AD-DOM-02 - Machine account quota should be retrievable
Overviewβ
The machine account quota (ms-DS-MachineAccountQuota) attribute controls how many computer accounts a standard (non-administrative) user can join to the domain. The default value of 10 can create security risks:
- Rogue Computer Joins: Attackers with valid user credentials can join unauthorized computers to the domain
- Lateral Movement: Joined computers can be used as pivot points for further attacks
- Resource Exhaustion: Excessive computer accounts can clutter the directory and complicate management
Security Recommendationβ
Consider reducing the machine account quota to 0 and using alternative methods for computer joins:
- Set quota to 0: Prevents standard users from joining computers
- Use pre-staged accounts: Administrators create computer accounts in advance
- Delegate join permissions: Grant specific groups permission to join computers
- Implement privileged access workstations: Use dedicated admin workstations for domain joins
To modify the quota:
Set-ADDomain -Identity "yourdomain.com" -Replace @{"ms-DS-MachineAccountQuota"="0"}
How the Test Worksβ
This test retrieves the current machine account quota value from Active Directory. The test is informational and helps you assess whether the default value poses a risk in your environment.
Related Testsβ
Test-MtAdDomainFunctionalLevel- Retrieves the domain functional levelTest-MtAdDomainControllerCount- Counts domain controllers
Related linksβ
- Microsoft Defender for Identity: Resolve unsecure domain configurations
- ANSSI Active Directory checkpoints: Unrestricted domain join
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DOM-02 |
| Severity | Low |
| Suite | Active Directory |
| Category | AD.Domain |
| PowerShell test | Test-MtAdMachineAccountQuota |
| Tags | AD, AD-DOM-02, AD.Domain |
Sourceβ
- Pester test:
tests/ad/domain/Test-MtAdMachineAccountQuota.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdMachineAccountQuota.ps1


