AD-GRP-07 - Security group count should be retrievable
Overviewβ
Security groups are the foundation of access control in Active Directory. Understanding their count and distribution is critical for:
- Access management assessment: High numbers of security groups may indicate complex or poorly managed permissions
- Security auditing: Security groups directly control who can access what resources
- Privilege analysis: Helps identify the scale of group-based access control to audit
- Compliance requirements: Many frameworks require documentation and regular review of security groups
Security groups can be assigned permissions to resources, unlike distribution groups.
Control Typeβ
Operational
Security Recommendationβ
Establish governance around security groups:
- Implement a naming convention for security groups to improve manageability
- Regularly audit security group memberships, especially for privileged groups
- Document the purpose and owner of each security group
- Remove unused or stale security groups to reduce attack surface
- Consider implementing privileged access management for highly sensitive groups
How the Test Worksβ
This test examines all group objects and identifies those where:
- The
GroupCategoryproperty equals "Security" - These groups can be assigned permissions and used for access control
The test provides counts and percentages to understand the proportion of security groups versus distribution groups.
Related Testsβ
Test-MtAdGroupDistributionCount- Counts distribution groups (email-only)Test-MtAdGroupDomainLocalCount- Counts domain local scope groupsTest-MtAdGroupGlobalCount- Counts global scope groupsTest-MtAdGroupUniversalCount- Counts universal scope groups
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-GRP-07 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Group |
| PowerShell test | Test-MtAdGroupSecurityCount |
| Tags | AD, AD-GRP-07, AD.Group |
Sourceβ
- Pester test:
tests/ad/group/Test-MtAdGroupSecurityCount.Tests.ps1 - PowerShell source:
powershell/public/ad/group/Test-MtAdGroupSecurityCount.ps1

