AD-DACL-08 - DACL ACE distribution per identity should be retrievable
Overviewโ
Knowing which identities appear most frequently in DACLs helps identify central delegation patterns, inherited administrative groups, and accounts that may have accumulated permissions over time.
- Hotspot Detection: Frequently occurring identities can represent broad administrative reach.
- Permission Hygiene: Distribution data helps distinguish expected administrative groups from unusual direct assignments.
- Operational Review: Repeated counts per identity make it easier to validate changes after cleanup or redesign.
Security Recommendationโ
Review identities with unusually high ACE counts. Confirm they are expected administrative groups and not stale accounts, orphaned SIDs, or overly broad delegated principals.
How the Test Worksโ
This test reads DaclEntries from Get-MtADDomainState, groups entries by IdentityReference, and reports the number of ACEs associated with each identity.
Related Testsโ
Test-MtAdDaclDistinctIdentityCountTest-MtAdDaclPrivilegedAllowAceDetailsTest-MtAdDaclPrivilegedExtendedRightDetails
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DACL-08 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclIdentityAceDistribution |
| Tags | AD, AD-DACL-08, AD.DACL |
Sourceโ
- Pester test:
tests/ad/dacl/Test-MtAdDaclIdentityAceDistribution.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclIdentityAceDistribution.ps1

