AD-USER-19 - User in container count should be retrievable
Overviewβ
Users are easier to manage when placed in organizational units (OUs) that align to administration, policy, and lifecycle requirements. Accounts stored in container paths such as CN=Users often indicate default placement or limited organizational structure.
- Delegation limitations: Containers are less flexible for delegated administration
- Policy design impact: OUs are the preferred structure for policy and lifecycle management
- Default placement visibility: Helps identify accounts still living in
CN=Usersor similar container paths
Security Recommendationβ
- Move standard user accounts from container paths into appropriate OUs
- Define an OU model that supports administration, policy, and lifecycle requirements
- Regularly review new accounts for default or non-standard placement
How the Test Worksβ
This test counts user objects whose distinguished names indicate they are beneath a container path, including accounts under CN=Users.
Related Testsβ
Test-MtAdUserManagerSetCount- Helps assess whether organizational metadata is mature enough for governanceTest-MtAdUserKnownServiceAccountCount- Finds service accounts that may also require dedicated OUs
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-19 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserInContainerCount |
| Tags | AD, AD-USER-19, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserInContainerCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserInContainerCount.ps1

