Skip to main content
Version: 2.2.1-preview

AD-MSA-01 - Managed service account count should be retrievable

Overviewโ€‹

  • Managed Service Accounts (MSAs) and Group Managed Service Accounts (gMSAs) provide significant security improvements over traditional service accounts by automating password management and simplifying service principal name (SPN) management.

Security Benefits:

  • Automatic Password Rotation: Passwords change automatically (every 30 days for gMSAs)
  • Eliminates Manual Management: No need for administrators to manage service account passwords
  • No Interactive Logon: Cannot be used for interactive logon, reducing attack surface
  • Reduced Credential Theft Risk: Passwords are complex and regularly changed
  • Simplified Administration: No manual password changes or coordination required

Types of Managed Service Accounts:

  • Standalone MSA: For use on a single computer (legacy, largely replaced by gMSA)
  • Group MSA (gMSA): Can be used across multiple computers, preferred solution

Security Recommendationโ€‹

  1. Use gMSAs Where Possible:

    • Replace traditional service accounts with gMSAs
    • Prioritize high-privilege service accounts
    • Plan migration for legacy applications
  2. Implementation Requirements:

    • At least one Windows Server 2012 or later domain controller
    • KDS root key must be created (one-time operation)
    • Applications must support gMSA authentication
  3. Best Practices:

    • Use gMSAs for all new service deployments
    • Create separate gMSAs for different services
    • Document gMSA usage and permissions
    • Regular audit of gMSA deployments

How the Test Worksโ€‹

This test counts managed service accounts in Active Directory and categorizes them by:

  • Total MSAs and gMSAs
  • Group vs. standalone MSAs
  • Account details and status
  • Test-MtAdUserKnownServiceAccountCount - Traditional service account identification
  • Test-MtAdKdsRootKeysCount - KDS root key requirement for gMSAs
  • Test-MtAdUserPasswordNeverExpiresCount - Traditional accounts with non-expiring passwords

Referencesโ€‹

Test Metadataโ€‹

FieldValue
Test IDAD-MSA-01
SeverityInfo
SuiteActive Directory
CategoryAD.Security
PowerShell testTest-MtAdManagedServiceAccountCount
TagsAD, AD-MSA-01, AD.Security

Sourceโ€‹

  • Pester test: tests/ad/security/Test-MtAdManagedServiceAccountCount.Tests.ps1
  • PowerShell source: powershell/public/ad/security/Test-MtAdManagedServiceAccountCount.ps1