AD-FORS-02 - UPN suffixes details should be retrievable
Overviewβ
Detailed visibility into UPN (User Principal Name) suffix configuration is essential for maintaining a secure and well-managed Active Directory environment. UPN suffixes directly impact:
- User Authentication: Users log on with UPN format ([email protected]), making suffix configuration critical for daily operations
- Multi-Domain Environments: Organizations with multiple domains or brands rely on UPN suffixes for seamless authentication
- Security Boundaries: Understanding configured UPN suffixes helps identify potential authentication attack surfaces
- Operational Continuity: During domain migrations or consolidations, UPN suffix management ensures user authentication continuity
Security Recommendationβ
Based on the UPN suffix details retrieved:
- Audit Regularly: Review the list of UPN suffixes quarterly to ensure they align with current business requirements
- Remove Unused Suffixes: Delete UPN suffixes from divested business units or completed migration projects
- Document Changes: Maintain documentation of why each UPN suffix exists and which business unit owns it
- Monitor for Unauthorized Additions: Unexpected UPN suffixes could indicate compromise or unauthorized administrative activity
How the Test Worksβ
This test retrieves the complete list of UPN suffixes configured at the forest level. It displays each suffix individually, allowing administrators to review the complete authentication namespace configuration. The test uses Get-ADForest to access the UPNSuffixes property.
Related Testsβ
Test-MtAdUpnSuffixesCount- Provides a count of configured UPN suffixesTest-MtAdSpnSuffixesCount- Checks SPN suffix configuration
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-FORS-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Forest |
| PowerShell test | Test-MtAdUpnSuffixesDetails |
| Tags | AD, AD-FORS-02, AD.Forest |
Sourceβ
- Pester test:
tests/ad/domain/Test-MtAdUpnSuffixesDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdUpnSuffixesDetails.ps1

