AD-TRUST-01 - Trust total count should be retrievable
Overviewβ
Domain trusts are critical security boundaries in Active Directory environments. Understanding the number and configuration of trusts is essential for:
- Security Assessment: Knowing how many external entities can authenticate in your environment
- Attack Surface Management: Each trust represents a potential attack vector that needs monitoring
- Compliance Reporting: Many frameworks require documentation of trust relationships
- Operational Visibility: Understanding cross-domain authentication paths
Trusts allow users from one domain to access resources in another. While necessary for multi-domain environments, unnecessary or misconfigured trusts can create security vulnerabilities.
Security Recommendationβ
- Inventory: Maintain an inventory of all trust relationships and their purposes
- Regular Review: Periodically review trusts to ensure they are still needed
- Documentation: Document the business justification for each trust
- Monitoring: Monitor trust validation status and authentication events
- Principle of Least Privilege: Only create trusts when absolutely necessary
How the Test Worksβ
This test retrieves all trust objects from Active Directory using Get-ADTrust and counts the total number of configured trusts. The test returns:
- Total count of trusts
- Informational result (no pass/fail criteria)
Related Testsβ
Test-MtAdTrustInterForestCount- Identifies external/inter-forest trustsTest-MtAdTrustQuarantinedCount- Checks for SID filtering on trustsTest-MtAdTrustStaleCount- Identifies trusts not validated recentlyTest-MtAdTrustDetails- Provides detailed trust configuration information
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-TRUST-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Trust |
| PowerShell test | Test-MtAdTrustTotalCount |
| Tags | AD, AD-TRUST-01, AD.Trust |
Sourceβ
- Pester test:
tests/ad/trust/Test-MtAdTrustTotalCount.Tests.ps1 - PowerShell source:
powershell/public/ad/trust/Test-MtAdTrustTotalCount.ps1

