Skip to main content
Version: 2.2.1-preview

AD-DACL-18 - Inherited object type details should be retrievable

Overview​

Inherited object type detail helps explain where inheritable ACEs are intended to apply.

  • Scoping transparency: Reveals which descendant object classes are targeted most often
  • Delegation review: Helps validate whether inherited permissions are narrowly or broadly applied
  • Troubleshooting support: Useful when investigating unexpected effective permissions on child objects

Security Recommendation​

  • Review heavily used inherited object type targets for overly broad delegations
  • Confirm that inherited ACE scope matches intended administrative boundaries
  • Reassess inherited rights on sensitive containers if descendant object targeting is not well understood

How the Test Works​

This test reads $adState.DaclEntries, filters out the all-zero InheritedObjectType value, and groups the remaining ACEs by inherited object type GUID.

  • Test-MtAdDaclInheritedObjectTypeCount - Counts distinct inherited object type GUIDs
  • Test-MtAdDaclPrivilegedExtendedRightIdentity - Shows identities with privileged extended rights
  • Test-MtAdDaclUnresolvedSidDetails - Lists objects containing orphaned SID ACEs

Test Metadata​

FieldValue
Test IDAD-DACL-18
SeverityInfo
SuiteActive Directory
CategoryAD.DACL
PowerShell testTest-MtAdDaclInheritedObjectTypeDetails
TagsAD, AD-DACL-18, AD.DACL

Source​

  • Pester test: tests/ad/dacl/Test-MtAdDaclInheritedObjectTypeDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/dacl/Test-MtAdDaclInheritedObjectTypeDetails.ps1