AD-USER-02 - Dormant enabled user count should be retrievable
Overviewβ
Enabled user accounts that have not logged on for more than 90 days are a common sign of weak identity hygiene. Forgotten but still-enabled accounts can retain access, group memberships, and password material that attackers may target.
Security Recommendationβ
Investigate dormant enabled accounts and disable or remove those that are no longer needed. For exceptions such as break-glass or low-use service accounts, apply stronger controls and document ownership.
How the Test Worksβ
This test retrieves Active Directory user data from Get-MtADDomainState, filters to enabled users, and counts accounts where LastLogonDate is older than 90 days. The output shows the number and percentage of dormant enabled users.
Related Testsβ
Test-MtAdUserDisabledCountTest-MtAdUserNeverLoggedInCountTest-MtAdUserPasswordNeverExpiresCount
Related linksβ
- Microsoft Defender for Identity: Remove stale Active Directory accounts
- ANSSI Active Directory checkpoints: Dormant accounts
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-02 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserDormantEnabledCount |
| Tags | AD, AD-USER-02, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserDormantEnabledCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserDormantEnabledCount.ps1


