Skip to main content
Version: 2.2.1-preview

AD-DACL-11 - Privileged extended right count should be retrievable

Overview​

Extended rights control specific privileged operations in Active Directory, such as sensitive control-access permissions tied to object classes or administrative workflows. Understanding how often they are delegated helps surface potentially risky permission models.

  • Sensitive Operations: Some extended rights can enable password resets, replication access, or other administrative actions.
  • Delegation Mapping: Counting these ACEs helps you understand how broadly control-access permissions are assigned.
  • Scope Awareness: Distinct ObjectType values show how granular or broad the delegation is.

Security Recommendation​

Review principals granted extended rights and verify that those delegations are necessary, documented, and limited to the smallest practical scope.

How the Test Works​

This test reads DaclEntries from Get-MtADDomainState, filters to allow ACEs whose ActiveDirectoryRights includes ExtendedRight, and reports counts across identities, objects, and object types.

  • Test-MtAdDaclPrivilegedExtendedRightDetails
  • Test-MtAdDaclPrivilegedAllowAceCount
  • Test-MtAdDaclPrivilegedAllowAceDetails

Test Metadata​

FieldValue
Test IDAD-DACL-11
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclPrivilegedExtendedRightCount
TagsAD, AD-DACL-11, AD.DACL

Source​

  • Pester test: tests/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightCount.ps1