Skip to main content
Version: 2.3.0

AD-GPOREP-17 - No GPOs should contain a cpassword

Overview​

Test-MtAdGpoCpasswordFoundCount​

Counts the number of GPOs that contain a cpassword.

Why This Test Matters​

  • Detective control: counts GPOs containing a cpassword which indicates potential credential exposure.

Control Type​

Detective

Security Recommendation​

  • Review cpassword occurrences and rotate credentials or secure storage as needed.

How the Test Works​

  • Retrieves GPO state, filters for CpasswordFound, and reports totals and percentage of GPOs with cpasswords.
  • Test-MtAdGpoCpasswordFoundDetails.

Test Metadata​

FieldValue
Test IDAD-GPOREP-17
SeverityCritical
SuiteActive Directory
CategoryAD.GPOState
PowerShell testTest-MtAdGpoCpasswordFoundCount
TagsAD, AD-GPOREP-17, AD.GPOState

Source​

  • Pester test: tests/ad/gpostate/Test-MtAdGpoCpasswordFoundCount.Tests.ps1
  • PowerShell source: powershell/public/ad/gpostate/Test-MtAdGpoCpasswordFoundCount.ps1