Skip to main content
Version: 2.2.1-preview

AD-DACL-05 - Deny ACE count should be retrievable

Overviewโ€‹

Deny ACEs are powerful because they can override allow permissions and create access outcomes that are difficult to troubleshoot. Counting them provides a quick baseline for how much explicit denial logic exists in the collected AD permission set.

  • Highlights explicit deny usage in AD DACLs
  • Supports troubleshooting for delegation and access issues
  • Helps prioritize deeper review when deny ACE volume is high

Security Recommendationโ€‹

Review deny ACE usage carefully. Ensure each deny entry is intentional, documented, and still required. Excessive or poorly understood deny entries can create administrative confusion and mask broader permission issues.

How the Test Worksโ€‹

This test retrieves $adState.DaclEntries, filters entries where AccessControlType contains Deny, and reports the total deny ACE count along with the number of affected objects.

  • Test-MtAdDaclDenyAceDetails
  • Test-MtAdDaclDistinctObjectCount
  • Test-MtAdDaclOuObjectCount

Test Metadataโ€‹

FieldValue
Test IDAD-DACL-05
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclDenyAceCount
TagsAD, AD-DACL-05, AD.DACL

Sourceโ€‹

  • Pester test: tests/ad/dacl/Test-MtAdDaclDenyAceCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclDenyAceCount.ps1