Skip to main content
Version: 2.2.1-preview

AD-DACL-08 - DACL ACE distribution per identity should be retrievable

Overviewโ€‹

Knowing which identities appear most frequently in DACLs helps identify central delegation patterns, inherited administrative groups, and accounts that may have accumulated permissions over time.

  • Hotspot Detection: Frequently occurring identities can represent broad administrative reach.
  • Permission Hygiene: Distribution data helps distinguish expected administrative groups from unusual direct assignments.
  • Operational Review: Repeated counts per identity make it easier to validate changes after cleanup or redesign.

Security Recommendationโ€‹

Review identities with unusually high ACE counts. Confirm they are expected administrative groups and not stale accounts, orphaned SIDs, or overly broad delegated principals.

How the Test Worksโ€‹

This test reads DaclEntries from Get-MtADDomainState, groups entries by IdentityReference, and reports the number of ACEs associated with each identity.

  • Test-MtAdDaclDistinctIdentityCount
  • Test-MtAdDaclPrivilegedAllowAceDetails
  • Test-MtAdDaclPrivilegedExtendedRightDetails

Test Metadataโ€‹

FieldValue
Test IDAD-DACL-08
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclIdentityAceDistribution
TagsAD, AD-DACL-08, AD.DACL

Sourceโ€‹

  • Pester test: tests/ad/dacl/Test-MtAdDaclIdentityAceDistribution.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclIdentityAceDistribution.ps1