AD-GMC-09 - Empty non-privileged group details should be retrievable
Overviewโ
Detailed visibility into empty non-privileged groups enables effective cleanup:
- Identification: Lists specific groups that can be removed
- Age assessment: Shows creation and modification dates to determine staleness
- Categorization: Groups by type (security vs. distribution) and scope
- Cleanup planning: Provides data needed for maintenance windows
- Audit trail: Documents what was empty before cleanup
Security Recommendationโ
Before removing empty groups:
- Verify groups are not referenced by applications or scripts
- Check if groups are used in Group Policy or Conditional Access
- Document groups before deletion for potential rollback
- Consider disabling groups first before permanent deletion
- Communicate with application owners about group dependencies
- Maintain a log of cleaned groups for compliance purposes
How the Test Worksโ
This test identifies all Active Directory groups that:
- Have no members
- Do not have adminCount = 1
It then lists these groups with their:
- Name
- Group scope (DomainLocal, Global, Universal)
- Group category (Security, Distribution)
- Creation date
- Last modification date
Related Testsโ
Test-MtAdGroupEmptyNonPrivilegedCount- Counts empty non-privileged groupsTest-MtAdGroupPrivilegedWithMembersDetails- Reviews privileged group memberships
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-GMC-09 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupEmptyNonPrivilegedDetails |
| Tags | AD, AD-GMC-09, AD.GMC, AD.Group |
Sourceโ
- Pester test:
tests/ad/group/Test-MtAdGroupEmptyNonPrivilegedDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupEmptyNonPrivilegedDetails.ps1


