AD-USER-04 - Reversible encryption user count should be retrievable
Overviewβ
Reversible password encryption is effectively equivalent to storing passwords in a decryptable form. Accounts configured this way create serious exposure if the directory or credential material is compromised.
Security Recommendationβ
Disable reversible password encryption unless it is required for a documented legacy dependency that cannot be modernized immediately. Remediate those dependencies as a priority.
How the Test Worksβ
This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts with reversible-encryption-style indicators. It checks explicit reversible encryption properties when available and falls back to the relevant userAccountControl flag.
Related Testsβ
Test-MtAdUserKerberosDesOnlyCountTest-MtAdUserPasswordNotRequiredCountTest-MtAdUserNoPreAuthCount
Related linksβ
- Microsoft Defender for Identity: Unsecure account attributes
- ANSSI Active Directory checkpoints: Privileged accounts with passwords stored using reversible encryption
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-04 |
| Severity | Medium |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserReversibleEncryptionCount |
| Tags | AD, AD-USER-04, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserReversibleEncryptionCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserReversibleEncryptionCount.ps1


