Skip to main content
Version: 2.2.1-preview

AD-USER-18 - User script path count should be retrievable

Overview​

The ScriptPath attribute can launch scripts automatically during user sign-in. These scripts may map drives, alter environment settings, or execute legacy administrative logic.

  • Execution surface: Logon scripts can introduce code execution paths during authentication
  • Legacy dependency detection: Helps identify environments still relying on older sign-in automation
  • Review priority: Highlights scripts and shares that may need access hardening or modernization

Security Recommendation​

  • Review every configured logon script for business need and secure coding practices
  • Protect the storage locations that host scripts from unauthorized modification
  • Retire unnecessary scripts and move critical logic to managed modern tooling where possible

How the Test Works​

This test counts user objects where the ScriptPath attribute contains a non-empty value.

  • Test-MtAdUserHomeDirectoryCount - Identifies related legacy provisioning settings
  • Test-MtAdUserProfilePathCount - Finds users with additional sign-in infrastructure dependencies

Test Metadata​

FieldValue
Test IDAD-USER-18
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserScriptPathCount
TagsAD, AD-USER-18, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserScriptPathCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserScriptPathCount.ps1