AD-COMP-03 - Computer CreatorSid count should be retrievable
Overviewโ
The ms-ds-CreatorSid attribute identifies which security principal created a computer account. This is valuable for:
- Audit trail: Understanding who or what created computer accounts helps trace unauthorized additions
- Delegation analysis: Identifying service accounts or users with excessive computer creation rights
- Security monitoring: Detecting unusual computer creation patterns that may indicate compromise
- Compliance: Meeting requirements for tracking resource creation in the directory
Security Recommendationโ
Computer account creation should be tightly controlled:
- Limit the
ms-DS-MachineAccountQuotaattribute (default is 10) to prevent standard users from creating computer accounts - Use dedicated service accounts for automated computer provisioning
- Regularly audit computer accounts to identify those created by unexpected principals
- Consider setting the quota to 0 and using pre-staged computer accounts or dedicated provisioning processes
How the Test Worksโ
This test counts computer objects that have the ms-ds-CreatorSid attribute populated. This attribute is typically set when:
- A user or service account explicitly creates a computer account
- The creating principal has been captured in the directory
Note: Not all computer accounts will have this attribute, depending on how they were created.
Related Testsโ
Test-MtAdComputerNonStandardGroup- Identifies computers with unusual primary group assignmentsTest-MtAdComputerInDefaultContainer- Finds computers that may have been auto-created
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-COMP-03 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Computer |
| PowerShell test | Test-MtAdComputerCreatorSidCount |
| Tags | AD, AD-COMP-03, AD.Computer |
Sourceโ
- Pester test:
tests/ad/computer/Test-MtAdComputerCreatorSidCount.Tests.ps1 - PowerShell source:
powershell/public/ad/computer/Test-MtAdComputerCreatorSidCount.ps1

