AD-DACL-12 - Privileged extended right details should be retrievable
Overviewβ
Extended rights are most useful when you can see which specific ObjectType values are being delegated. Grouping ACEs by GUID reveals whether permissions are narrowly targeted or broadly applied.
- GUID-Level Visibility: Highlights which extended-right object types occur most often.
- Delegation Review: Helps correlate control-access permissions with documented administration patterns.
- Change Tracking: Makes it easier to compare extended-right usage over time.
Security Recommendationβ
Document the purpose of delegated extended rights and review object types with high counts or unexpected identity coverage.
How the Test Worksβ
This test reads DaclEntries from Get-MtADDomainState, filters to allow ACEs containing ExtendedRight, normalizes missing ObjectType values, and groups the results by ObjectType.
Related Testsβ
Test-MtAdDaclPrivilegedExtendedRightCountTest-MtAdDaclPrivilegedAllowAceDetailsTest-MtAdDaclIdentityAceDistribution
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DACL-12 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclPrivilegedExtendedRightDetails |
| Tags | AD, AD-DACL-12, AD.DACL |
Sourceβ
- Pester test:
tests/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightDetails.ps1

