AD-DACL-03 - Conflict object count should be retrievable
Overviewβ
Conflict objects with CNF markers typically originate from replication or naming conflicts. Even when old, they can indicate historical AD hygiene issues and should be understood before being ignored.
- Surfaces replication-conflict remnants in DACL analysis
- Helps identify cleanup candidates
- Provides context for unexpected objects appearing in permission reviews
Security Recommendationβ
Investigate conflict objects and confirm whether they are expected remnants, still referenced, or safe to clean up. Review their permissions before remediation to understand any delegated access that may still exist.
How the Test Worksβ
This test retrieves $adState.DaclEntries, searches for CNF within ObjectDN, deduplicates matching distinguished names, and reports the number of unique conflict objects and associated DACL entries.
Related Testsβ
Test-MtAdDaclConflictObjectDetailsTest-MtAdDaclDistinctObjectCountTest-MtAdDaclDenyAceDetails
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DACL-03 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclConflictObjectCount |
| Tags | AD, AD-DACL-03, AD.DACL |
Sourceβ
- Pester test:
tests/ad/dacl/Test-MtAdDaclConflictObjectCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclConflictObjectCount.ps1

