AD-GPOS-01 - GPO state total count should be retrievable
Overviewโ
Test-MtAdGpoStateTotalCountโ
Counts the total number of Group Policy Objects (GPOs) returned by Get-MtADGpoState.
Why This Test Mattersโ
- Operational control: provides a quick overview of the total GPOs present in the AD state to gauge scope.
Control Typeโ
Operational
Security Recommendationโ
- Use as a baseline metric; no remediation required unless counts look unexpectedly abnormal.
How the Test Worksโ
- Calls Get-MtADGpoState, counts non-null GPOs in the GPOs collection, and reports a Markdown table with a single Total GPOs value.
Related Testsโ
Test-MtAdGpoStateTotalCountis the primary reference.
Related linksโ
- Microsoft Learn - Group Policy overview
- ANSSI checkpoint: https://www.anssi.gouv.fr/
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-GPOS-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.GPOState |
| PowerShell test | Test-MtAdGpoStateTotalCount |
| Tags | AD, AD-GPOS-01, AD.GPOState |
Sourceโ
- Pester test:
tests/ad/gpostate/Test-MtAdGpoStateTotalCount.Tests.ps1 - PowerShell source:
powershell/public/ad/gpostate/Test-MtAdGpoStateTotalCount.ps1
