AD-USER-04 - Reversible encryption user count should be retrievable
Overviewβ
Reversible password encryption is effectively equivalent to storing passwords in a decryptable form. Accounts configured this way create serious exposure if the directory or credential material is compromised.
Control Typeβ
Detective
Security Recommendationβ
Disable reversible password encryption unless it is required for a documented legacy dependency that cannot be modernized immediately. Remediate those dependencies as a priority.
How the Test Worksβ
This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts with reversible-encryption-style indicators. It checks explicit reversible encryption properties when available and falls back to the relevant userAccountControl flag.
Related Testsβ
Test-MtAdUserKerberosDesOnlyCountTest-MtAdUserPasswordNotRequiredCountTest-MtAdUserNoPreAuthCount
Related linksβ
- Microsoft Defender for Identity: Unsecure account attributes
- ANSSI Active Directory checkpoints: Privileged accounts with passwords stored using reversible encryption
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-04 |
| Severity | Medium |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserReversibleEncryptionCount |
| Tags | AD, AD-USER-04, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserReversibleEncryptionCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserReversibleEncryptionCount.ps1


