I don't know it this thread will provide any insight but it might be worth a look.
Is it possible to create functional hidden accounts in AD?
Not exactly (at least through the UI). While there is a procedure that will
*almost* allow you to hide an account even from other administrators, the
problem is that there is a little glitch in AD that lets you get around
this.
Here's the procedure (copied and pasted from a post I made to a newsgroup on
this subject):
Create a user.
Name him Jim Bob Billy Joe (okay, name him whatever you want).
Make Jim Bob Billy Joe a member of domain admins.
Create another user.
Name him Jack Schmoe.
Make Jack Schmoe a member of domain admins, as well.
As Jack Schmoe, open ADU&C.
In ADU&C, create an OU called Mine All Mine.
Right-click on the Mine All Mine OU.
Deselect permissions inheritance.
Copy existing permissions when prompted.
Remove all entries from the ACL except System and other computer-related
entries.
Add Jack Schmoe to the ACL.
Give Jack Schmoe full control permissions to the OU.
Add Jim Bob Billy Joe to the ACL.
Deny Jim Bob Billy Joe all permissions to the OU.
Create a new user in the Mine All Mine OU.
Name the user Hidden User (or whatever).
Right-click on Hidden User and bring up the properties of the object.
Perform the same procedures on the user object as you did on the OU
object (although you won't actually have to do much of anything if you
create the user in the Mine All Mine OU in the first place as opposed to
moving the user there from another OU).
Run ADU&C as Jim Bob Billy Joe.
See weird OU named Mine All Mine.
Right-click weird OU and bring up the properties of the OU.
Note results.
Try to move the OU.
Note results.
Try to rename the OU.
Note results.
Try to delete the OU.
Note results.
So, this gives you the ability to "sort of" hide a user, but here's the
glitch:
If you right-click on an object in ADU&C to which you *do* have access,
bring up the properties and select the security tab, you will see the ACL
for that object. Click "Cancel." Then right click the hidden object
mentioned above. Note difference in results.
So, as far as the hidden accounts you've mentioned, I would suspect that
they were programmatically created. Do you have any information about them
other than that you believe they exist due to the error message in the app
you ran?
Thanks,
Laura A. Robinson
Technical Instructor/Consultant
MCT, MCSE, CLI, PCLP