Skip to main content
Version: 2.2.1-preview

AD-GMC-02 - Distinct account types of members count should be retrievable

Overviewโ€‹

  • Understanding the types of objects that can be group members helps assess Active Directory security posture:
  • Security Principal Types: Groups can contain users, groups, computers, and foreign security principals
  • Nested Groups: Groups containing other groups create inheritance chains that can be complex to audit
  • Computer Membership: Computers in groups may indicate service accounts or special access requirements
  • Foreign Principals: External domain members represent trust relationships that extend beyond the local domain

Security Recommendationโ€‹

  • Monitor group membership composition:
  • Nested group membership can create unexpected access paths
  • Foreign security principals indicate cross-domain access that should be regularly reviewed
  • Computer accounts in sensitive groups may indicate misconfigurations

How the Test Worksโ€‹

  • This test analyzes group membership across Active Directory and:
  • Identifies distinct object classes among group members
  • Counts unique account types (user, group, computer, foreignSecurityPrincipal)
  • Provides visibility into membership composition

For performance reasons, the test analyzes members from the first 50 groups and deduplicates by SID.

  • Test-MtAdGroupMemberAccountTypeDetails - Detailed breakdown of account types
  • Test-MtAdGroupMemberForeignSidCount - Identifies foreign security principals specifically

Test Metadataโ€‹

FieldValue
Test IDAD-GMC-02
SeverityInfo
SuiteActive Directory
CategoryAD.Group
PowerShell testTest-MtAdGroupMemberAccountTypeCount
TagsAD, AD-GMC-02, AD.Group

Sourceโ€‹

  • Pester test: tests/ad/group/Test-MtAdGroupMemberAccountTypeCount.Tests.ps1
  • PowerShell source: powershell/public/ad/group/Test-MtAdGroupMemberAccountTypeCount.ps1