One-Liner: Find a Renamed and Relocated AD Guest Account WITHOUT using the Well-Known SID

So… someone decided to rename and move the domain’s Guest account.

You could find searching via the well-know SID…

SID: S-1-5-21domain-501
Name: Guest
Description: A user account for people who do not have individual accounts. This user account does not require a password. By default, the Guest account is disabled.

Or… you could try this little trick…


Get-ADUser -Filter "primaryGroupID -ne 513“ 




Comments (0)

Skip to main content