AD-GPO-04 - Unlinked GPO count should be compliant
Overviewβ
Unlinked (or orphaned) Group Policy Objects (GPOs) exist in Active Directory but are not linked to any OU, domain, or site. While they may look harmless, they can still create operational and security risk:
- Resource and operational overhead: Unused GPOs add clutter and can increase administrative effort.
- Accidental exposure: An unlinked GPO can be mistakenly linked later, suddenly applying unknown settings to users or computers.
- Harder incident investigation: Policy behavior becomes harder to reason about when unused GPOs remain in the environment.
Security Recommendationβ
After verification, remove unlinked GPOs to reduce risk and simplify policy management:
- Confirm the GPOβs purpose (documentation, change history, owners).
- Verify it is not required for any special-case deployment path.
- If you are confident it is unused, remove it (or archive it) and ensure backups/restore requirements are met.
- Restrict who can create/link GPOs to prevent accidental re-introduction.
How the Test Worksβ
This test retrieves Active Directory Group Policy state data using Get-MtADGpoState and:
- Uses the cached list of GPOs (
$gpoState.GPOs). - Extracts GPO link references from the collected
GPOLinks(viagPLink). - Counts GPOs whose IDs are not referenced by any collected
gPLinkentry.
Related Testsβ
Test-MtAdGpoTotalCount- Counts the total number of GPOsTest-MtAdGpoLinkedCount- Identifies GPOs that are actively linkedTest-MtAdGpoCreatedBefore2020Count- Identifies potentially outdated GPOs
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GPO-04 |
| Severity | Unknown |
| Suite | Active Directory |
| Category | AD.GPO |
| PowerShell test | Test-MtAdGpoUnlinkedCount |
| Tags | AD, AD-GPO-04, AD.GPO |
Sourceβ
- Pester test:
tests/ad/gpo/Test-MtAdGpoUnlinkedCount.Tests.ps1 - PowerShell source:
powershell/public/ad/gpo/Test-MtAdGpoUnlinkedCount.ps1

