AD-USER-22 - Built-in administrator account count should be retrievable
Overviewβ
Built-in and critical administrator-related accounts are among the most sensitive identities in Active Directory. Attackers frequently target these accounts because they provide durable, high-impact access.
- High-value targets: RID 500 accounts are especially attractive to attackers.
- Detection support: Helps validate whether renamed administrator accounts still exist.
- Tier-0 review: Critical system objects warrant extra monitoring and protection.
Security Recommendationβ
- Minimize use of built-in administrator accounts.
- Monitor all RID 500 activity closely.
- Apply strong credential protection and privileged access controls.
- Review critical system accounts for expected state and usage.
How the Test Worksβ
This test counts user objects whose SID ends in -500 or are marked as isCriticalSystemObject.
Related Testsβ
Test-MtAdUserBuiltInAdminEnabledDetailsTest-MtAdUserBuiltInAdminLastLogonDetailsTest-MtAdUserBuiltInAdminPasswordAgeDetails
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-22 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserBuiltInAdminCount |
| Tags | AD, AD-USER-22, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserBuiltInAdminCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserBuiltInAdminCount.ps1

