Skip to main content
Version: 2.2.1-preview

AD-DACL-01 - Distinct DACL object count should be retrievable

Overview​

Knowing how many distinct Active Directory objects are represented in the collected DACL dataset helps establish the scope of permission analysis.

  • Measures DACL coverage across collected directory objects
  • Provides a baseline for comparing later DACL metrics
  • Helps validate collection breadth when reviewing AD permission visibility

Security Recommendation​

Use this count as a baseline metric when reviewing DACL analysis. Unexpectedly low counts can indicate collection gaps, limited visibility, or an unexpectedly small review scope.

How the Test Works​

This test retrieves $adState.DaclEntries, extracts the ObjectDN value from each entry, deduplicates the object list, and reports the total number of unique objects with DACL entries.

  • Test-MtAdDaclOuObjectCount
  • Test-MtAdDaclConflictObjectCount
  • Test-MtAdDaclDenyAceCount

Test Metadata​

FieldValue
Test IDAD-DACL-01
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclDistinctObjectCount
TagsAD, AD-DACL-01, AD.DACL

Source​

  • Pester test: tests/ad/dacl/Test-MtAdDaclDistinctObjectCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclDistinctObjectCount.ps1