AD-GPOL-01 - GPO linked count should be retrievable
Overviewโ
Linked Group Policy Objects (GPOs) are actively applying settings to users and/or computers across your Active Directory environment.
For security assessments, it is important to understand the scope of actively linked (and therefore applying) policies. This test helps you:
- Identify the ratio of active vs unused policies
- Spot environments where many GPOs exist but only a subset are actually applied
- Prioritize review/cleanup efforts based on real policy exposure
Security Recommendationโ
- Review linked (active) GPOs regularly: Linked policies can change security posture immediately when modified.
- Audit unused/unlinked GPOs: Large numbers of unused policies can indicate mismanagement and increase the risk of accidental changes.
- Use the linked ratio: A low linked ratio might indicate policy sprawl or a backlog of orphaned policies.
How the Test Worksโ
This test retrieves GPO state from Active Directory using Get-MtADGpoState (it uses $gpoState.GPOs and $gpoState.GPOLinks).
It then:
- Parses
gPLinkvalues to identify enabled (0) and enforced (2) link entries. - Counts distinct GPO GUIDs that have at least one enabled link.
- Compares linked GPO count vs total GPO count and reports both metrics in Markdown.
Related Testsโ
Test-MtAdGpoTotalCount- Total GPO inventoryTest-MtAdGpoUnlinkedCount- GPOs not linked anywhereTest-MtAdGpoCreatedBefore2020Count- Potentially legacy GPOsTest-MtAdGpoChangedBefore2020Count- Potentially stale GPOs
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-GPOL-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.GPO |
| PowerShell test | Test-MtAdGpoLinkedCount |
| Tags | AD, AD-GPOL-01, AD.GPO |
Sourceโ
- Pester test:
tests/ad/gpo/Test-MtAdGpoLinkedCount.Tests.ps1 - PowerShell source:
powershell/public/ad/gpo/Test-MtAdGpoLinkedCount.ps1

