AD-GMC-08 - Empty non-privileged group count should be retrievable
Overviewโ
Empty groups that are not privileged (no adminCount) represent directory clutter that should be addressed:
- Directory hygiene: Unused groups create noise and confusion in access management
- Audit complexity: Empty groups increase the surface area for security audits
- Change tracking: Groups created for temporary purposes but never cleaned up
- Operational efficiency: Simplifies group management and reduces confusion
- Potential risks: Empty groups could be populated unexpectedly
Security Recommendationโ
Implement a regular cleanup process:
- Review empty non-privileged groups quarterly
- Establish group lifecycle policies (creation, usage, retirement)
- Document exceptions for empty groups that must be preserved
- Consider automated cleanup for groups empty for extended periods
- Maintain an exceptions list for groups required by applications
How the Test Worksโ
This test iterates through all Active Directory groups, checks their membership count, and identifies groups that:
- Have no members
- Do not have adminCount = 1 (not privileged groups protected by AdminSDHolder)
The test categorizes groups by their status (empty privileged, empty non-privileged, with members).
Related Testsโ
Test-MtAdGroupEmptyNonPrivilegedDetails- Lists specific empty non-privileged groupsTest-MtAdGroupPrivilegedWithMembersCount- Reviews privileged groups with members
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-GMC-08 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupEmptyNonPrivilegedCount |
| Tags | AD, AD-GMC-08, AD.GMC, AD.Group |
Sourceโ
- Pester test:
tests/ad/group/Test-MtAdGroupEmptyNonPrivilegedCount.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupEmptyNonPrivilegedCount.ps1

