AD-DACL-16 - Unresolved SID details should be retrievable
Overviewβ
Knowing which directory objects contain orphaned SID ACEs helps target cleanup work where it matters most.
- Object-focused remediation: Grouping unresolved SIDs by object shows exactly where stale ACEs exist
- Audit clarity: Makes manual DACL review easier during privileged access assessments
- Change tracking: Helps confirm whether decommissioned identities still linger on important objects
Security Recommendationβ
- Remove orphaned ACEs after confirming the referenced SID is no longer valid
- Prioritize cleanup on privileged OUs, admin groups, and delegation-heavy containers
- Document recurring sources of unresolved SIDs to improve identity lifecycle processes
How the Test Worksβ
This test reads $adState.DaclEntries, filters unresolved IdentityReference values that begin with S-1-5-21, and groups them by ObjectDN.
Related Testsβ
Test-MtAdDaclUnresolvedSidCount- Counts unresolved SID referencesTest-MtAdDaclNonInheritedAceCount- Counts explicit ACEs that may require reviewTest-MtAdDaclInheritedObjectTypeDetails- Shows inheritance targeting across ACEs
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DACL-16 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclUnresolvedSidDetails |
| Tags | AD, AD-DACL-16, AD.DACL |
Sourceβ
- Pester test:
tests/ad/dacl/Test-MtAdDaclUnresolvedSidDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclUnresolvedSidDetails.ps1

