AD-DCOMP-06 - Stale enabled computer count should be retrievable
Overviewโ
Stale enabled computer accounts represent a significant security risk in Active Directory. These are computer accounts that remain enabled but have not authenticated to the domain for an extended period (typically 180 days or more).
Security Risks:
- Attack Vector: Stale accounts can be compromised and reactivated by attackers
- Lateral Movement: Compromised stale accounts provide footholds for lateral movement
- Credential Theft: May have weak or unchanged passwords
- Shadow IT: May indicate forgotten or unauthorized systems
- Compliance Issues: Violates security policies requiring regular account review
Common Causes:
- Decommissioned systems that were never disabled
- Virtual machines that were deleted but not removed from AD
- Test systems that are no longer in use
- Hardware refreshes where old accounts remain
Security Recommendationโ
-
Regular Review Process:
- Quarterly review of stale enabled computers
- Document business justification for exceptions
- Automate detection and reporting
-
Remediation Actions:
- Disable computers after 90-180 days of inactivity
- Delete disabled computers after additional review period
- Verify with system owners before deletion
-
Preventive Measures:
- Implement automated provisioning/deprovisioning
- Use computer account lifecycle management
- Regular audits of computer account creation
How the Test Worksโ
This test identifies enabled computers that:
- Have never logged on, OR
- Have not logged on for 180+ days
Provides counts and lists affected computers.
Related Testsโ
Test-MtAdComputerDormantCount- Dormant computer identificationTest-MtAdComputerDisabledCount- Disabled computer analysisTest-MtAdUserDormantEnabledCount- Stale user account check
Related linksโ
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DCOMP-06 |
| Severity | Medium |
| Suite | Active Directory |
| Category | AD.Security |
| PowerShell test | Test-MtAdComputerStaleEnabledCount |
| Tags | AD, AD-DCOMP-06, AD.Security |
Sourceโ
- Pester test:
tests/ad/security/Test-MtAdComputerStaleEnabledCount.Tests.ps1 - PowerShell source:
powershell/public/ad/security/Test-MtAdComputerStaleEnabledCount.ps1


