AD-DACL-11 - Privileged extended right count should be retrievable
Overviewβ
Extended rights control specific privileged operations in Active Directory, such as sensitive control-access permissions tied to object classes or administrative workflows. Understanding how often they are delegated helps surface potentially risky permission models.
- Sensitive Operations: Some extended rights can enable password resets, replication access, or other administrative actions.
- Delegation Mapping: Counting these ACEs helps you understand how broadly control-access permissions are assigned.
- Scope Awareness: Distinct
ObjectTypevalues show how granular or broad the delegation is.
Security Recommendationβ
Review principals granted extended rights and verify that those delegations are necessary, documented, and limited to the smallest practical scope.
How the Test Worksβ
This test reads DaclEntries from Get-MtADDomainState, filters to allow ACEs whose ActiveDirectoryRights includes ExtendedRight, and reports counts across identities, objects, and object types.
Related Testsβ
Test-MtAdDaclPrivilegedExtendedRightDetailsTest-MtAdDaclPrivilegedAllowAceCountTest-MtAdDaclPrivilegedAllowAceDetails
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DACL-11 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclPrivilegedExtendedRightCount |
| Tags | AD, AD-DACL-11, AD.DACL |
Sourceβ
- Pester test:
tests/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightCount.ps1

