AD-USER-11 - User AdminCount count should be retrievable
Overviewโ
The AdminCount attribute is commonly set on protected and privileged accounts. These users often inherit AdminSDHolder protections and may retain elevated access or restricted ACL inheritance.
- Privilege visibility: Highlights accounts that may be administrative or formerly administrative
- Delegation impact: Protected accounts behave differently from standard users
- Security review: Helps identify users that warrant stronger monitoring and change control
Security Recommendationโ
- Review each account with
AdminCount = 1to confirm it still requires elevated protections - Validate that privileged accounts are intentionally assigned and documented
- Investigate stale or unexpected protected users and remove unnecessary privileged group membership
How the Test Worksโ
This test counts user objects where the AdminCount attribute equals 1.
Related Testsโ
Test-MtAdUserNonStandardPrimaryGroupCount- Finds users with unusual group membership baselinesTest-MtAdUserSpnSetCount- Identifies potentially high-value service accounts
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-USER-11 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserAdminCountCount |
| Tags | AD, AD-USER-11, AD.User |
Sourceโ
- Pester test:
tests/ad/user/Test-MtAdUserAdminCountCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserAdminCountCount.ps1

