AD-USER-12 - User non-standard primary group count should be retrievable
Overviewβ
Most user accounts use PrimaryGroupId = 513, which corresponds to Domain Users. When a user has a different primary group, the configuration is often intentional but uncommon.
- Privilege review: Non-standard primary groups can indicate elevated or specialized access models
- Migration residue: Legacy migrations and scripted provisioning may leave unusual values behind
- Access clarity: Atypical primary groups make account analysis more complex
Security Recommendationβ
- Review users whose
PrimaryGroupIdis not513 - Confirm the configuration is required and documented
- Standardize primary groups where there is no operational reason for deviation
How the Test Worksβ
This test counts user objects where primaryGroupId is populated and not equal to 513.
Related Testsβ
Test-MtAdUserAdminCountCount- Highlights protected or privileged accountsTest-MtAdUserSidHistoryCount- Identifies migration-related account artifacts
Related linksβ
- Microsoft Defender for Identity: Accounts with non-default Primary Group ID
- ANSSI Active Directory checkpoints: Accounts with modified PrimaryGroupID
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-12 |
| Severity | Medium |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserNonStandardPrimaryGroupCount |
| Tags | AD, AD-USER-12, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserNonStandardPrimaryGroupCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserNonStandardPrimaryGroupCount.ps1


