AD-DACL-15 - Unresolved SID count should be retrievable
Overviewโ
Unresolved SIDs in DACLs often indicate deleted users or groups, stale migration artifacts, or incomplete cleanup.
- Stale delegation detection: Old ACEs can remain after identities are removed
- Operational hygiene: Orphaned SID references make permissions harder to review and audit
- Migration validation: Unresolved SIDs can reveal accounts that were not fully remapped or retired
Security Recommendationโ
- Investigate unresolved SID ACEs and determine whether they can be removed
- Validate that deprovisioning and migration processes clean up obsolete permissions
- Review privileged containers first, where stale ACEs can cause confusion during incident response
How the Test Worksโ
This test reads $adState.DaclEntries and looks for entries whose IdentityReference starts with S-1-5-21, which commonly indicates a SID that did not resolve to a friendly name.
Related Testsโ
Test-MtAdDaclUnresolvedSidDetails- Lists unresolved SID references by objectTest-MtAdDaclDistinctIdentityCount- Counts distinct identities present in ACEsTest-MtAdDaclIdentityAceDistribution- Shows ACE distribution across identities
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DACL-15 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclUnresolvedSidCount |
| Tags | AD, AD-DACL-15, AD.DACL |
Sourceโ
- Pester test:
tests/ad/dacl/Test-MtAdDaclUnresolvedSidCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclUnresolvedSidCount.ps1

