AD-USER-20 - Known service account count should be retrievable
Overviewโ
Many environments use recognizable naming conventions for service accounts such as svc_, service_, or _svc. These patterns make service accounts easier to inventory and harden.
- Service account inventory: Helps locate likely service identities quickly
- Hardening prioritization: Supports focused review of passwords, SPNs, and delegation
- Monitoring alignment: Makes it easier to target logon, privilege, and usage monitoring
Security Recommendationโ
- Review accounts matching known service account naming patterns for proper ownership and documentation
- Apply stronger controls to service accounts, including long random passwords and interactive logon restrictions
- Prefer managed service account options where the workload supports them
How the Test Worksโ
This test counts user objects whose SamAccountName or Name matches common service account naming patterns such as svc_, service_, _svc, sa_, and similar variants.
Related Testsโ
Test-MtAdUserSpnSetCount- Identifies service accounts through SPN usageTest-MtAdUserAdminCountCount- Highlights service accounts that may also be protected or privileged
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-USER-20 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserKnownServiceAccountCount |
| Tags | AD, AD-USER-20, AD.User |
Sourceโ
- Pester test:
tests/ad/user/Test-MtAdUserKnownServiceAccountCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserKnownServiceAccountCount.ps1

