AD-GMC-02 - Distinct account types of members count should be retrievable
Overviewโ
- Understanding the types of objects that can be group members helps assess Active Directory security posture:
- Security Principal Types: Groups can contain users, groups, computers, and foreign security principals
- Nested Groups: Groups containing other groups create inheritance chains that can be complex to audit
- Computer Membership: Computers in groups may indicate service accounts or special access requirements
- Foreign Principals: External domain members represent trust relationships that extend beyond the local domain
Security Recommendationโ
- Monitor group membership composition:
- Nested group membership can create unexpected access paths
- Foreign security principals indicate cross-domain access that should be regularly reviewed
- Computer accounts in sensitive groups may indicate misconfigurations
How the Test Worksโ
- This test analyzes group membership across Active Directory and:
- Identifies distinct object classes among group members
- Counts unique account types (user, group, computer, foreignSecurityPrincipal)
- Provides visibility into membership composition
For performance reasons, the test analyzes members from the first 50 groups and deduplicates by SID.
Related Testsโ
Test-MtAdGroupMemberAccountTypeDetails- Detailed breakdown of account typesTest-MtAdGroupMemberForeignSidCount- Identifies foreign security principals specifically
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-GMC-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupMemberAccountTypeCount |
| Tags | AD, AD-GMC-02, AD.Group |
Sourceโ
- Pester test:
tests/ad/group/Test-MtAdGroupMemberAccountTypeCount.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupMemberAccountTypeCount.ps1

