AD-FGPP-03 - Fine-grained password policy setting counts should be retrievable
Overviewβ
Having a detailed breakdown of fine-grained password policy settings allows you to:
- Audit security levels: Verify that privileged accounts have stronger policies
- Identify misconfigurations: Spot policies that may be incorrectly configured
- Ensure compliance: Validate that all policies meet minimum security requirements
- Document coverage: Understand exactly what controls are in place
This detailed view complements the value count by showing the actual settings rather than just the number of variations.
Security Recommendationβ
When reviewing fine-grained password policy settings, ensure:
| User Type | Min Length | Max Age | History | Complexity | Lockout Threshold |
|---|---|---|---|---|---|
| Domain Admins | 15+ | 60 days | 24+ | Enabled | 3-5 |
| Service Accounts | 20+ | Never | 24+ | Enabled | 3-5 |
| Regular Users | 14+ | 90 days | 24 | Enabled | 5 |
To review and modify policy settings:
- Open Active Directory Administrative Center
- Navigate to System > Password Settings Container
- Double-click each policy to review settings
- Adjust as needed to meet security requirements
How the Test Worksβ
This test retrieves all fine-grained password policies using Get-ADFineGrainedPasswordPolicy and creates a table showing key settings for each policy:
- Policy name
- Minimum password length
- Maximum password age (in days)
- Password history count
- Complexity enabled (Yes/No)
- Lockout threshold
Related Testsβ
Test-MtAdFineGrainedPolicyCount- Counts the number of FGPPsTest-MtAdFineGrainedPolicyValueCount- Shows distinct values across policiesTest-MtAdFineGrainedPolicyAppliesTo- Shows which users/groups each policy applies to
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-FGPP-03 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.PasswordPolicy |
| PowerShell test | Test-MtAdFineGrainedPolicySettingCounts |
| Tags | AD, AD-FGPP-03, AD.PasswordPolicy |
Sourceβ
- Pester test:
tests/ad/passwordpolicy/Test-MtAdFineGrainedPolicySettingCounts.Tests.ps1 - PowerShell source:
powershell/public/ad/passwordpolicy/Test-MtAdFineGrainedPolicySettingCounts.ps1

