AD-TRUST-04 - Trust non-quarantined details should be retrievable
Overviewβ
Non-quarantined trusts (those without SID filtering) are a significant security risk:
- SID History Vulnerability: Attackers can exploit SID history to elevate privileges across trust boundaries
- Privilege Escalation Path: Compromised external accounts can gain access to privileged resources
- Audit Finding: Most security audits flag non-quarantined external trusts as high-risk
- Compliance Gap: Fails compliance requirements for many security frameworks
This test specifically identifies which trusts lack SID filtering, enabling targeted remediation.
Security Recommendationβ
Immediate Actions:
- Review each non-quarantined trust to determine if SID filtering can be enabled
- Test applications that rely on cross-trust authentication before enabling SID filtering
- Enable SID filtering on all inter-forest trusts where possible
Long-term Strategy:
- Replace external trusts with forest trusts where possible
- Implement selective authentication for sensitive resources
- Regularly audit trust configurations
- Document any trusts that must remain non-quarantined with business justification
Command to Enable SID Filtering:
Set-ADTrust -Target <TrustName> -Quarantine $true
How the Test Worksβ
This test filters trust objects where Quarantined is $false and displays:
- Target domain of the trust
- Trust direction (Inbound, Outbound, or Bidirectional)
- Whether it's an intra-forest or inter-forest trust
- Trust type (External, Forest, or Kerberos)
Related Testsβ
Test-MtAdTrustQuarantinedCount- Count of quarantined vs non-quarantined trustsTest-MtAdTrustInterForestCount- Identifies external trusts that should be quarantinedTest-MtAdTrustDetails- Complete trust configuration details
Related linksβ
- Microsoft Learn: Security considerations for trusts
- ANSSI Active Directory checkpoints: Unfiltered outbound domain trust relationship
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-TRUST-04 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.Trust |
| PowerShell test | Test-MtAdTrustNonQuarantinedDetails |
| Tags | AD, AD-TRUST-04, AD.Trust |
Sourceβ
- Pester test:
tests/ad/trust/Test-MtAdTrustNonQuarantinedDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/trust/Test-MtAdTrustNonQuarantinedDetails.ps1


