AD-DACL-13 - Privileged extended right identities should be retrievable
Overviewโ
Privileged extended rights in Active Directory can authorize sensitive operations that go beyond standard read or write permissions.
- Privilege escalation risk: Rights such as password reset or replication access can enable takeover paths
- Delegation review: Extended rights are often assigned during admin delegation and may persist longer than intended
- Exposure visibility: Grouping by identity shows which principals hold high-impact rights across the directory
Security Recommendationโ
- Review every identity granted privileged extended rights
- Confirm the assignment is documented, approved, and still required
- Remove stale delegations, especially for replication and password-management rights
How the Test Worksโ
This test reads $adState.DaclEntries, filters for allow ACEs with ActiveDirectoryRights = ExtendedRight, matches them to a set of privileged extended right GUIDs, and groups the results by IdentityReference.
Related Testsโ
Test-MtAdDaclPrivilegedExtendedRightCount- Counts privileged extended rights in useTest-MtAdDaclPrivilegedExtendedRightDetails- Breaks down privileged extended rights by typeTest-MtAdDaclNonInheritedAceCount- Counts explicit DACL entries that may represent custom delegations
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DACL-13 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclPrivilegedExtendedRightIdentity |
| Tags | AD, AD-DACL-13, AD.DACL |
Sourceโ
- Pester test:
tests/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightIdentity.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightIdentity.ps1

