AD-USER-21 - Known service account details should be retrievable
Overviewโ
Service accounts often run business-critical workloads and commonly receive exceptions such as long-lived credentials, SPNs, or privileged access. Naming-pattern reviews help defenders quickly identify accounts that deserve deeper validation.
- Exposure reduction: Find accounts likely used by services before attackers do.
- Privilege review: Verify service accounts are not over-privileged.
- Credential hygiene: Check for non-expiring passwords and stale patterns.
- Inventory accuracy: Confirm naming standards are applied consistently.
Security Recommendationโ
- Maintain a defined naming standard for service accounts.
- Review matched accounts for owner, purpose, and required privileges.
- Prefer gMSAs where possible instead of traditional user-based service accounts.
- Investigate service-like names that lack documentation.
How the Test Worksโ
This test reviews AD user objects and flags accounts whose SamAccountName or Name matches common service-account conventions such as svc-, service-, app-, sql-, or admin-svc.
Related Testsโ
Test-MtAdUserDelegationConfiguredCountTest-MtAdUserDelegationDetails
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-USER-21 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserKnownServiceAccountDetails |
| Tags | AD, AD-USER-21, AD.User |
Sourceโ
- Pester test:
tests/ad/user/Test-MtAdUserKnownServiceAccountDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserKnownServiceAccountDetails.ps1

