AD-GPOL-04 - Enforced GPO link count should be retrievable
Overviewβ
Enforced Group Policy Object (GPO) links are special link entries that block inheritance from being overridden at lower levels (for example, by child OUs).
This can be a powerful mechanism for security baselines, but it also increases the chance that a critical policy unintentionally becomes βstickyβ across the domain.
Security Recommendationβ
- Enforced GPOs override inheritance blocking: any configuration enforced at a higher scope can still apply even if child OUs attempt to disable inheritance.
- Use enforced links sparingly: reserve them for critical security policies that must apply everywhere.
- Review enforced policies regularly: confirm the GPOβs purpose and ownership, and ensure the enforced settings remain aligned with current security requirements.
How the Test Worksβ
This test retrieves Active Directory GPO state from Get-MtADGpoState (using $gpoState.GPOLinks) and:
- Examines each collected link object for the
Enforcedproperty. - Counts link entries where
Enforcedis$true. - Reports the enforced link count and the enforced ratio in Markdown.
Related Testsβ
Test-MtAdGpoTotalCount- Counts total GPO inventoryTest-MtAdGpoLinkedCount- Identifies GPOs that are actively linkedTest-MtAdGpoUnlinkedCount- Identifies GPOs not linked anywhereTest-MtAdGpoUnlinkedDetails- Shows unlinked GPO details
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GPOL-04 |
| Severity | Unknown |
| Suite | Active Directory |
| Category | AD.GPO |
| PowerShell test | Test-MtAdGpoEnforcedCount |
| Tags | AD, AD-GPOL-04, AD.GPO |
Sourceβ
- Pester test:
tests/ad/gpo/Test-MtAdGpoEnforcedCount.Tests.ps1 - PowerShell source:
powershell/public/ad/gpo/Test-MtAdGpoEnforcedCount.ps1

