Skip to main content
Version: 2.2.1-preview

AD-USER-03 - Non-expiring password user count should be retrievable

Overview​

Passwords that never expire reduce credential hygiene and increase the blast radius of password theft. While some service accounts may require non-expiring credentials, they should be rare, controlled, and closely monitored.

Security Recommendation​

Minimize the use of non-expiring passwords. Where legacy constraints require them, migrate to managed service accounts, vaulting, or other compensating controls.

How the Test Works​

This test retrieves Active Directory user data from Get-MtADDomainState, filters to enabled users, and counts accounts where PasswordNeverExpires = $true. The output includes the count and percentage relative to enabled users.

  • Test-MtAdUserDormantEnabledCount
  • Test-MtAdUserPasswordNotRequiredCount
  • Test-MtAdUserNeverLoggedInCount

Test Metadata​

FieldValue
Test IDAD-USER-03
SeverityHigh
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserPasswordNeverExpiresCount
TagsAD, AD-USER-03, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserPasswordNeverExpiresCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserPasswordNeverExpiresCount.ps1