AD-FGPP-04 - Fine-grained password policy application targets should be retrievable
Overviewโ
Understanding which users and groups each fine-grained password policy applies to is essential for:
- Verifying coverage: Ensure all privileged accounts are covered by stronger policies
- Avoiding gaps: Identify users who should have stricter policies but don't
- Preventing conflicts: Spot users who may be subject to multiple conflicting policies
- Audit compliance: Demonstrate that security controls are applied appropriately
A policy that doesn't apply to anyone is wasted configuration. A policy that applies to the wrong users can create security gaps or usability issues.
Security Recommendationโ
Ensure your fine-grained password policies are applied correctly:
- Privileged groups: Domain Admins, Enterprise Admins, Schema Admins should have the strongest policies
- Service accounts: Accounts used for services and applications need appropriate policies
- No gaps: All users with elevated privileges should be covered
- No conflicts: Users should not be subject to multiple FGPPs (the one with the lowest precedence wins)
To review and modify policy application:
- Open Active Directory Administrative Center
- Navigate to System > Password Settings Container
- Double-click a policy
- In the Directly Applies To section, review and modify the users and groups
Note: If a user is subject to multiple FGPPs, the one with the lowest precedence number wins. If precedence is equal, the policy with the most specific match wins.
How the Test Worksโ
This test retrieves all fine-grained password policies using Get-ADFineGrainedPasswordPolicy and shows which users and groups each policy applies to. For each policy, the test reports:
- Policy name
- List of users and groups the policy applies to
- Object type (user, group, etc.)
- Warning if a policy has no application targets
Related Testsโ
Test-MtAdFineGrainedPolicyCount- Counts the number of FGPPsTest-MtAdFineGrainedPolicySettingCounts- Shows detailed settings for each policy
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-FGPP-04 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.PasswordPolicy |
| PowerShell test | Test-MtAdFineGrainedPolicyAppliesTo |
| Tags | AD, AD-FGPP-04, AD.PasswordPolicy |
Sourceโ
- Pester test:
tests/ad/passwordpolicy/Test-MtAdFineGrainedPolicyAppliesTo.Tests.ps1 - PowerShell source:
powershell/public/ad/passwordpolicy/Test-MtAdFineGrainedPolicyAppliesTo.ps1

