AD-USER-03 - Non-expiring password user count should be retrievable
Overviewβ
Passwords that never expire reduce credential hygiene and increase the blast radius of password theft. While some service accounts may require non-expiring credentials, they should be rare, controlled, and closely monitored.
Security Recommendationβ
Minimize the use of non-expiring passwords. Where legacy constraints require them, migrate to managed service accounts, vaulting, or other compensating controls.
How the Test Worksβ
This test retrieves Active Directory user data from Get-MtADDomainState, filters to enabled users, and counts accounts where PasswordNeverExpires = $true. The output includes the count and percentage relative to enabled users.
Related Testsβ
Test-MtAdUserDormantEnabledCountTest-MtAdUserPasswordNotRequiredCountTest-MtAdUserNeverLoggedInCount
Related linksβ
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-03 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserPasswordNeverExpiresCount |
| Tags | AD, AD-USER-03, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserPasswordNeverExpiresCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserPasswordNeverExpiresCount.ps1


