AD-GPOS-02 - WMI filter count should be retrievable
Overviewβ
Test-MtAdGpoWmiFilterCountβ
Counts the number of GPOs that have a non-empty WMI filter.
Why This Test Mattersβ
- Operational control: counts GPOs that have a non-empty WMI filter to gauge policy scoping across the environment.
Control Typeβ
Operational
Security Recommendationβ
- Review configure WMI filters to ensure correct targeting and minimize unnecessary exposure.
How the Test Worksβ
- Gets GPO state, computes the number of GPOs with a non-empty WmiFilter, and reports totals and ratios.
Related Testsβ
Test-MtAdGpoWmiFilterDetails.
Related linksβ
- Microsoft Learn - Group Policy management
- ANSSI checkpoint: https://www.anssi.gouv.fr/
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GPOS-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.GPOState |
| PowerShell test | Test-MtAdGpoWmiFilterCount |
| Tags | AD, AD-GPOS-02, AD.GPOState |
Sourceβ
- Pester test:
tests/ad/gpostate/Test-MtAdGpoWmiFilterCount.Tests.ps1 - PowerShell source:
powershell/public/ad/gpostate/Test-MtAdGpoWmiFilterCount.ps1
