Skip to content
arrow_back
search
ISM-1827 policy ASD Information Security Manual (ISM)

Use Dedicated Admin Accounts for Domain Controllers

Ensure domain controllers have unique admin accounts not used elsewhere for better security.

record_voice_over

Plain language

This control is about making sure that the people who manage your core computer systems have special accounts they use just for that purpose. This is important because if an intruder manages to get into these accounts, they could control your entire network. Using accounts specifically for these tasks helps limit the damage if one account is compromised.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.
policy ASD Information Security Manual (ISM) ISM-1827
priority_high

Why it matters

If domain controllers are administered with non-dedicated accounts, compromise of that account can lead to Domain Admin control and full Active Directory takeover.

settings

Operational notes

Audit Domain Admin and DC logons to confirm dedicated admin accounts are used only for AD DS/domain controller administration, not email or daily user activity.

Mapping detail

Mapping

Direction

Controls