Skip to main content
Version: 2.2.1-preview

AD-USER-04 - Reversible encryption user count should be retrievable

Overview​

Reversible password encryption is effectively equivalent to storing passwords in a decryptable form. Accounts configured this way create serious exposure if the directory or credential material is compromised.

Security Recommendation​

Disable reversible password encryption unless it is required for a documented legacy dependency that cannot be modernized immediately. Remediate those dependencies as a priority.

How the Test Works​

This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts with reversible-encryption-style indicators. It checks explicit reversible encryption properties when available and falls back to the relevant userAccountControl flag.

  • Test-MtAdUserKerberosDesOnlyCount
  • Test-MtAdUserPasswordNotRequiredCount
  • Test-MtAdUserNoPreAuthCount

Test Metadata​

FieldValue
Test IDAD-USER-04
SeverityMedium
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserReversibleEncryptionCount
TagsAD, AD-USER-04, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserReversibleEncryptionCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserReversibleEncryptionCount.ps1