Skip to main content
Version: 2.2.1-preview

AD-DACL-10 - Privileged allow ACE details should be retrievable

Overviewโ€‹

A count alone does not show where powerful ACEs are applied. Grouping privileged allow ACEs by object helps identify high-value directory objects that carry sensitive delegated rights.

  • Object-Centric Review: Highlights which objects hold the most powerful ACEs.
  • Delegation Validation: Makes it easier to confirm whether privileged rights are intentional.
  • Attack Path Awareness: Sensitive permissions on administrative objects can enable escalation.

Security Recommendationโ€‹

Review objects with privileged allow ACEs and confirm the assigned identities and rights are justified. Reduce direct assignments where possible and prefer auditable group-based delegation.

How the Test Worksโ€‹

This test reads DaclEntries from Get-MtADDomainState, filters to allow ACEs containing GenericAll, WriteDacl, WriteOwner, or ExtendedRight, and groups the results by object.

  • Test-MtAdDaclPrivilegedAllowAceCount
  • Test-MtAdDaclIdentityAceDistribution
  • Test-MtAdDaclPrivilegedExtendedRightDetails

Test Metadataโ€‹

FieldValue
Test IDAD-DACL-10
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclPrivilegedAllowAceDetails
TagsAD, AD-DACL-10, AD.DACL

Sourceโ€‹

  • Pester test: tests/ad/dacl/Test-MtAdDaclPrivilegedAllowAceDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclPrivilegedAllowAceDetails.ps1