Skip to main content
Version: 2.2.1-preview

AD-USER-17 - User profile path count should be retrievable

Overview​

The ProfilePath attribute is commonly associated with roaming profiles and centralized workstation state. It often points to legacy file server infrastructure that should be reviewed for resilience and access control.

  • Legacy profile management: Identifies users depending on roaming profiles
  • Data exposure review: Highlights centralized storage paths that may require tighter controls
  • Operational dependency mapping: Helps quantify reliance on older desktop management models

Security Recommendation​

  • Review profile share permissions and access paths
  • Confirm roaming profiles are still necessary for affected users
  • Consider modern endpoint and profile management approaches where appropriate

How the Test Works​

This test counts user objects where the ProfilePath attribute contains a non-empty value.

  • Test-MtAdUserHomeDirectoryCount - Highlights related file share dependencies
  • Test-MtAdUserScriptPathCount - Finds additional legacy sign-in configuration

Test Metadata​

FieldValue
Test IDAD-USER-17
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserProfilePathCount
TagsAD, AD-USER-17, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserProfilePathCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserProfilePathCount.ps1