AD-GRP-06 - Distribution group count should be retrievable
Overviewβ
Distribution groups are email-only groups used for Exchange and email distribution lists. Understanding their count and proportion helps:
- Email infrastructure assessment: Provides visibility into the email distribution infrastructure
- Security boundary awareness: Distinguishes email-only groups from security groups that control access
- Exchange management: Helps assess Exchange/Exchange Online integration and email distribution complexity
- Migration planning: Useful when planning migrations to Exchange Online or other email systems
Distribution groups cannot be used for access controlβthey are purely for email functionality.
Security Recommendationβ
Regularly review distribution groups to:
- Identify and remove stale or unused distribution lists
- Ensure sensitive distribution groups have appropriate ownership
- Verify that distribution groups are not being used inappropriately for security purposes
- Consider converting distribution groups to Office 365 Groups where appropriate for modern collaboration
How the Test Worksβ
This test examines all group objects and identifies those where:
- The
GroupCategoryproperty equals "Distribution" - These groups are used solely for email distribution, not access control
The test provides counts and percentages to understand the distribution of group types in your environment.
Related Testsβ
Test-MtAdGroupSecurityCount- Counts security groups used for access controlTest-MtAdGroupDomainLocalCount- Counts domain local scope groupsTest-MtAdGroupGlobalCount- Counts global scope groupsTest-MtAdGroupUniversalCount- Counts universal scope groups
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GRP-06 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupDistributionCount |
| Tags | AD, AD-GRP-06, AD.Group |
Sourceβ
- Pester test:
tests/ad/group/Test-MtAdGroupDistributionCount.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupDistributionCount.ps1

