AD-FOR-02 - Forest domain count should be retrievable
Overviewβ
Understanding the number and names of domains in your forest is critical for:
- Security Boundaries: Each domain represents a security boundary with its own policies
- Trust Management: Understanding trust relationships between domains
- Administrative Scope: Knowing where administrative permissions apply
- Compliance Scope: Determining the scope of compliance assessments
- Disaster Recovery: Planning recovery procedures across all domains
Control Typeβ
Operational
Security Recommendationβ
- Minimize Domains: Fewer domains reduce complexity and attack surface
- Document Structure: Maintain documentation of all domains and their purposes
- Review Regularly: Periodically review if all domains are still needed
- Consistent Policies: Apply consistent security policies across all domains
How the Test Worksβ
This test retrieves all domains from the Active Directory forest and counts them. It also lists all domain names for reference.
Related Testsβ
Test-MtAdForestFunctionalLevel- Retrieves the forest functional levelTest-MtAdDomainControllerCount- Counts domain controllers in the current domain
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-FOR-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Forest |
| PowerShell test | Test-MtAdForestDomainCount |
| Tags | AD, AD-FOR-02, AD.Forest |
Sourceβ
- Pester test:
tests/ad/domain/Test-MtAdForestDomainCount.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdForestDomainCount.ps1

