AD-SUB-03 - Catch-all subnets count should be retrievable
Overviewโ
Catch-all subnets (overly broad IP ranges) can cause:
- Authentication inefficiency: Clients may authenticate to distant DCs
- WAN congestion: Unnecessary cross-site authentication traffic
- Security concerns: Difficult to track and audit client locations
- Operational confusion: Site boundaries don't reflect actual topology
Common catch-all subnets include 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16.
Security Recommendationโ
- Replace catch-all subnets with specific, appropriately-sized subnets
- Use /24 or smaller subnets for most locations
- Document exceptions where catch-all subnets are intentionally used
- Review subnet definitions during network planning
How the Test Worksโ
This test identifies subnets with overly broad CIDR notation that could encompass multiple physical locations.
Related Testsโ
Test-MtAdSubnetNonInternalCount- Identifies public IP subnetsTest-MtAdSubnetTotalCount- Counts total subnetsTest-MtAdSiteWithoutSubnetCount- Identifies sites without subnets
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-SUB-03 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Site |
| PowerShell test | Test-MtAdSubnetCatchAllCount |
| Tags | AD, AD-SUB-03, AD.Site |
Sourceโ
- Pester test:
tests/ad/site/Test-MtAdSubnetCatchAllCount.Tests.ps1 - PowerShell source:
powershell/public/ad/site/Test-MtAdSubnetCatchAllCount.ps1

