AD-USER-25 - Built-in administrator password age details should be retrievable
Overviewβ
Highly privileged accounts with old passwords are prime targets for password spraying, credential theft, and persistence. Reviewing password age for built-in administrator style accounts helps validate that sensitive credentials are rotated appropriately.
- Credential risk reduction: Long-lived privileged passwords increase exposure.
- Control validation: Supports verification of password rotation practices.
- Exception tracking: Highlights accounts with non-expiring privileged credentials.
Security Recommendationβ
- Rotate passwords for privileged accounts on a defined schedule.
- Avoid non-expiring passwords on privileged identities wherever possible.
- Review break-glass or emergency accounts separately with compensating controls.
How the Test Worksβ
This test lists built-in administrator style accounts and reports PasswordLastSet, calculated password age in days, and PasswordNeverExpires state.
Related Testsβ
Test-MtAdUserBuiltInAdminCountTest-MtAdUserBuiltInAdminLastLogonDetails
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-25 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserBuiltInAdminPasswordAgeDetails |
| Tags | AD, AD-USER-25, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserBuiltInAdminPasswordAgeDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserBuiltInAdminPasswordAgeDetails.ps1

