AD-GRP-10 - Universal group count should be retrievable
Overviewβ
Universal groups play a specific role in multi-domain Active Directory environments:
- Cross-domain flexibility: Can contain users and groups from any domain in the forest
- Forest-wide access: Can be used for access control across the entire forest
- Global Catalog storage: Group membership is stored in the Global Catalog
- Replication impact: Membership changes trigger forest-wide replication
- Multi-domain consolidation: Useful for nesting global groups from multiple domains
High numbers of universal groups may indicate a complex multi-domain environment or potential replication optimization opportunities.
Security Recommendationβ
Use universal groups strategically:
- Minimize membership changes to universal groups to reduce replication traffic
- Use universal groups primarily in multi-domain environments where cross-domain access is needed
- Nest global groups (containing users) into universal groups rather than adding users directly
- Consider the replication impact when designing universal group structure
- Document the forest-wide access each universal group provides
- In single-domain environments, prefer global and domain local groups
How the Test Worksβ
This test examines all group objects and identifies those where:
- The
GroupScopeproperty equals "Universal" - These groups can contain members from any domain in the forest
- Membership is stored in the Global Catalog
The test provides counts and percentages to understand the distribution of group scopes in your environment.
Related Testsβ
Test-MtAdGroupDistributionCount- Counts distribution groups (email-only)Test-MtAdGroupSecurityCount- Counts security groups by categoryTest-MtAdGroupDomainLocalCount- Counts domain local scope groupsTest-MtAdGroupGlobalCount- Counts global scope groups
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GRP-10 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupUniversalCount |
| Tags | AD, AD-GRP-10, AD.Group |
Sourceβ
- Pester test:
tests/ad/group/Test-MtAdGroupUniversalCount.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupUniversalCount.ps1

