Skip to main content
Version: 2.2.1-preview

AD-DACL-07 - Distinct DACL identity count should be retrievable

Overview​

Every DACL ACE references a security principal. Tracking the number of distinct identities appearing in delegated permissions helps you understand how widely access has been spread across the directory.

  • Delegation Visibility: A large number of distinct identities can indicate broad or inconsistent delegation.
  • Review Prioritization: Security teams can focus on identities that appear repeatedly across sensitive objects.
  • Baseline Tracking: Repeated measurement makes it easier to spot growth in delegated access over time.

Security Recommendation​

Keep delegation models simple and intentional. Prefer group-based administration over direct assignment to many individual accounts or SIDs.

How the Test Works​

This test reads DaclEntries from Get-MtADDomainState, extracts unique IdentityReference values, and reports how many distinct identities appear across all collected ACEs.

  • Test-MtAdDaclIdentityAceDistribution
  • Test-MtAdDaclPrivilegedAllowAceCount
  • Test-MtAdDaclPrivilegedExtendedRightCount

Test Metadata​

FieldValue
Test IDAD-DACL-07
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclDistinctIdentityCount
TagsAD, AD-DACL-07, AD.DACL

Source​

  • Pester test: tests/ad/dacl/Test-MtAdDaclDistinctIdentityCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclDistinctIdentityCount.ps1