Skip to content
arrow_back
search
ISM-1619 policy ASD Information Security Manual (ISM)

Configure Service Accounts as Managed Service Accounts

Ensure service accounts are created as Managed Service Accounts for improved security.

record_voice_over

Plain language

Using Managed Service Accounts (MSAs) for service accounts means that these accounts are better protected and managed automatically. If this isn't done, your organisation might leave backdoor access open to critical systems, potentially leading to data breaches or service disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Service accounts are created as group Managed Service Accounts.
policy ASD Information Security Manual (ISM) ISM-1619
priority_high

Why it matters

Without group Managed Service Accounts, service credentials are harder to protect, increasing risk of account takeover, unauthorised access and data breaches.

settings

Operational notes

Use group Managed Service Accounts for services, remove unused gMSAs, and regularly review which hosts and services are permitted to use each gMSA.

Mapping detail

Mapping

Direction

Controls