Skip to main content
Version: 2.2.1-preview

AD-DACL-09 - Privileged allow ACE count should be retrievable

Overview​

Allow ACEs that grant GenericAll, WriteDacl, WriteOwner, or ExtendedRight can enable high-impact control over Active Directory objects. These permissions are commonly involved in privilege escalation and persistence paths.

  • GenericAll: Grants broad control over the object.
  • WriteDacl / WriteOwner: Enables permission tampering or ownership takeover.
  • ExtendedRight: May allow sensitive control-access operations depending on object type.

Security Recommendation​

Limit privileged rights to tightly controlled administrative groups. Investigate unexpected identities or objects that accumulate these permissions.

How the Test Works​

This test reads DaclEntries from Get-MtADDomainState, filters to allow ACEs, and counts entries where ActiveDirectoryRights includes GenericAll, WriteDacl, WriteOwner, or ExtendedRight.

  • Test-MtAdDaclPrivilegedAllowAceDetails
  • Test-MtAdDaclPrivilegedExtendedRightCount
  • Test-MtAdDaclDistinctIdentityCount

Test Metadata​

FieldValue
Test IDAD-DACL-09
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclPrivilegedAllowAceCount
TagsAD, AD-DACL-09, AD.DACL

Source​

  • Pester test: tests/ad/dacl/Test-MtAdDaclPrivilegedAllowAceCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclPrivilegedAllowAceCount.ps1