AD-DOM-04 - RIDs remaining should be retrievable
Overviewβ
RIDs (Relative Identifiers) are essential for creating unique Security Identifiers (SIDs) for every user, group, and computer in Active Directory. Each domain has a finite pool of approximately 1 billion RIDs:
- SID Exhaustion: Running out of RIDs would prevent creation of any new security principals
- Business Impact: New users, groups, or computers could not be created
- Recovery Complexity: RID pool exhaustion requires complex forest recovery procedures
Security Recommendationβ
Monitor RID consumption regularly:
- Normal Usage: Most domains use only a small fraction of available RIDs over their lifetime
- High Consumption: Rapid RID consumption may indicate:
- Excessive computer account creation/deletion cycles
- Automated provisioning scripts creating many accounts
- Security issues like computer account flooding attacks
- Threshold Alerting: Set alerts when RID usage exceeds 50% (very conservative) or 75%
If RID consumption is unexpectedly high:
- Investigate the source of high account creation
- Review computer join policies and scripts
- Consider implementing stricter controls on account creation
How the Test Worksβ
This test retrieves the RID available pool from Active Directory and calculates the remaining RIDs. The RID pool is a 64-bit value where the high 32 bits represent the total pool and the low 32 bits represent used RIDs.
Related Testsβ
Test-MtAdDomainControllerCount- Counts domain controllers (RID masters)Test-MtAdMachineAccountQuota- Checks machine account creation limits
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DOM-04 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Domain |
| PowerShell test | Test-MtAdRidsRemaining |
| Tags | AD, AD-DOM-04, AD.Domain |
Sourceβ
- Pester test:
tests/ad/domain/Test-MtAdRidsRemaining.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdRidsRemaining.ps1

