AD-DACL-17 - Inherited object type count should be retrievable
Overviewโ
Inherited object type GUIDs define which descendant object classes an inheritable ACE targets.
- Delegation scope visibility: Helps show how precisely ACE inheritance is scoped
- Privilege impact analysis: Broad inheritance can extend powerful rights to many child objects
- Configuration review: Distinct inherited object types reveal the variety of object classes affected by delegations
Security Recommendationโ
- Review inherited ACEs that target sensitive descendant object classes
- Prefer precise scoping over overly broad inheritance where possible
- Validate that inheritance design matches your delegation model and administrative boundaries
How the Test Worksโ
This test reads $adState.DaclEntries, filters for InheritedObjectType GUIDs that are not the all-zero default value, and counts the distinct GUIDs present.
Related Testsโ
Test-MtAdDaclInheritedObjectTypeDetails- Provides a breakdown by inherited object type GUIDTest-MtAdDaclNonInheritedAceCount- Counts ACEs that are explicitly assignedTest-MtAdDaclPrivilegedAllowAceDetails- Shows privileged allow authorizations in DACLs
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DACL-17 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclInheritedObjectTypeCount |
| Tags | AD, AD-DACL-17, AD.DACL |
Sourceโ
- Pester test:
tests/ad/dacl/Test-MtAdDaclInheritedObjectTypeCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclInheritedObjectTypeCount.ps1

