AD-DACL-01 - Distinct DACL object count should be retrievable
Overviewβ
Knowing how many distinct Active Directory objects are represented in the collected DACL dataset helps establish the scope of permission analysis.
- Measures DACL coverage across collected directory objects
- Provides a baseline for comparing later DACL metrics
- Helps validate collection breadth when reviewing AD permission visibility
Security Recommendationβ
Use this count as a baseline metric when reviewing DACL analysis. Unexpectedly low counts can indicate collection gaps, limited visibility, or an unexpectedly small review scope.
How the Test Worksβ
This test retrieves $adState.DaclEntries, extracts the ObjectDN value from each entry, deduplicates the object list, and reports the total number of unique objects with DACL entries.
Related Testsβ
Test-MtAdDaclOuObjectCountTest-MtAdDaclConflictObjectCountTest-MtAdDaclDenyAceCount
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DACL-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclDistinctObjectCount |
| Tags | AD, AD-DACL-01, AD.DACL |
Sourceβ
- Pester test:
tests/ad/dacl/Test-MtAdDaclDistinctObjectCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclDistinctObjectCount.ps1

