Skip to content
arrow_back
search
ISM-1829 policy ASD Information Security Manual (ISM)

Prevent Password Storage in Group Policy Preferences

Make sure passwords aren't saved in Group Policy Preferences for added security.

record_voice_over

Plain language

This control is about making sure that passwords aren't stored in what's called Group Policy Preferences, which is a Microsoft way to manage settings on lots of computers at once. Storing passwords here is risky because if someone gets hold of these settings, they could easily find and misuse these passwords, putting your entire network in danger.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Passwords are not stored in Group Policy Preferences.
policy ASD Information Security Manual (ISM) ISM-1829
priority_high

Why it matters

If passwords are stored in Group Policy Preferences, attackers can recover them and use them for lateral movement and domain compromise.

settings

Operational notes

Audit GPOs for Group Policy Preferences password fields (e.g., cpassword) and remove any found; use LAPS or a secrets vault instead.

Mapping detail

Mapping

Direction

Controls