Skip to main content
Version: 2.2.1-preview

AD-DACL-13 - Privileged extended right identities should be retrievable

Overviewโ€‹

Privileged extended rights in Active Directory can authorize sensitive operations that go beyond standard read or write permissions.

  • Privilege escalation risk: Rights such as password reset or replication access can enable takeover paths
  • Delegation review: Extended rights are often assigned during admin delegation and may persist longer than intended
  • Exposure visibility: Grouping by identity shows which principals hold high-impact rights across the directory

Security Recommendationโ€‹

  • Review every identity granted privileged extended rights
  • Confirm the assignment is documented, approved, and still required
  • Remove stale delegations, especially for replication and password-management rights

How the Test Worksโ€‹

This test reads $adState.DaclEntries, filters for allow ACEs with ActiveDirectoryRights = ExtendedRight, matches them to a set of privileged extended right GUIDs, and groups the results by IdentityReference.

  • Test-MtAdDaclPrivilegedExtendedRightCount - Counts privileged extended rights in use
  • Test-MtAdDaclPrivilegedExtendedRightDetails - Breaks down privileged extended rights by type
  • Test-MtAdDaclNonInheritedAceCount - Counts explicit DACL entries that may represent custom delegations

Test Metadataโ€‹

FieldValue
Test IDAD-DACL-13
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclPrivilegedExtendedRightIdentity
TagsAD, AD-DACL-13, AD.DACL

Sourceโ€‹

  • Pester test: tests/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightIdentity.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclPrivilegedExtendedRightIdentity.ps1