Private/AD/Get-ADManagedUserCount.ps1

<#
.SYNOPSIS
Count the enabled AD accounts IDBridge has linked - the change-volume guard's population.

.DESCRIPTION
The change-volume guard's denominator for AD (Invoke-IDBridge, ChangeThreshold). A user counts
when it carries an EmployeeID - the personID link IDBridge writes on create, link and deactivate -
and is enabled. Where the account sits in the domain doesn't matter: disabled accounts in the
trash OU and accounts IDBridge never linked (service, admin, hand-made accounts) never count, and
AD.userRootOU plays no part (it is only the service account's delegation OU). The count reads
directory state only: a broken source feed cannot shrink its own denominator. Nothing is linked on
a fresh domain, so the count is 0 and Test-IDBridgeChangeThreshold skips the check with a Warn.
Assumes nothing else populates EmployeeID in the domain (e.g. an HR sync) - those accounts would
count too. Mirrors Get-GoogleManagedUserCount.

.PARAMETER Users
The AD users (from Get-TargetDataAD .Users). Null or empty allowed.

.OUTPUTS
[int] the managed user count.

.EXAMPLE
$population = Get-ADManagedUserCount -Users $adData.Users

.NOTES
   Created by: Sam Cattanach
   Modified: 2026-10-09
#>

function Get-ADManagedUserCount {
    [CmdletBinding()]
    [OutputType([int])]
    param (
        [Parameter(Mandatory = $true)]
        [AllowNull()]
        [AllowEmptyCollection()]
        $Users
    )

    return @($Users | Where-Object { $_.Enabled -eq $true -and $_.EmployeeID }).Count
}