Skip to main content
Version: 2.2.1-preview

AD-TRUST-05 - Trust configuration details should be retrievable

Overviewโ€‹

Comprehensive trust documentation is essential for security operations:

  • Security Audits: Auditors require detailed trust configuration information
  • Incident Response: Understanding trust relationships helps during security incidents
  • Change Management: Tracking trust configurations supports change control processes
  • Risk Assessment: Detailed trust information enables proper risk evaluation
  • Compliance: Many frameworks require documentation of trust relationships

Trust details reveal critical security properties including:

  • Direction: Who can access whose resources
  • Type: External vs Forest trust (different security models)
  • SID Filtering: Whether the trust is quarantined
  • Selective Authentication: Whether authentication is restricted

Security Recommendationโ€‹

Configuration Best Practices:

  1. Use Forest Trusts: Prefer forest trusts over external trusts for better security
  2. Enable SID Filtering: Always enable SID filtering on external trusts
  3. Selective Authentication: Use selective authentication when possible
  4. Inbound Only: Prefer inbound trusts over bidirectional when possible
  5. Document Everything: Maintain detailed documentation of each trust's purpose

Trust Properties to Monitor:

  • Quarantined: Should be $true for external trusts
  • SelectiveAuthentication: Consider enabling for sensitive environments
  • Direction: Bidirectional trusts have higher risk
  • IntraForest: External trusts ($false) need extra scrutiny

How the Test Worksโ€‹

This test retrieves all trust properties and displays:

  • Target domain
  • Trust direction
  • Trust type
  • Intra-forest status
  • Quarantine (SID filtering) status
  • Selective authentication status
  • Test-MtAdTrustTotalCount - Overall trust count
  • Test-MtAdTrustInterForestCount - External trust identification
  • Test-MtAdTrustQuarantinedCount - SID filtering status
  • Test-MtAdTrustStaleCount - Trust validation status

Test Metadataโ€‹

FieldValue
Test IDAD-TRUST-05
SeverityInfo
SuiteActive Directory
CategoryAD.Trust
PowerShell testTest-MtAdTrustDetails
TagsAD, AD-TRUST-05, AD.Trust

Sourceโ€‹

  • Pester test: tests/ad/trust/Test-MtAdTrustDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/trust/Test-MtAdTrustDetails.ps1