AD-OU-01 - OU overlapping name count should be retrievable
Overviewโ
- Organizational Units with overlapping (duplicate) names can create administrative confusion and operational risks in Active Directory:
- Administrative errors: Administrators may inadvertently apply Group Policies, permissions, or settings to the wrong OU when multiple OUs share the same name
- Scripting complications: Automation scripts that reference OUs by name may target incorrect containers
- Policy application issues: Group Policy links may be applied to unintended OUs
- Audit confusion: Security audits and compliance reports become harder to interpret when OU names are ambiguous
- While Active Directory technically allows duplicate OU names (as long as they're in different locations), this practice should be minimized to reduce operational risk.
Security Recommendationโ
-
Review OUs with duplicate names and consider renaming them to be more descriptive and unique. Use naming conventions that incorporate location, function, or department to make OU names unambiguous. For example:
-
Instead of multiple "Users" OUs, use "NYC-Users", "LA-Users", "London-Users"
-
Instead of multiple "Servers" OUs, use "Production-Servers", "Test-Servers", "Dev-Servers"
How the Test Worksโ
- This test retrieves all Organizational Units from Active Directory and:
- Groups OUs by their Name property
- Identifies names that appear more than once
- Counts the number of duplicate name groups
- Lists all OUs that share names with other OUs
Related Testsโ
Test-MtAdOuAtDomainRootCount- Analyzes OU structure at the domain root levelTest-MtAdOuEmptyCount- Identifies OUs that contain no objects
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-OU-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.OU |
| PowerShell test | Test-MtAdOuOverlappingNameCount |
| Tags | AD, AD-OU-01, AD.OU |
Sourceโ
- Pester test:
tests/ad/ou/Test-MtAdOuOverlappingNameCount.Tests.ps1 - PowerShell source:
powershell/public/ad/ou/Test-MtAdOuOverlappingNameCount.ps1

