How To Find All Services that Uses Administrator Account to Start

Reset the local admin password the other day and I needed to find out all services that rely on the local admin account to run so no interruption would happen after the reboot. Obviously, the easiest way to find out is using PowerShell. But how?

I first tried the Get-Service cmdlet but found that it doesn’t return the value for the log-on account (service account) that runs the service. Maybe I’m missing something here…

Then, I turned my eyes to another cmdlet Get-WmiObject that seems to pull more information about the service, including the log-on account I was looking for , though it’s named as StartName as the result.

So, here is the final command I ran that list all the services that use Admin account to start.

Get-WmiObject Win32-Service -ComputerName computername | Select DisplayName, StartName | Where-Object {$_.StartName -eq "administrator"}

If you want to check for multiple servers, type in all the names after -ComputerName, separated by the comma.

Leave a Reply

Your email address will not be published. Required fields are marked *