AD-USER-24 - Built-in administrator last logon details should be retrievable
Overviewβ
Knowing when built-in administrator style accounts last authenticated is critical for detecting stale privileged access and spotting suspicious activity.
- Unexpected use detection: Recent logons on sensitive accounts may warrant investigation.
- Stale privilege cleanup: Dormant privileged accounts should be reviewed or disabled.
- Incident response: Last logon data helps reconstruct privileged account activity.
Security Recommendationβ
- Investigate interactive or unexpected usage of RID 500 accounts.
- Disable or tightly restrict privileged accounts with no valid business need.
- Correlate recent logons with change windows, tickets, and admin workflows.
How the Test Worksβ
This test lists built-in administrator style accounts and returns their LastLogonDate plus the number of days since the recorded logon.
Related Testsβ
Test-MtAdUserBuiltInAdminEnabledDetailsTest-MtAdUserBuiltInAdminPasswordAgeDetails
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-24 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserBuiltInAdminLastLogonDetails |
| Tags | AD, AD-USER-24, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserBuiltInAdminLastLogonDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserBuiltInAdminLastLogonDetails.ps1

