AD-DACL-05 - Deny ACE count should be retrievable
Overviewโ
Deny ACEs are powerful because they can override allow permissions and create access outcomes that are difficult to troubleshoot. Counting them provides a quick baseline for how much explicit denial logic exists in the collected AD permission set.
- Highlights explicit deny usage in AD DACLs
- Supports troubleshooting for delegation and access issues
- Helps prioritize deeper review when deny ACE volume is high
Security Recommendationโ
Review deny ACE usage carefully. Ensure each deny entry is intentional, documented, and still required. Excessive or poorly understood deny entries can create administrative confusion and mask broader permission issues.
How the Test Worksโ
This test retrieves $adState.DaclEntries, filters entries where AccessControlType contains Deny, and reports the total deny ACE count along with the number of affected objects.
Related Testsโ
Test-MtAdDaclDenyAceDetailsTest-MtAdDaclDistinctObjectCountTest-MtAdDaclOuObjectCount
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DACL-05 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclDenyAceCount |
| Tags | AD, AD-DACL-05, AD.DACL |
Sourceโ
- Pester test:
tests/ad/dacl/Test-MtAdDaclDenyAceCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclDenyAceCount.ps1

