One-Liner: Find a Renamed and Relocated AD Guest Account WITHOUT using the Well-Known SID

So... someone decided to rename and move the domain's Guest account.

You could find searching via the well-know SID...

SID: S-1-5-21domain-501
Name: Guest
Description: A user account for people who do not have individual accounts. This user account does not require a password. By default, the Guest account is disabled.

Or... you could try this little trick...

 

 
Get-ADUser -Filter "primaryGroupID -ne 513“ 

capture197