Skip to main content
Version: 2.2.1-preview

AD-DACL-12 - Privileged extended right details should be retrievable

Overview​

Extended rights are most useful when you can see which specific ObjectType values are being delegated. Grouping ACEs by GUID reveals whether permissions are narrowly targeted or broadly applied.

  • GUID-Level Visibility: Highlights which extended-right object types occur most often.
  • Delegation Review: Helps correlate control-access permissions with documented administration patterns.
  • Change Tracking: Makes it easier to compare extended-right usage over time.

Security Recommendation​

Document the purpose of delegated extended rights and review object types with high counts or unexpected identity coverage.

How the Test Works​

This test reads DaclEntries from Get-MtADDomainState, filters to allow ACEs containing ExtendedRight, normalizes missing ObjectType values, and groups the results by ObjectType.

  • Test-MtAdDaclPrivilegedExtendedRightCount
  • Test-MtAdDaclPrivilegedAllowAceDetails
  • Test-MtAdDaclIdentityAceDistribution

Test Metadata​

FieldValue
Test IDAD-DACL-12
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclPrivilegedExtendedRightDetails
TagsAD, AD-DACL-12, AD.DACL

Source​

  • Pester test: tests/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightDetails.ps1