Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

AdminCount

← Back to Glossary
By NHI Mgmt Group Updated September 26, 2026 Domain: Governance, Ownership & Risk

AdminCount is an attribute on Active Directory objects that helps identify accounts that are or were members of protected groups. A value of 1 does not always mean the account is currently privileged, but it does signal that the object may still carry remnants of elevated protection and should be reviewed carefully.

What AdminCount Means in Active Directory

AdminCount is best understood as a tracking signal, not a current privilege verdict. It shows that an object has been associated with protected group membership and may still retain security settings that deserve closer review.

That matters because the attribute can outlive the privilege state that created it. An account may no longer be in a protected group, yet still carry inherited protection markers or ACL history that affect how it is governed and investigated.

Why AdminCount Exists and What It Reveals

In Active Directory, protected groups receive special handling to reduce the chance that highly privileged accounts are exposed to broad delegation or inherited control paths. AdminCount helps flag objects that were once treated as sensitive in that model.

Practically, the attribute becomes a clue that the object has crossed a privilege boundary at some point. That makes it useful for discovery, hygiene checks, and understanding why an account may behave differently from ordinary directory objects.

How AdminCount Affects Security Review

AdminCount can indicate that an account still deserves manual scrutiny even if it no longer appears privileged on paper. Reviewers often use it to find objects that may have retained protection, restrictive permissions, or unexpected access behavior after group changes.

Because the attribute is historical in nature, it should be interpreted alongside current group membership, delegated permissions, and effective access. A value of 1 is a prompt to investigate the object’s present state, not a shortcut to assume active administrative rights.

Common Misreadings and Operational Consequences

The most common mistake is treating AdminCount as proof of live privilege. In reality, it is a persistence signal that can remain after access has changed, which means it can both overstate and understate actual risk if used alone.

That creates a governance issue: stale protection markers can complicate entitlement reviews, account lifecycle cleanup, and visibility into whether privileged protections have been fully removed from an object.

Risk and Threat Considerations

AdminCount is a useful review marker because stale privileged remnants can obscure the true security posture of an account. If teams assume the attribute always reflects current privilege, they may miss overprotected objects, incomplete deprovisioning, or accounts that still have sensitive ACL history.

Failure mechanism: Protected-group handling can leave residual security descriptors or protection flags behind after group membership changes, creating a gap between directory metadata and effective access.

Impact: That mismatch can lead to incorrect access decisions, lingering exposure on formerly privileged accounts, and slower detection of privilege hygiene problems during audits or incident response.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeAdminCount flags objects tied to protected privilege history and access review.
IA-5 — Authenticator ManagementAdminCount often appears in account hygiene work where privileged credentials must be reviewed.
Recommendation — Verify effective access and remove unnecessary elevated permissions from formerly privileged accounts. Review credential state for accounts that previously held elevated protections.
NIST CSF 2.0ID.AM-05 — Assets are prioritized based on classification, criticality, and business valueAdminCount helps identify sensitive directory objects that need prioritized review.
Recommendation — Prioritize directory objects with privileged history in asset and account review workflows.
ISO/IEC 27001:2022A.5.15 — Access controlAdminCount relates to directory access governance and review of protected accounts.
Recommendation — Confirm access rights for accounts marked by privileged history and remove obsolete protection.
CIS Controls v8CIS-6 — Access Control ManagementAdminCount supports account review and cleanup after privilege changes.
Recommendation — Review and remediate access on accounts that retain privileged protection remnants.

Practitioner Guidance

What to watch for: Treat AdminCount as a review trigger when investigating accounts that were once privileged, especially if current group membership no longer matches the attribute. The key question is whether the object’s present permissions and protection state still align with how it is used today.

Practitioner takeaway: Use AdminCount to find directory objects that deserve validation, then confirm effective access and cleanup state rather than relying on the attribute as a current authorization source.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org