AD-GRP-07 - Security group count should be retrievable
Overviewβ
Security groups are the foundation of access control in Active Directory. Understanding their count and distribution is critical for:
- Access management assessment: High numbers of security groups may indicate complex or poorly managed permissions
- Security auditing: Security groups directly control who can access what resources
- Privilege analysis: Helps identify the scale of group-based access control to audit
- Compliance requirements: Many frameworks require documentation and regular review of security groups
Security groups can be assigned permissions to resources, unlike distribution groups.
Security Recommendationβ
Establish governance around security groups:
- Implement a naming convention for security groups to improve manageability
- Regularly audit security group memberships, especially for privileged groups
- Document the purpose and owner of each security group
- Remove unused or stale security groups to reduce attack surface
- Consider implementing privileged access management for highly sensitive groups
How the Test Worksβ
This test examines all group objects and identifies those where:
- The
GroupCategoryproperty equals "Security" - These groups can be assigned permissions and used for access control
The test provides counts and percentages to understand the proportion of security groups versus distribution groups.
Related Testsβ
Test-MtAdGroupDistributionCount- Counts distribution groups (email-only)Test-MtAdGroupDomainLocalCount- Counts domain local scope groupsTest-MtAdGroupGlobalCount- Counts global scope groupsTest-MtAdGroupUniversalCount- Counts universal scope groups
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GRP-07 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupSecurityCount |
| Tags | AD, AD-GRP-07, AD.Group |
Sourceβ
- Pester test:
tests/ad/group/Test-MtAdGroupSecurityCount.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupSecurityCount.ps1

