Skip to main content
Version: 2.2.1-preview

AD-OU-01 - OU overlapping name count should be retrievable

Overviewโ€‹

  • Organizational Units with overlapping (duplicate) names can create administrative confusion and operational risks in Active Directory:
  • Administrative errors: Administrators may inadvertently apply Group Policies, permissions, or settings to the wrong OU when multiple OUs share the same name
  • Scripting complications: Automation scripts that reference OUs by name may target incorrect containers
  • Policy application issues: Group Policy links may be applied to unintended OUs
  • Audit confusion: Security audits and compliance reports become harder to interpret when OU names are ambiguous
  • While Active Directory technically allows duplicate OU names (as long as they're in different locations), this practice should be minimized to reduce operational risk.

Security Recommendationโ€‹

  • Review OUs with duplicate names and consider renaming them to be more descriptive and unique. Use naming conventions that incorporate location, function, or department to make OU names unambiguous. For example:

  • Instead of multiple "Users" OUs, use "NYC-Users", "LA-Users", "London-Users"

  • Instead of multiple "Servers" OUs, use "Production-Servers", "Test-Servers", "Dev-Servers"

How the Test Worksโ€‹

  • This test retrieves all Organizational Units from Active Directory and:
  • Groups OUs by their Name property
  • Identifies names that appear more than once
  • Counts the number of duplicate name groups
  • Lists all OUs that share names with other OUs
  • Test-MtAdOuAtDomainRootCount - Analyzes OU structure at the domain root level
  • Test-MtAdOuEmptyCount - Identifies OUs that contain no objects

Test Metadataโ€‹

FieldValue
Test IDAD-OU-01
SeverityInfo
SuiteActive Directory
CategoryAD.OU
PowerShell testTest-MtAdOuOverlappingNameCount
TagsAD, AD-OU-01, AD.OU

Sourceโ€‹

  • Pester test: tests/ad/ou/Test-MtAdOuOverlappingNameCount.Tests.ps1
  • PowerShell source: powershell/public/ad/ou/Test-MtAdOuOverlappingNameCount.ps1