Skip to content

Glossary

Machine account quota

ms-DS-MachineAccountQuota is the domain setting that lets any authenticated user create up to ten computer accounts in Active Directory by default.

The ms-DS-MachineAccountQuota attribute on the domain object defines how many computer accounts a regular authenticated user may create without any delegated permission. The default is 10, a legacy convenience so users could join their own machines to the domain. The creating user is recorded in the object's ms-DS-CreatorSID attribute and keeps control of its password and several attributes, including service principal names.

It matters because a computer account is a full security principal that attackers can create on demand. Attacker-controlled machine accounts are a key ingredient in resource-based constrained delegation abuse, several AD CS escalation paths and various relay chains, and they give a foothold identity even after the original user is disabled. Set the quota to 0 and delegate domain-join rights explicitly to a dedicated group or service account, scoped to the specific OUs where new computers should land. Before changing it, check event 4741 and ms-DS-CreatorSID to find who currently relies on self-service joins.

See Set ms-DS-MachineAccountQuota to 0 and Constrained delegation and RBCD done safely.