AD-DACL-04 - Conflict object details should be retrievable
Overviewโ
High-level counts are useful, but remediation usually requires object-level detail. This test helps administrators pinpoint each conflict object present in the DACL dataset and understand how many ACEs are attached to it.
- Shows the exact conflict objects found in DACL analysis
- Supports cleanup validation by exposing object class and DN
- Quantifies ACE volume on each conflict object
Security Recommendationโ
Review each listed conflict object, confirm why it exists, and determine whether it is still needed. If an object is obsolete, validate dependencies and permissions before cleanup.
How the Test Worksโ
This test retrieves $adState.DaclEntries, filters for entries whose ObjectDN contains CNF, groups them by object distinguished name, and returns each object with its class and ACE count.
Related Testsโ
Test-MtAdDaclConflictObjectCountTest-MtAdDaclDenyAceDetailsTest-MtAdDaclOuObjectCount
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DACL-04 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclConflictObjectDetails |
| Tags | AD, AD-DACL-04, AD.DACL |
Sourceโ
- Pester test:
tests/ad/dacl/Test-MtAdDaclConflictObjectDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclConflictObjectDetails.ps1

