Skip to main content
Version: 2.2.1-preview

AD-FOR-02 - Forest domain count should be retrievable

Overviewโ€‹

Understanding the number and names of domains in your forest is critical for:

  • Security Boundaries: Each domain represents a security boundary with its own policies
  • Trust Management: Understanding trust relationships between domains
  • Administrative Scope: Knowing where administrative permissions apply
  • Compliance Scope: Determining the scope of compliance assessments
  • Disaster Recovery: Planning recovery procedures across all domains

Security Recommendationโ€‹

  • Minimize Domains: Fewer domains reduce complexity and attack surface
  • Document Structure: Maintain documentation of all domains and their purposes
  • Review Regularly: Periodically review if all domains are still needed
  • Consistent Policies: Apply consistent security policies across all domains

How the Test Worksโ€‹

This test retrieves all domains from the Active Directory forest and counts them. It also lists all domain names for reference.

  • Test-MtAdForestFunctionalLevel - Retrieves the forest functional level
  • Test-MtAdDomainControllerCount - Counts domain controllers in the current domain

Test Metadataโ€‹

FieldValue
Test IDAD-FOR-02
SeverityInfo
SuiteActive Directory
CategoryAD.Forest
PowerShell testTest-MtAdForestDomainCount
TagsAD, AD-FOR-02, AD.Forest

Sourceโ€‹

  • Pester test: tests/ad/domain/Test-MtAdForestDomainCount.Tests.ps1
  • PowerShell source: powershell/public/ad/domain/Test-MtAdForestDomainCount.ps1