Skip to main content
Version: 2.2.1-preview

AD-USER-25 - Built-in administrator password age details should be retrievable

Overview​

Highly privileged accounts with old passwords are prime targets for password spraying, credential theft, and persistence. Reviewing password age for built-in administrator style accounts helps validate that sensitive credentials are rotated appropriately.

  • Credential risk reduction: Long-lived privileged passwords increase exposure.
  • Control validation: Supports verification of password rotation practices.
  • Exception tracking: Highlights accounts with non-expiring privileged credentials.

Security Recommendation​

  • Rotate passwords for privileged accounts on a defined schedule.
  • Avoid non-expiring passwords on privileged identities wherever possible.
  • Review break-glass or emergency accounts separately with compensating controls.

How the Test Works​

This test lists built-in administrator style accounts and reports PasswordLastSet, calculated password age in days, and PasswordNeverExpires state.

  • Test-MtAdUserBuiltInAdminCount
  • Test-MtAdUserBuiltInAdminLastLogonDetails

Test Metadata​

FieldValue
Test IDAD-USER-25
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserBuiltInAdminPasswordAgeDetails
TagsAD, AD-USER-25, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserBuiltInAdminPasswordAgeDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserBuiltInAdminPasswordAgeDetails.ps1