AD-FOR-02 - Forest domain count should be retrievable
Overviewโ
Understanding the number and names of domains in your forest is critical for:
- Security Boundaries: Each domain represents a security boundary with its own policies
- Trust Management: Understanding trust relationships between domains
- Administrative Scope: Knowing where administrative permissions apply
- Compliance Scope: Determining the scope of compliance assessments
- Disaster Recovery: Planning recovery procedures across all domains
Security Recommendationโ
- Minimize Domains: Fewer domains reduce complexity and attack surface
- Document Structure: Maintain documentation of all domains and their purposes
- Review Regularly: Periodically review if all domains are still needed
- Consistent Policies: Apply consistent security policies across all domains
How the Test Worksโ
This test retrieves all domains from the Active Directory forest and counts them. It also lists all domain names for reference.
Related Testsโ
Test-MtAdForestFunctionalLevel- Retrieves the forest functional levelTest-MtAdDomainControllerCount- Counts domain controllers in the current domain
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-FOR-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Forest |
| PowerShell test | Test-MtAdForestDomainCount |
| Tags | AD, AD-FOR-02, AD.Forest |
Sourceโ
- Pester test:
tests/ad/domain/Test-MtAdForestDomainCount.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdForestDomainCount.ps1

