Skip to main content
Version: 2.2.1-preview

AD-GPOL-06 - GPO linked OU count should be retrievable

Overviewโ€‹

Understanding the distribution of GPO links across Organizational Units is important for several security reasons:

  • Policy Coverage: Identifies OUs that may lack necessary security policies
  • Compliance Assessment: Helps ensure all organizational units receive appropriate policy coverage
  • Security Gaps: OUs without GPO links may rely solely on domain-level policies, potentially missing OU-specific security controls
  • Policy Management: Provides visibility into how broadly GPOs are deployed across the directory structure

Security Recommendationโ€‹

Review OUs without GPO links to ensure:

  • They inherit appropriate policies from parent containers
  • They don't require OU-specific security policies
  • Critical security settings are not being missed
  • Consider creating OU-specific policies for organizational units with unique security requirements

How the Test Worksโ€‹

This test retrieves all Organizational Units from Active Directory and counts:

  • Total number of OUs in the domain
  • Number of OUs with GPO links (gPLink attribute is populated)
  • Number of OUs without GPO links

The gPLink attribute is checked to determine if any GPOs are linked to each OU.

  • Test-MtAdGpoLinkedCount - Counts distinct GPOs with links
  • Test-MtAdGpoUnlinkedTargetCount - Counts targets without GPO links
  • Test-MtAdComputerOUCount - Counts distinct OUs containing computers

Test Metadataโ€‹

FieldValue
Test IDAD-GPOL-06
SeverityInfo
SuiteActive Directory
CategoryAD.GPO
PowerShell testTest-MtAdGpoLinkedOUCount
TagsAD, AD-GPOL-06, AD.GPO

Sourceโ€‹

  • Pester test: tests/ad/gpo/Test-MtAdGpoLinkedOUCount.Tests.ps1
  • PowerShell source: powershell/public/ad/gpo/Test-MtAdGpoLinkedOUCount.ps1