Skip to main content
Version: 2.2.1-preview

AD-DACL-04 - Conflict object details should be retrievable

Overviewโ€‹

High-level counts are useful, but remediation usually requires object-level detail. This test helps administrators pinpoint each conflict object present in the DACL dataset and understand how many ACEs are attached to it.

  • Shows the exact conflict objects found in DACL analysis
  • Supports cleanup validation by exposing object class and DN
  • Quantifies ACE volume on each conflict object

Security Recommendationโ€‹

Review each listed conflict object, confirm why it exists, and determine whether it is still needed. If an object is obsolete, validate dependencies and permissions before cleanup.

How the Test Worksโ€‹

This test retrieves $adState.DaclEntries, filters for entries whose ObjectDN contains CNF, groups them by object distinguished name, and returns each object with its class and ACE count.

  • Test-MtAdDaclConflictObjectCount
  • Test-MtAdDaclDenyAceDetails
  • Test-MtAdDaclOuObjectCount

Test Metadataโ€‹

FieldValue
Test IDAD-DACL-04
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclConflictObjectDetails
TagsAD, AD-DACL-04, AD.DACL

Sourceโ€‹

  • Pester test: tests/ad/dacl/Test-MtAdDaclConflictObjectDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclConflictObjectDetails.ps1