Skip to main content
Version: 2.2.1-preview

AD-USER-13 - User SID History count should be retrievable

Overviewโ€‹

SIDHistory is commonly used during migrations so users can retain access to resources secured with legacy SIDs. Long-term SID history can create unnecessary complexity and unintended access paths.

  • Migration artifact detection: Identifies users that may still carry legacy identities
  • Trust boundary review: Helps spot cross-domain access dependencies
  • Permission cleanup: Supports least-privilege remediation after migrations

Security Recommendationโ€‹

  • Review users with SIDHistory to confirm ongoing business need
  • Remove unnecessary SID history entries after resource migration is complete
  • Pay special attention to SIDs originating from external or less-trusted domains

How the Test Worksโ€‹

This test counts user objects where the SIDHistory attribute contains one or more values.

  • Test-MtAdUserNonStandardPrimaryGroupCount - Finds other migration or provisioning anomalies
  • Test-MtAdUserAdminCountCount - Helps prioritize review of privileged accounts

Test Metadataโ€‹

FieldValue
Test IDAD-USER-13
SeverityMedium
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserSidHistoryCount
TagsAD, AD-USER-13, AD.User

Sourceโ€‹

  • Pester test: tests/ad/user/Test-MtAdUserSidHistoryCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserSidHistoryCount.ps1