Skip to main content
Version: 2.2.1-preview

AD-USER-22 - Built-in administrator account count should be retrievable

Overview​

Built-in and critical administrator-related accounts are among the most sensitive identities in Active Directory. Attackers frequently target these accounts because they provide durable, high-impact access.

  • High-value targets: RID 500 accounts are especially attractive to attackers.
  • Detection support: Helps validate whether renamed administrator accounts still exist.
  • Tier-0 review: Critical system objects warrant extra monitoring and protection.

Security Recommendation​

  • Minimize use of built-in administrator accounts.
  • Monitor all RID 500 activity closely.
  • Apply strong credential protection and privileged access controls.
  • Review critical system accounts for expected state and usage.

How the Test Works​

This test counts user objects whose SID ends in -500 or are marked as isCriticalSystemObject.

  • Test-MtAdUserBuiltInAdminEnabledDetails
  • Test-MtAdUserBuiltInAdminLastLogonDetails
  • Test-MtAdUserBuiltInAdminPasswordAgeDetails

Test Metadata​

FieldValue
Test IDAD-USER-22
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserBuiltInAdminCount
TagsAD, AD-USER-22, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserBuiltInAdminCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserBuiltInAdminCount.ps1