FM 13-02 Chapter 13 · Windows and Active Directory
userAccountControl flags Decode and build AD userAccountControl and msDS-SupportedEncryptionTypes, with risky flags and LDAP filters.
Local only Runs in your browser. Nothing you enter leaves this page.
userAccountControl msDS-SupportedEncryptionTypes
userAccountControl, decimal or 0x hex
Normal user 512 Disabled user 514 Password never expires 66048 Disabled, never expires 66050 Computer 4096 Domain controller 532480 Read-only DC 83890176 No preauth, never expires 4260352
Decimal 66048 Copy
Hex 0x00010200 Copy
Flags set NORMAL_ACCOUNT | DONT_EXPIRE_PASSWORD Copy DONT_EXPIRE_PASSWORD : Common on service accounts. Long-lived passwords are what Kerberoasting cracks offline.
Flags SCRIPT 0x00000001 · 1 Logon script runs ACCOUNTDISABLE 0x00000002 · 2 Account is disabled HOMEDIR_REQUIRED 0x00000008 · 8 Home folder required LOCKOUT 0x00000010 · 16 Account is locked out PASSWD_NOTREQD 0x00000020 · 32 No password requiredrisk PASSWD_CANT_CHANGE 0x00000040 · 64 User cannot change password ENCRYPTED_TEXT_PWD_ALLOWED 0x00000080 · 128 Store password with reversible encryptionrisk TEMP_DUPLICATE_ACCOUNT 0x00000100 · 256 Local account for a user from another domain NORMAL_ACCOUNT 0x00000200 · 512 Normal user account INTERDOMAIN_TRUST_ACCOUNT 0x00000800 · 2048 Trust account for a trusting domain WORKSTATION_TRUST_ACCOUNT 0x00001000 · 4096 Computer account (workstation or member server) SERVER_TRUST_ACCOUNT 0x00002000 · 8192 Domain controller computer account DONT_EXPIRE_PASSWORD 0x00010000 · 65536 Password never expirescaution MNS_LOGON_ACCOUNT 0x00020000 · 131072 Majority Node Set (cluster) logon account SMARTCARD_REQUIRED 0x00040000 · 262144 Smart card required for interactive logonhardening TRUSTED_FOR_DELEGATION 0x00080000 · 524288 Trusted for unconstrained Kerberos delegationrisk NOT_DELEGATED 0x00100000 · 1048576 Account is sensitive and cannot be delegatedhardening USE_DES_KEY_ONLY 0x00200000 · 2097152 Use only DES keys for Kerberosrisk DONT_REQ_PREAUTH 0x00400000 · 4194304 Kerberos pre-authentication not requiredrisk PASSWORD_EXPIRED 0x00800000 · 8388608 Password has expired TRUSTED_TO_AUTH_FOR_DELEGATION 0x01000000 · 16777216 Constrained delegation with protocol transition (S4U2Self)risk NO_AUTH_DATA_REQUIRED 0x02000000 · 33554432 No PAC in service tickets for this account (MS-ADTS) PARTIAL_SECRETS_ACCOUNT 0x04000000 · 67108864 Read-only domain controller computer account USE_AES_KEYS 0x08000000 · 134217728 Use AES keys (MS-ADTS, not used by Windows) LDAP filter All set Any set Not set
Filter (userAccountControl:1.2.840.113556.1.4.803:=66048) Copy Filters use the bitwise matching rules: 1.2.840.113556.1.4.803 (AND, all bits set) and .804 (OR,
any bit set). Combine them, for example enabled users without pre-authentication: (&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
Flag names and values follow Microsoft's userAccountControl table and MS-ADTS 2.2.16; encryption
types follow MS-KILE 2.2.7.