AD-USER-23 - Enabled built-in administrator details should be retrievable
Overviewβ
Enabled built-in administrator style accounts provide immediate opportunities for misuse if their credentials are exposed. A simple inventory of active accounts in this category helps confirm whether emergency or legacy access remains enabled unnecessarily.
- Exposure review: Enabled privileged accounts increase attack surface.
- Account validation: Confirms which sensitive accounts remain active.
- Operational control: Supports decisions to disable or tightly restrict use.
Security Recommendationβ
- Disable built-in administrator accounts when not required.
- If they must remain enabled, restrict sign-in paths and monitor all usage.
- Ensure password rotation, MFA-equivalent controls, and break-glass procedures are documented.
How the Test Worksβ
This test returns enabled user accounts that match the built-in administrator RID (-500) or are marked as critical system objects.
Related Testsβ
Test-MtAdUserBuiltInAdminCountTest-MtAdUserBuiltInAdminLastLogonDetails
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-23 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserBuiltInAdminEnabledDetails |
| Tags | AD, AD-USER-23, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserBuiltInAdminEnabledDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserBuiltInAdminEnabledDetails.ps1

