AD-DC-08 - DC operating system details should be retrievable
Overviewโ
Understanding the operating system distribution across your domain controllers helps with:
- Security compliance: Identifying DCs on unsupported OS versions
- Patch management: Planning update cycles across different OS versions
- Upgrade planning: Prioritizing which DCs to upgrade first
- Capacity planning: Understanding feature availability across DCs
- Risk assessment: Evaluating exposure from outdated systems
Domain controllers running end-of-life operating systems are a critical security risk as they no longer receive security updates, making them vulnerable to known exploits.
Security Recommendationโ
Upgrade domain controllers running end-of-life operating systems immediately.
Priority order for upgrades:
- Windows Server 2008 R2 and earlier (unsupported)
- Windows Server 2012/2012 R2 (extended support ended)
- Windows Server 2016 (still supported, but older)
Upgrade process:
- Promote new DCs on supported OS versions
- Transfer FSMO roles if needed
- Demote old DCs
- Remove from domain
How the Test Worksโ
This test retrieves the OperatingSystem attribute from all domain controllers and groups them by OS version, showing:
- Count of DCs per OS version
- Percentage distribution
- Names of DCs running each OS
Related Testsโ
Test-MtAdDcOperatingSystemCount- Count of unique OS versionsTest-MtAdDomainControllerCount- Total DC count
Related linksโ
- Microsoft Learn: Windows Server release information
- ANSSI Active Directory checkpoints: DC/RODC with an obsolete operating system
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DC-08 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.DomainController |
| PowerShell test | Test-MtAdDcOperatingSystemDetails |
| Tags | AD, AD-DC-08, AD.DomainController |
Sourceโ
- Pester test:
tests/ad/domaincontroller/Test-MtAdDcOperatingSystemDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/domaincontroller/Test-MtAdDcOperatingSystemDetails.ps1


