Skip to main content
Version: 2.3.0

AD-GPOS-06 - User disabled GPO settings details should be compliant

Overview​

Test-MtAdGpoUserSettingsDisabledDetails​

Returns details of GPOs where user settings are disabled.

Why This Test Matters​

  • Detective control: looks for GPOs where user settings are disabled, which can impact user policy delivery.

Control Type​

Operational

Security Recommendation​

  • Review user-disabled GPOs and confirm whether disabling is intentional per policy.

How the Test Works​

  • Gets GPO state, filters for reports where the UserDisabled status is true and renders a details table including display name and status.
  • Test-MtAdGpoUserSettingsDisabledDetails (self reference for template clarity).

Test Metadata​

FieldValue
Test IDAD-GPOS-06
SeverityInfo
SuiteActive Directory
CategoryAD.GPOState
PowerShell testTest-MtAdGpoUserSettingsDisabledDetails
TagsAD, AD-GPOS-06, AD.GPOState

Source​

  • Pester test: tests/ad/gpostate/Test-MtAdGpoUserSettingsDisabledDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/gpostate/Test-MtAdGpoUserSettingsDisabledDetails.ps1