AD-FGPP-01 - Fine-grained password policy count should be retrievable
Overviewโ
Fine-grained password policies (FGPP) provide critical flexibility for security-conscious organizations:
- Privileged account protection: Apply stricter password policies to administrators and service accounts
- Risk-based policies: Different policies for different risk levels (e.g., IT admins vs. regular users)
- Compliance flexibility: Meet varying compliance requirements for different user populations
- Service account security: Enforce stronger policies for accounts that cannot use MFA
Without FGPPs, all users in the domain are subject to the same password policy, which often results in either:
- Too weak a policy for privileged accounts, or
- Too restrictive a policy for regular users, leading to workarounds
Security Recommendationโ
Consider implementing fine-grained password policies for:
- Domain Admins and privileged accounts: Stronger requirements (longer passwords, shorter max age)
- Service accounts: Long, complex passwords that don't expire (since they can't easily be changed)
- High-risk users: Users with access to sensitive data
To create a fine-grained password policy:
- Open Active Directory Administrative Center
- Navigate to System > Password Settings Container
- Right-click and select New > Password Settings
- Configure policy settings and apply to appropriate users/groups
How the Test Worksโ
This test retrieves all fine-grained password policies using Get-ADFineGrainedPasswordPolicy and counts them. The test reports:
- Number of FGPPs configured
- Whether FGPPs are being used for granular policy control
Related Testsโ
Test-MtAdFineGrainedPolicyAppliesTo- Shows which users/groups each policy applies toTest-MtAdPasswordHistoryCount- Checks the default domain password history
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-FGPP-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.PasswordPolicy |
| PowerShell test | Test-MtAdFineGrainedPolicyCount |
| Tags | AD, AD-FGPP-01, AD.PasswordPolicy |
Sourceโ
- Pester test:
tests/ad/passwordpolicy/Test-MtAdFineGrainedPolicyCount.Tests.ps1 - PowerShell source:
powershell/public/ad/passwordpolicy/Test-MtAdFineGrainedPolicyCount.ps1

