Skip to main content

Overview

Enumerate user accounts in SCCM database. This command provides comprehensive user intelligence including domain accounts, login patterns, and user-device relationships.

Syntax

Parameters

string
The IP address, FQDN, or NetBIOS name of the SMS Provider to connect to
string
The three-character site code (e.g., “PS1”)
string
Filter users by name pattern (supports partial matching)
string
Specify properties to retrieve (can be used multiple times)
string
Custom WQL WHERE clause for advanced filtering
boolean
Return count of results only
boolean
Display all user properties

Examples

Key Properties

Required Permissions

SMS Admins local group membership on the SMS Provider server

Intelligence Gathering

High-Value Targets:
Service Accounts:
Naming Conventions:
  • Administrative accounts: admin, administrator prefixes
  • Service accounts: svc-, service- prefixes
  • Personal accounts: firstname.lastname format
  • Shared accounts: shared-, team- prefixes
Domain Analysis:
  • Multiple domains indicate complex environments
  • Domain trust relationships
  • Cross-domain user access patterns

Common Queries

Use Cases

High-Privilege Users:
  • Domain administrators and privileged accounts
  • Service accounts with elevated permissions
  • Shared administrative accounts
User Activity Analysis:
  • Login patterns and frequency
  • Account usage patterns
  • Dormant or inactive accounts
Credential Targeting:
  • Focus on administrative and service accounts
  • Identify high-value user targets
  • Map user privilege relationships
Lateral Movement:
  • User-device relationship mapping
  • Cross-domain access patterns
  • Service account abuse opportunities