AD-USER-13 - User SID History count should be retrievable
Overviewโ
SIDHistory is commonly used during migrations so users can retain access to resources secured with legacy SIDs. Long-term SID history can create unnecessary complexity and unintended access paths.
- Migration artifact detection: Identifies users that may still carry legacy identities
- Trust boundary review: Helps spot cross-domain access dependencies
- Permission cleanup: Supports least-privilege remediation after migrations
Security Recommendationโ
- Review users with
SIDHistoryto confirm ongoing business need - Remove unnecessary SID history entries after resource migration is complete
- Pay special attention to SIDs originating from external or less-trusted domains
How the Test Worksโ
This test counts user objects where the SIDHistory attribute contains one or more values.
Related Testsโ
Test-MtAdUserNonStandardPrimaryGroupCount- Finds other migration or provisioning anomaliesTest-MtAdUserAdminCountCount- Helps prioritize review of privileged accounts
Related linksโ
- Microsoft Defender for Identity: Unsecure SID History attributes
- ANSSI Active Directory checkpoints: Accounts or groups with SID history set
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-USER-13 |
| Severity | Medium |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserSidHistoryCount |
| Tags | AD, AD-USER-13, AD.User |
Sourceโ
- Pester test:
tests/ad/user/Test-MtAdUserSidHistoryCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserSidHistoryCount.ps1


