AD-TRUST-06 - Trust stale count should be retrievable
Overviewβ
Stale trusts (those not validated for extended periods) indicate potential issues:
- Decommissioned Domains: The target domain may no longer exist
- Connectivity Issues: Network problems preventing trust validation
- Orphaned Trusts: Trusts created for temporary purposes that were never removed
- Security Hygiene: Unused trusts increase attack surface unnecessarily
- Operational Risk: Stale trusts may fail unexpectedly when needed
Trust validation occurs when the trusting domain attempts to verify the trust relationship with the trusted domain. If this hasn't happened in 60+ days, it suggests the trust is not actively used.
Security Recommendationβ
Immediate Actions:
- Review all stale trusts to determine if they are still needed
- Test connectivity to the target domain
- Verify the target domain still exists
Remediation Steps:
- Verify Need: Confirm if the trust serves a business purpose
- Test Connectivity: Attempt to validate the trust manually
- Remove if Unused: Delete trusts that are no longer needed
- Document Exceptions: For trusts that must remain, document why
Command to Validate a Trust:
Test-ADTrust -Target <TrustName>
Command to Remove a Trust:
Remove-ADTrust -Target <TrustName>
How the Test Worksβ
This test checks the LastValidated property of each trust. Trusts are considered stale if:
LastValidatedis not nullLastValidatedis more than 60 days in the past
The test returns:
- Total trust count
- Count of stale trusts
- Count of trusts with unknown validation status
- Count of valid trusts
Related Testsβ
Test-MtAdTrustStaleDetails- Lists specific stale trusts with detailsTest-MtAdTrustTotalCount- Overall trust countTest-MtAdTrustDetails- Complete trust configuration including last validated date
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-TRUST-06 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Trust |
| PowerShell test | Test-MtAdTrustStaleCount |
| Tags | AD, AD-TRUST-06, AD.Trust |
Sourceβ
- Pester test:
tests/ad/trust/Test-MtAdTrustStaleCount.Tests.ps1 - PowerShell source:
powershell/public/ad/trust/Test-MtAdTrustStaleCount.ps1

