This repository was archived by the owner on Sep 12, 2023. It is now read-only.

Description
Hi,
so far the T0 list is limited to group objects, but i'd suggest to extend it to several built-in objects which should always considered T0, such as:
- Domain root object
- AdminSDHolder object
- TrustedDomain objects
- krbtgt user account
- RID-500 account
- AAD Connect object(s)
Even possibly extending it to whole OUs and GPOs.
Let me know what you think, cheers