test(lab): give each new fixture a new account for the effective-access case
When an account is deleted and created again with the same name, a Kerberos S4U
logon for it keeps returning the SID and the groups of the deleted account for
a while, on the domain controller, the client, and the file server. The matrix
deletes the fixture after each cell and creates it for the next, so the
effective-access tests of the Admin role found no access for the new account in
cells that followed within minutes (Windows Server 2022 cell, candidate and
baseline alike, shown by a probe that creates the accounts in a loop). A new
fixture now gets NtfsLiveSubject and four digits; a fixture that exists keeps
its account.
The end-state check of the matrix also reports leftover scheduled tasks, stage
folders, standard users, and probe accounts, which the review asked for.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
$directory=@(foreach($namein$DomainController){Invoke-LabCommand-ComputerName$name-ActivityName"Read the fixture of $name"-ScriptBlock$directoryScript@labCommand})
$directory=@(foreach($namein$DomainController){Invoke-LabCommand-ComputerName$name-ActivityName"Read the fixture of $name"-ScriptBlock$directoryScript@labCommand})
foreach($statein$directory){
foreach($statein$directory){
'{0,-14} OU NTFSSecurityLive: {1,-5} NtfsLive* accounts: {2}'-f$state.Domain,$state.Unit,($(if($state.Sids){$state.Sids-join', '}else{'none'}))
# Runs on the domain controller: creates or updates the accounts and groups in their organizational unit, pushes them
# Runs on the domain controller: creates or updates the accounts and groups in their organizational unit, pushes them
# to the other domain controllers of the domain, and returns their SIDs.
# to the other domain controllers of the domain, and returns their SIDs.
$accountScript={
$accountScript={
@ -1060,6 +1074,14 @@ $modules = @(
)
)
Write-LabProgress'Preparing the accounts, the file server, and the client'
Write-LabProgress'Preparing the accounts, the file server, and the client'
# When an account is deleted and created again with the same name, a Kerberos S4U logon for it keeps returning the SID and the groups of
# the deleted account for a while: on the domain controller, the client, and the file server of the operating-system matrix, for every
# version of the module. The Authz functions behind Get-NTFSEffectiveAccess log an account on this way, so the cmdlet returned no access
# for the new account. A new fixture therefore gets a name for the account of case 3 that no earlier fixture used; a fixture that
# exists keeps its account.
$existingSubjects=@(Invoke-LabCommand-ComputerName$DomainController-ActivityName'Look for the account of case 3'-ScriptBlock$findSubjectScript-ArgumentList$organizationalUnitName,$subjectBaseName@labCommand)