU structure.
Related Testsβ
Test-MtAdComputerPerOUAverage- Calculates the average computers per OUTest-MtAdComputerInDefaultContainer- Identifies computers in the unmanaged default container
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-COMP-07 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Computer |
| PowerShell test | Test-MtAdComputerOUCount |
| Tags | AD, AD-COMP-07, AD.Computer |
Sourceβ
- Pester test:
tests/ad/computer/Test-MtAdComputerOUCount.Tests.ps1 - PowerShell source:
powershell/public/ad/computer/Test-MtAdComputerOUCount.ps1

