Skip to main content
Version: 2.2.1-preview

AD-USER-16 - User home directory count should be retrievable

Overview​

The HomeDirectory attribute points users to network-based storage locations. While useful in legacy environments, it can reveal older provisioning patterns and dependencies on file servers.

  • Legacy infrastructure visibility: Identifies users tied to mapped-drive style home folders
  • Access control review: Highlights centralized storage paths that may contain sensitive data
  • Modernization planning: Helps quantify remaining on-premises file service dependencies

Security Recommendation​

  • Review home directory locations for proper ACLs and ownership controls
  • Confirm the attribute is still required for active users
  • Retire obsolete mappings and legacy storage dependencies where feasible

How the Test Works​

This test counts user objects where the HomeDirectory attribute contains a non-empty value.

  • Test-MtAdUserProfilePathCount - Finds roaming profile dependencies
  • Test-MtAdUserScriptPathCount - Identifies legacy logon automation

Test Metadata​

FieldValue
Test IDAD-USER-16
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserHomeDirectoryCount
TagsAD, AD-USER-16, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserHomeDirectoryCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserHomeDirectoryCount.ps1