Skip to main content
Version: 2.2.1-preview

AD-DACL-15 - Unresolved SID count should be retrievable

Overviewโ€‹

Unresolved SIDs in DACLs often indicate deleted users or groups, stale migration artifacts, or incomplete cleanup.

  • Stale delegation detection: Old ACEs can remain after identities are removed
  • Operational hygiene: Orphaned SID references make permissions harder to review and audit
  • Migration validation: Unresolved SIDs can reveal accounts that were not fully remapped or retired

Security Recommendationโ€‹

  • Investigate unresolved SID ACEs and determine whether they can be removed
  • Validate that deprovisioning and migration processes clean up obsolete permissions
  • Review privileged containers first, where stale ACEs can cause confusion during incident response

How the Test Worksโ€‹

This test reads $adState.DaclEntries and looks for entries whose IdentityReference starts with S-1-5-21, which commonly indicates a SID that did not resolve to a friendly name.

  • Test-MtAdDaclUnresolvedSidDetails - Lists unresolved SID references by object
  • Test-MtAdDaclDistinctIdentityCount - Counts distinct identities present in ACEs
  • Test-MtAdDaclIdentityAceDistribution - Shows ACE distribution across identities

Test Metadataโ€‹

FieldValue
Test IDAD-DACL-15
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclUnresolvedSidCount
TagsAD, AD-DACL-15, AD.DACL

Sourceโ€‹

  • Pester test: tests/ad/dacl/Test-MtAdDaclUnresolvedSidCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclUnresolvedSidCount.ps1