AD-GPO-05 - GPO unlinked details should be compliant
Overviewโ
Unlinked Group Policy Objects (GPOs) are policies that exist in Active Directory but are not linked to any site, domain, or organizational unit (OU). Even when unlinked, these GPOs still represent configuration artifacts that can create operational overhead and increase risk.
- Security risk: Unused policies may still contain insecure settings that could be re-enabled accidentally.
- Operational complexity: GPO sprawl makes it harder to reason about what policies actually apply.
- Maintenance hygiene: Tracking unlinked GPOs supports safe cleanup and ongoing policy governance.
Security Recommendationโ
Review the returned unlinked GPOs and consider removing those that are no longer needed.
This reduces the attack surface by removing unused policies that could be re-linked or misconfigured in the future.
How the Test Worksโ
This test uses Get-MtADGpoState to retrieve cached GPO data ($gpoState.GPOs). It then identifies unlinked
GPOs and generates a markdown table containing:
- GPO DisplayName
- CreationTime
- ModificationTime
The table is intended to support quick review during GPO cleanup and maintenance activities.
Related Testsโ
Test-MtAdGpoUnlinkedCount- Identifies how many GPOs are not linked to any locationTest-MtAdGpoLinkedCount- Counts GPOs that are actively linkedTest-MtAdGpoTotalCount- Counts the total number of GPOs in the domain
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-GPO-05 |
| Severity | Unknown |
| Suite | Active Directory |
| Category | AD.GPO |
| PowerShell test | Test-MtAdGpoUnlinkedDetails |
| Tags | AD, AD-GPO-05, AD.GPO |
Sourceโ
- Pester test:
tests/ad/gpo/Test-MtAdGpoUnlinkedDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/gpo/Test-MtAdGpoUnlinkedDetails.ps1

