Skip to main content
Version: 2.2.1-preview

AD-DOM-03 - Domain controller count should be retrievable

Overviewโ€‹

Understanding the number and distribution of domain controllers in your domain is critical for:

  • High Availability: Ensuring sufficient DCs exist to handle authentication load and provide redundancy
  • Disaster Recovery: Knowing how many DCs need to be recovered in a disaster scenario
  • Site Coverage: Verifying that all sites have appropriate DC coverage for local authentication
  • Capacity Planning: Determining if additional DCs are needed based on user and computer growth

Security Recommendationโ€‹

  • Minimum Redundancy: Maintain at least 2 DCs per domain for fault tolerance
  • Geographic Distribution: Place DCs strategically across sites to ensure local authentication
  • RODC Consideration: Consider Read-Only Domain Controllers (RODC) for branch offices
  • Regular Monitoring: Track DC health and availability as part of your security monitoring

How the Test Worksโ€‹

This test retrieves all domain controllers from Active Directory and counts them. It also lists the names of all DCs for easy reference.

  • Test-MtAdDomainFunctionalLevel - Retrieves the domain functional level
  • Test-MtAdForestDomainCount - Counts domains in the forest

Test Metadataโ€‹

FieldValue
Test IDAD-DOM-03
SeverityInfo
SuiteActive Directory
CategoryAD.Domain
PowerShell testTest-MtAdDomainControllerCount
TagsAD, AD-DOM-03, AD.Domain

Sourceโ€‹

  • Pester test: tests/ad/domain/Test-MtAdDomainControllerCount.Tests.ps1
  • PowerShell source: powershell/public/ad/domain/Test-MtAdDomainControllerCount.ps1