AD-FGPP-02 - Fine-grained password policy value count should be retrievable
Overviewโ
Understanding the variation in fine-grained password policy settings helps you:
- Identify inconsistencies: Spot policies that may be too lenient or too strict
- Validate policy design: Ensure you have appropriate differentiation between user types
- Find gaps: Discover if certain security controls are missing from some policies
- Audit compliance: Verify that all policies meet minimum security requirements
Having multiple distinct values indicates you're using FGPPs to differentiate security requirements. Having identical values across all policies may indicate unnecessary duplication.
Security Recommendationโ
Review your fine-grained password policies to ensure:
- Privileged accounts have the strongest policies (longest passwords, shortest max age)
- Service accounts have appropriate policies (very long passwords, no expiration if needed)
- Regular users have balanced policies (secure but usable)
- No policies are weaker than the default domain policy
To review policy values:
- Open Active Directory Administrative Center
- Navigate to System > Password Settings Container
- Review each policy's settings
- Ensure policies are appropriately differentiated
How the Test Worksโ
This test retrieves all fine-grained password policies using Get-ADFineGrainedPasswordPolicy and counts distinct values for key settings:
- Minimum password length
- Maximum password age
- Password history count
- Complexity enabled
- Lockout threshold
The test reports the variety of settings across all policies.
Related Testsโ
Test-MtAdFineGrainedPolicyCount- Counts the number of FGPPsTest-MtAdFineGrainedPolicyAppliesTo- Shows which users/groups each policy applies to
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-FGPP-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.PasswordPolicy |
| PowerShell test | Test-MtAdFineGrainedPolicyValueCount |
| Tags | AD, AD-FGPP-02, AD.PasswordPolicy |
Sourceโ
- Pester test:
tests/ad/passwordpolicy/Test-MtAdFineGrainedPolicyValueCount.Tests.ps1 - PowerShell source:
powershell/public/ad/passwordpolicy/Test-MtAdFineGrainedPolicyValueCount.ps1

