Skip to main content
Version: 2.2.1-preview

AD-USER-23 - Enabled built-in administrator details should be retrievable

Overview​

Enabled built-in administrator style accounts provide immediate opportunities for misuse if their credentials are exposed. A simple inventory of active accounts in this category helps confirm whether emergency or legacy access remains enabled unnecessarily.

  • Exposure review: Enabled privileged accounts increase attack surface.
  • Account validation: Confirms which sensitive accounts remain active.
  • Operational control: Supports decisions to disable or tightly restrict use.

Security Recommendation​

  • Disable built-in administrator accounts when not required.
  • If they must remain enabled, restrict sign-in paths and monitor all usage.
  • Ensure password rotation, MFA-equivalent controls, and break-glass procedures are documented.

How the Test Works​

This test returns enabled user accounts that match the built-in administrator RID (-500) or are marked as critical system objects.

  • Test-MtAdUserBuiltInAdminCount
  • Test-MtAdUserBuiltInAdminLastLogonDetails

Test Metadata​

FieldValue
Test IDAD-USER-23
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserBuiltInAdminEnabledDetails
TagsAD, AD-USER-23, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserBuiltInAdminEnabledDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserBuiltInAdminEnabledDetails.ps1