AD-GRP-09 - Global group count should be retrievable
Overviewโ
Global groups are the most commonly used group type for organizing users in Active Directory:
- User organization: Used to organize users by role, department, or function
- Forest-wide usage: Can be used across the entire forest for access control
- Domain replication: Group membership only replicates within the domain, reducing replication traffic
- AGDLP/AGUDLP strategy: Accounts are placed into Global groups as the first step in the recommended group nesting strategy
A high number of global groups typically indicates well-organized user role management.
Security Recommendationโ
Optimize global group usage:
- Use global groups to organize users by role, department, or business function
- Keep global group membership relatively stable to minimize replication
- Nest global groups into domain local or universal groups for resource access
- Avoid assigning permissions directly to global groupsโuse them as user containers
- Implement a naming convention that reflects the group's purpose (e.g., "G-Department-Finance")
How the Test Worksโ
This test examines all group objects and identifies those where:
- The
GroupScopeproperty equals "Global" - These groups can contain users and other global groups from the same domain
- Membership changes only replicate within the domain
The test provides counts and percentages to understand the distribution of group scopes in your environment.
Related Testsโ
Test-MtAdGroupDistributionCount- Counts distribution groups (email-only)Test-MtAdGroupSecurityCount- Counts security groups by categoryTest-MtAdGroupDomainLocalCount- Counts domain local scope groupsTest-MtAdGroupUniversalCount- Counts universal scope groups
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-GRP-09 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupGlobalCount |
| Tags | AD, AD-GRP-09, AD.Group |
Sourceโ
- Pester test:
tests/ad/group/Test-MtAdGroupGlobalCount.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupGlobalCount.ps1

