AD-GMC-07 - Foreign SID details by domain should be retrievable
Overviewβ
Foreign security principals (FSPs) represent security principals from trusted external domains or forests. Understanding their distribution is important because:
- Trust visibility: Identifies external trusts that may have been forgotten or are no longer needed
- Security boundaries: Helps assess the blast radius if an external domain is compromised
- Access control: Reveals who has access to resources from outside the domain
- Cleanup opportunities: May highlight groups that can be cleaned up after domain migrations
Security Recommendationβ
Regularly review foreign security principals:
- Remove memberships from domains that are no longer trusted
- Audit groups containing external accounts for appropriate access levels
- Document all domain trusts and their business justifications
- Consider converting external access to local accounts where appropriate
- Monitor for unexpected foreign principal additions
How the Test Worksβ
This test examines all group memberships in Active Directory and identifies security principals with SIDs that don't match the local domain SID. It groups these foreign principals by their domain SID and counts how many exist from each external domain.
Related Testsβ
Test-MtAdGroupMemberForeignSidCount- Counts total foreign security principalsTest-MtAdGroupPrivilegedWithMembersDetails- Reviews privileged group memberships
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GMC-07 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupMemberForeignSidDetails |
| Tags | AD, AD-GMC-07, AD.GMC, AD.Group |
Sourceβ
- Pester test:
tests/ad/group/Test-MtAdGroupMemberForeignSidDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupMemberForeignSidDetails.ps1

