Skip to main content
Version: 2.2.1-preview

AD-USER-11 - User AdminCount count should be retrievable

Overviewโ€‹

The AdminCount attribute is commonly set on protected and privileged accounts. These users often inherit AdminSDHolder protections and may retain elevated access or restricted ACL inheritance.

  • Privilege visibility: Highlights accounts that may be administrative or formerly administrative
  • Delegation impact: Protected accounts behave differently from standard users
  • Security review: Helps identify users that warrant stronger monitoring and change control

Security Recommendationโ€‹

  • Review each account with AdminCount = 1 to confirm it still requires elevated protections
  • Validate that privileged accounts are intentionally assigned and documented
  • Investigate stale or unexpected protected users and remove unnecessary privileged group membership

How the Test Worksโ€‹

This test counts user objects where the AdminCount attribute equals 1.

  • Test-MtAdUserNonStandardPrimaryGroupCount - Finds users with unusual group membership baselines
  • Test-MtAdUserSpnSetCount - Identifies potentially high-value service accounts

Test Metadataโ€‹

FieldValue
Test IDAD-USER-11
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserAdminCountCount
TagsAD, AD-USER-11, AD.User

Sourceโ€‹

  • Pester test: tests/ad/user/Test-MtAdUserAdminCountCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserAdminCountCount.ps1