Skip to main content
AD Academy
Back to all recipes
Level: JuniorLast updated:

Recursive report: who really is in Domain Admins

Get-ADGroupMember -Identity "Domain Admins" -Recursive |
  Get-ADUser -Properties LastLogonDate,Enabled |
  Select-Object Name,SamAccountName,Enabled,LastLogonDate | Sort-Object Name

Why it works this way

Nested groups hide members. -Recursive reveals those who got in through a group inside a group.

Watch out

  • In a healthy org the list is short — up to 5 dedicated accounts.
  • A service account in Domain Admins is a finding to fix, not to document.

Related events