Skip to main content
Version: 2.2.1-preview

AD-TRUST-07 - Trust stale details should be retrievable

Overviewโ€‹

Identifying specific stale trusts enables targeted remediation:

  • Prioritization: Focus cleanup efforts on the oldest, most likely unused trusts
  • Investigation: Specific target domains can be investigated for existence and need
  • Risk Assessment: Older trusts may represent higher security risks
  • Documentation: Detailed stale trust information supports decision-making
  • Compliance: Demonstrates active trust management for audits

Stale trusts often accumulate over time as:

  • Temporary project trusts are forgotten
  • Acquired company domains are decommissioned
  • Network restructuring leaves orphaned connections
  • Test environments are removed without cleanup

Security Recommendationโ€‹

Investigation Process:

  1. Identify Target Domain: Determine if the target domain still exists
  2. Check Business Need: Verify if any systems still require the trust
  3. Test Validation: Attempt manual trust validation
  4. Plan Removal: Schedule removal if trust is confirmed unused
  5. Document: Record removal rationale for audit purposes

Sample Investigation Commands:

#### Test if the trust can be validated
Test-ADTrust -Target <TrustName>

#### Check when the trust was created
Get-ADTrust -Filter {Target -eq "<TrustName>"} -Properties Created

#### View detailed trust information
Get-ADTrust -Filter {Target -eq "<TrustName>"} -Properties *

Removal Process:

  • Notify stakeholders before removing production trusts
  • Remove during maintenance windows
  • Document removal in change management system
  • Monitor for any authentication failures after removal

How the Test Worksโ€‹

This test identifies trusts where LastValidated is more than 60 days old and displays:

  • Target domain name
  • Trust direction
  • Last validation date
  • Days since last validation
  • Trust type

Results are sorted by last validation date (oldest first).

  • Test-MtAdTrustStaleCount - Count of stale trusts
  • Test-MtAdTrustTotalCount - Overall trust count
  • Test-MtAdTrustDetails - Complete trust configuration information

Test Metadataโ€‹

FieldValue
Test IDAD-TRUST-07
SeverityInfo
SuiteActive Directory
CategoryAD.Trust
PowerShell testTest-MtAdTrustStaleDetails
TagsAD, AD-TRUST-07, AD.Trust

Sourceโ€‹

  • Pester test: tests/ad/trust/Test-MtAdTrustStaleDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/trust/Test-MtAdTrustStaleDetails.ps1