AD-GPOL-05 - GPO blocked inheritance count should be compliant
Overview
GPO inheritance blocking controls whether settings from parent Organizational Units (OUs) flow down to child OUs. When inheritance is blocked on an OU, policies from higher-level scopes won’t apply as expected.
For security assessments, this matters because inheritance blocking can create security gaps:
- Parent OU policies won’t apply to the affected OUs.
- Security baselines can become inconsistent across the directory.
- “Sticky” configurations at lower levels can persist unnoticed.
Security Recommendation
- Review blocked inheritance regularly: confirm each OU blocking inheritance has a documented business/technical justification.
- Ensure compensating controls exist: if parent policies won’t apply, equivalent security settings must be configured directly where needed.
- Monitor and alert on changes: inheritance blocking is often changed unintentionally during OU restructuring or delegation work.
How the Test Works
This test retrieves Organizational Units (OUs) from Active Directory using:
Get-ADOrganizationalUnit -Filter * -Properties gpOptions- Counts OUs where
gpOptions -eq 1(wheregpOptionsindicates GPO inheritance blocking). - Reports the total OU count, the number of blocked OUs, and the blocked ratio in Markdown.
Related Tests
Test-MtAdGpoEnforcedCount- Counts enforced (inheritance-blocking) link entriesTest-MtAdGpoLinkedCount- Counts GPOs actively linked to apply settingsTest-MtAdGpoUnlinkedCount- Identifies unlinked/orphaned GPOs
Test Metadata
| Field | Value |
|---|---|
| Test ID | AD-GPOL-05 |
| Severity | Unknown |
| Suite | Active Directory |
| Category | AD.GPO |
| PowerShell test | Test-MtAdGpoBlockedInheritanceCount |
| Tags | AD, AD-GPOL-05, AD.GPO |
Source
- Pester test:
tests/ad/gpo/Test-MtAdGpoBlockedInheritanceCount.Tests.ps1 - PowerShell source:
powershell/public/ad/gpo/Test-MtAdGpoBlockedInheritanceCount.ps1

