Skip to main content
Version: 2.3.0

AD-GPOREP-13 - GPO disabled link details should be retrievable

Overviewโ€‹

Test-MtAdGpoDisabledLinkDetailsโ€‹

Returns details of GPOs with disabled GPO links.

Why This Test Mattersโ€‹

  • Detective control: checks for GPOs with disabled links to identify potential misconfigurations that could affect policy delivery.
  • Disabled links can lead to unexpected policy application gaps.

Control Typeโ€‹

Operational

Security Recommendationโ€‹

  • Review and re-enable intentional GPO links or remove unused GPOs to restore intended policy application.

How the Test Worksโ€‹

  • Retrieves GPO state via Get-MtADGpoState, filters GPOReports for DisabledLinks greater than 0, and renders a Markdown table with the results.
  • Test-MtAdGpoDisabledLinkCount - Count of disabled links across GPOs.

Test Metadataโ€‹

FieldValue
Test IDAD-GPOREP-13
SeverityInfo
SuiteActive Directory
CategoryAD.GPOState
PowerShell testTest-MtAdGpoDisabledLinkDetails
TagsAD, AD-GPOREP-13, AD.GPOState

Sourceโ€‹

  • Pester test: tests/ad/gpostate/Test-MtAdGpoDisabledLinkDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/gpostate/Test-MtAdGpoDisabledLinkDetails.ps1