AD-DACL-18 - Inherited object type details should be retrievable
Overviewβ
Inherited object type detail helps explain where inheritable ACEs are intended to apply.
- Scoping transparency: Reveals which descendant object classes are targeted most often
- Delegation review: Helps validate whether inherited permissions are narrowly or broadly applied
- Troubleshooting support: Useful when investigating unexpected effective permissions on child objects
Security Recommendationβ
- Review heavily used inherited object type targets for overly broad delegations
- Confirm that inherited ACE scope matches intended administrative boundaries
- Reassess inherited rights on sensitive containers if descendant object targeting is not well understood
How the Test Worksβ
This test reads $adState.DaclEntries, filters out the all-zero InheritedObjectType value, and groups the remaining ACEs by inherited object type GUID.
Related Testsβ
Test-MtAdDaclInheritedObjectTypeCount- Counts distinct inherited object type GUIDsTest-MtAdDaclPrivilegedExtendedRightIdentity- Shows identities with privileged extended rightsTest-MtAdDaclUnresolvedSidDetails- Lists objects containing orphaned SID ACEs
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DACL-18 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclInheritedObjectTypeDetails |
| Tags | AD, AD-DACL-18, AD.DACL |
Sourceβ
- Pester test:
tests/ad/dacl/Test-MtAdDaclInheritedObjectTypeDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclInheritedObjectTypeDetails.ps1

