AD-GPOREP-20 - No GPOs should contain a default password
Overviewβ
Test-MtAdGpoDefaultPasswordFoundDetailsβ
Returns details of GPOs that contain a default password.
Why This Test Mattersβ
- Detective control: verifies whether any GPO reports contain a default password and highlights those findings for remediation.
- In security terms, default passwords in GPOs are a common misconfiguration risk that attackers could exploit.
Control Typeβ
Detective
Security Recommendationβ
- Review GPOs listed in the report and replace default passwords with secure, unique credentials per policy. Remove any passwords that are no longer needed.
How the Test Worksβ
- Invokes Get-MtADGpoState to fetch GPO state data, then filters GPO reports where DefaultPasswordFound is true.
- Builds a Markdown table of GPO name and the DefaultPasswordFound flag, plus a summary line with counts.
Related Testsβ
Test-MtAdGpoDefaultPasswordFoundCount- Counts how many GPOs have a default password.
Related linksβ
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GPOREP-20 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.GPOState |
| PowerShell test | Test-MtAdGpoDefaultPasswordFoundDetails |
| Tags | AD, AD-GPOREP-20, AD.GPOState |
Sourceβ
- Pester test:
tests/ad/gpostate/Test-MtAdGpoDefaultPasswordFoundDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/gpostate/Test-MtAdGpoDefaultPasswordFoundDetails.ps1
