AD-GRP-01 - Group AdminCount should be retrievable
Overviewโ
The AdminCount attribute is a critical Active Directory security marker that indicates a group is considered "protected" by the system. Groups with AdminCount set receive special security protections that prevent delegation of administrative privileges through inheritance. This test helps identify:
- Privileged groups: Groups that are members of protected groups like Domain Admins, Enterprise Admins, or Schema Admins
- Security inheritance issues: Groups that may have broken inheritance due to AdminCount settings
- Audit targets: Groups requiring enhanced monitoring due to their administrative nature
- Delegation challenges: Groups that cannot receive permissions through normal inheritance
Security Recommendationโ
- Review all groups with AdminCount set to ensure they still require elevated privileges
- Remove groups from protected groups if they no longer need administrative access
- Be aware that removing a group from a protected group does not automatically clear the AdminCount attribute
- Manually clear AdminCount for groups that should no longer be protected
- Monitor changes to AdminCount attributes as they indicate privilege escalation
How the Test Worksโ
This test retrieves all group objects from Active Directory and counts:
- Total number of groups
- Number of groups with AdminCount attribute set (non-null and greater than 0)
- Percentage of groups with AdminCount
Related Testsโ
Test-MtAdGroupWithManagerCount- Identifies groups with delegated managementTest-MtAdGroupSidHistoryCount- Finds groups migrated from other domains
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-GRP-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupAdminCount |
| Tags | AD, AD-GRP-01, AD.Group |
Sourceโ
- Pester test:
tests/ad/group/Test-MtAdGroupAdminCount.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupAdminCount.ps1

