Skip to main content
Version: 2.2.1-preview

AD-DACL-03 - Conflict object count should be retrievable

Overview​

Conflict objects with CNF markers typically originate from replication or naming conflicts. Even when old, they can indicate historical AD hygiene issues and should be understood before being ignored.

  • Surfaces replication-conflict remnants in DACL analysis
  • Helps identify cleanup candidates
  • Provides context for unexpected objects appearing in permission reviews

Security Recommendation​

Investigate conflict objects and confirm whether they are expected remnants, still referenced, or safe to clean up. Review their permissions before remediation to understand any delegated access that may still exist.

How the Test Works​

This test retrieves $adState.DaclEntries, searches for CNF within ObjectDN, deduplicates matching distinguished names, and reports the number of unique conflict objects and associated DACL entries.

  • Test-MtAdDaclConflictObjectDetails
  • Test-MtAdDaclDistinctObjectCount
  • Test-MtAdDaclDenyAceDetails

Test Metadata​

FieldValue
Test IDAD-DACL-03
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclConflictObjectCount
TagsAD, AD-DACL-03, AD.DACL

Source​

  • Pester test: tests/ad/dacl/Test-MtAdDaclConflictObjectCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclConflictObjectCount.ps1