AD-GPOREP-17 - No GPOs should contain a cpassword
Overviewβ
Test-MtAdGpoCpasswordFoundCountβ
Counts the number of GPOs that contain a cpassword.
Why This Test Mattersβ
- Detective control: counts GPOs containing a cpassword which indicates potential credential exposure.
Control Typeβ
Detective
Security Recommendationβ
- Review cpassword occurrences and rotate credentials or secure storage as needed.
How the Test Worksβ
- Retrieves GPO state, filters for CpasswordFound, and reports totals and percentage of GPOs with cpasswords.
Related Testsβ
Test-MtAdGpoCpasswordFoundDetails.
Related linksβ
- Microsoft Learn - Group Policy management
- ANSSI checkpoint: https://www.anssi.gouv.fr/
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GPOREP-17 |
| Severity | Critical |
| Suite | Active Directory |
| Category | AD.GPOState |
| PowerShell test | Test-MtAdGpoCpasswordFoundCount |
| Tags | AD, AD-GPOREP-17, AD.GPOState |
Sourceβ
- Pester test:
tests/ad/gpostate/Test-MtAdGpoCpasswordFoundCount.Tests.ps1 - PowerShell source:
powershell/public/ad/gpostate/Test-MtAdGpoCpasswordFoundCount.ps1
