Skip to main content
Version: 2.2.1-preview

AD-COMP-01 - Computer disabled count should be retrievable

Overviewโ€‹

Disabled computer accounts that remain in Active Directory represent a security hygiene issue. While disabling a computer account is a valid administrative action (typically when decommissioning systems), these accounts should eventually be removed to:

  • Reduce attack surface: Disabled accounts can be re-enabled by attackers who gain privileged access
  • Prevent confusion: Distinguish between active and truly decommissioned systems
  • Maintain directory cleanliness: Simplify auditing and compliance reporting
  • Avoid stale data: Ensure Group Policy and software deployment targets are accurate

Security Recommendationโ€‹

Regularly review disabled computer accounts and delete those that are permanently decommissioned. Consider establishing a process where disabled computers are automatically deleted after a defined retention period (e.g., 30-90 days).

How the Test Worksโ€‹

This test retrieves all computer objects from Active Directory and counts:

  • Total number of computer accounts
  • Number of disabled computer accounts
  • Percentage of computers that are disabled

The test returns informational results to help you assess the scope of disabled accounts in your environment.

  • Test-MtAdComputerDormantCount - Identifies enabled computers that haven't logged on recently
  • Test-MtAdComputerInDefaultContainer - Finds computers in the default container (another hygiene indicator)

Test Metadataโ€‹

FieldValue
Test IDAD-COMP-01
SeverityInfo
SuiteActive Directory
CategoryAD.Computer
PowerShell testTest-MtAdComputerDisabledCount
TagsAD, AD-COMP-01, AD.Computer

Sourceโ€‹

  • Pester test: tests/ad/computer/Test-MtAdComputerDisabledCount.Tests.ps1
  • PowerShell source: powershell/public/ad/computer/Test-MtAdComputerDisabledCount.ps1