AD-GPOS-09 - GPO owner details should be accessible
Overviewβ
Test-MtAdGpoOwnerDetailsβ
Returns details of GPO owners, including how many GPOs each owner has.
Why This Test Mattersβ
- Operational value: summarizes GPO owners and how many GPOs each owner has, revealing ownership distribution.
Control Typeβ
Operational
Security Recommendationβ
- Ensure ownership aligns with policy and stewardship; adjust ownership for orphaned or unclear GPOs.
How the Test Worksβ
- Retrieves GPO state, groups GPOs by Owner, and renders a table with owner and GPO counts.
Related Testsβ
Test-MtAdGpoOwnerDistinctCount.
Related linksβ
- Microsoft Learn - Group Policy management
- ANSSI checkpoint: https://www.anssi.gouv.fr/
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GPOS-09 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.GPOState |
| PowerShell test | Test-MtAdGpoOwnerDetails |
| Tags | AD, AD-GPOS-09, AD.GPOState |
Sourceβ
- Pester test:
tests/ad/gpostate/Test-MtAdGpoOwnerDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/gpostate/Test-MtAdGpoOwnerDetails.ps1
