AD-GPOREP-18 - No GPOs should contain a cpassword
Overviewβ
Test-MtAdGpoCpasswordFoundDetailsβ
Returns details of GPOs that contain a cpassword.
Why This Test Mattersβ
- Detective control: detects GPOs that contain a Cpassword which could be exploited if leaked.
- Cpasswords expose sensitive credentials and should be protected.
Control Typeβ
Detective
Security Recommendationβ
- Rotate or remove the cpasswords where necessary and apply proper protection controls.
How the Test Worksβ
- Uses Get-MtADGpoState to obtain GPO data, filters for reports where CpasswordFound is true, and formats a Markdown table.
Related Testsβ
Test-MtAdGpoCpasswordFoundCount- counts GPOs with cpasswords.
Related linksβ
- Microsoft Learn - Group Policy security
- ANSSI checkpoint: https://www.anssi.gouv.fr/
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GPOREP-18 |
| Severity | Critical |
| Suite | Active Directory |
| Category | AD.GPOState |
| PowerShell test | Test-MtAdGpoCpasswordFoundDetails |
| Tags | AD, AD-GPOREP-18, AD.GPOState |
Sourceβ
- Pester test:
tests/ad/gpostate/Test-MtAdGpoCpasswordFoundDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/gpostate/Test-MtAdGpoCpasswordFoundDetails.ps1
