AD-COMP-02 - Computer dormant count should be retrievable
Overview
Dormant (stale) computer accounts—enabled accounts that haven't authenticated in 90+ days—pose significant security risks:
- Attack vector: Attackers can exploit dormant accounts that may have weak or unchanged passwords
- Shadow IT: These may represent forgotten test systems, VMs, or decommissioned hardware still in the directory
- Lateral movement: Compromised dormant accounts can be used to move laterally within the network
- Compliance issues: Many security frameworks require identification and remediation of stale accounts
Security Recommendation
Establish a process to:
- Identify dormant computers (this test)
- Investigate whether they represent legitimate systems
- Disable accounts for systems that are truly decommissioned
- Delete disabled accounts after a verification period
How the Test Works
This test examines all enabled computer accounts and identifies those where:
- The
lastLogonDateproperty is more than 90 days old - The account remains enabled
The 90-day threshold is a common security baseline, though your organization may adjust this based on your specific requirements (e.g., seasonal systems, remote workstations).
Related Tests
Test-MtAdComputerDisabledCount- Counts already-disabled computer accountsTest-MtAdComputerInDefaultContainer- Identifies computers that may be unmanaged
Test Metadata
| Field | Value |
|---|---|
| Test ID | AD-COMP-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Computer |
| PowerShell test | Test-MtAdComputerDormantCount |
| Tags | AD, AD-COMP-02, AD.Computer |
Source
- Pester test:
tests/ad/computer/Test-MtAdComputerDormantCount.Tests.ps1 - PowerShell source:
powershell/public/ad/computer/Test-MtAdComputerDormantCount.ps1

