Skip to main content
Version: 2.2.1-preview

AD-USER-24 - Built-in administrator last logon details should be retrievable

Overview​

Knowing when built-in administrator style accounts last authenticated is critical for detecting stale privileged access and spotting suspicious activity.

  • Unexpected use detection: Recent logons on sensitive accounts may warrant investigation.
  • Stale privilege cleanup: Dormant privileged accounts should be reviewed or disabled.
  • Incident response: Last logon data helps reconstruct privileged account activity.

Security Recommendation​

  • Investigate interactive or unexpected usage of RID 500 accounts.
  • Disable or tightly restrict privileged accounts with no valid business need.
  • Correlate recent logons with change windows, tickets, and admin workflows.

How the Test Works​

This test lists built-in administrator style accounts and returns their LastLogonDate plus the number of days since the recorded logon.

  • Test-MtAdUserBuiltInAdminEnabledDetails
  • Test-MtAdUserBuiltInAdminPasswordAgeDetails

Test Metadata​

FieldValue
Test IDAD-USER-24
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserBuiltInAdminLastLogonDetails
TagsAD, AD-USER-24, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserBuiltInAdminLastLogonDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserBuiltInAdminLastLogonDetails.ps1