Skip to main content
Version: 2.2.1-preview

AD-USER-12 - User non-standard primary group count should be retrievable

Overview​

Most user accounts use PrimaryGroupId = 513, which corresponds to Domain Users. When a user has a different primary group, the configuration is often intentional but uncommon.

  • Privilege review: Non-standard primary groups can indicate elevated or specialized access models
  • Migration residue: Legacy migrations and scripted provisioning may leave unusual values behind
  • Access clarity: Atypical primary groups make account analysis more complex

Security Recommendation​

  • Review users whose PrimaryGroupId is not 513
  • Confirm the configuration is required and documented
  • Standardize primary groups where there is no operational reason for deviation

How the Test Works​

This test counts user objects where primaryGroupId is populated and not equal to 513.

  • Test-MtAdUserAdminCountCount - Highlights protected or privileged accounts
  • Test-MtAdUserSidHistoryCount - Identifies migration-related account artifacts

Test Metadata​

FieldValue
Test IDAD-USER-12
SeverityMedium
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserNonStandardPrimaryGroupCount
TagsAD, AD-USER-12, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserNonStandardPrimaryGroupCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserNonStandardPrimaryGroupCount.ps1