Skip to main content
Version: 2.3.0

AD-GPOS-02 - WMI filter count should be retrievable

Overview​

Test-MtAdGpoWmiFilterCount​

Counts the number of GPOs that have a non-empty WMI filter.

Why This Test Matters​

  • Operational control: counts GPOs that have a non-empty WMI filter to gauge policy scoping across the environment.

Control Type​

Operational

Security Recommendation​

  • Review configure WMI filters to ensure correct targeting and minimize unnecessary exposure.

How the Test Works​

  • Gets GPO state, computes the number of GPOs with a non-empty WmiFilter, and reports totals and ratios.
  • Test-MtAdGpoWmiFilterDetails.

Test Metadata​

FieldValue
Test IDAD-GPOS-02
SeverityInfo
SuiteActive Directory
CategoryAD.GPOState
PowerShell testTest-MtAdGpoWmiFilterCount
TagsAD, AD-GPOS-02, AD.GPOState

Source​

  • Pester test: tests/ad/gpostate/Test-MtAdGpoWmiFilterCount.Tests.ps1
  • PowerShell source: powershell/public/ad/gpostate/Test-MtAdGpoWmiFilterCount.ps1