Skip to main content
Version: 2.2.1-preview

AD-GMC-09 - Empty non-privileged group details should be retrievable

Overviewโ€‹

Detailed visibility into empty non-privileged groups enables effective cleanup:

  • Identification: Lists specific groups that can be removed
  • Age assessment: Shows creation and modification dates to determine staleness
  • Categorization: Groups by type (security vs. distribution) and scope
  • Cleanup planning: Provides data needed for maintenance windows
  • Audit trail: Documents what was empty before cleanup

Security Recommendationโ€‹

Before removing empty groups:

  • Verify groups are not referenced by applications or scripts
  • Check if groups are used in Group Policy or Conditional Access
  • Document groups before deletion for potential rollback
  • Consider disabling groups first before permanent deletion
  • Communicate with application owners about group dependencies
  • Maintain a log of cleaned groups for compliance purposes

How the Test Worksโ€‹

This test identifies all Active Directory groups that:

  1. Have no members
  2. Do not have adminCount = 1

It then lists these groups with their:

  • Name
  • Group scope (DomainLocal, Global, Universal)
  • Group category (Security, Distribution)
  • Creation date
  • Last modification date
  • Test-MtAdGroupEmptyNonPrivilegedCount - Counts empty non-privileged groups
  • Test-MtAdGroupPrivilegedWithMembersDetails - Reviews privileged group memberships

Test Metadataโ€‹

FieldValue
Test IDAD-GMC-09
SeverityInfo
SuiteActive Directory
CategoryAD.Group
PowerShell testTest-MtAdGroupEmptyNonPrivilegedDetails
TagsAD, AD-GMC-09, AD.GMC, AD.Group

Sourceโ€‹

  • Pester test: tests/ad/group/Test-MtAdGroupEmptyNonPrivilegedDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/group/Test-MtAdGroupEmptyNonPrivilegedDetails.ps1