Skip to content
arrow_back
search
ISM-1833 policy ASD Information Security Manual (ISM)

Limit Privileges for User Accounts in Active Directory

User accounts are set up with just the access they need, nothing extra.

record_voice_over

Plain language

This control is about making sure user accounts in your organisation have just enough permission to do their jobs, nothing more. This matters because if accounts have too much access, a mistake or malicious action could harm sensitive information or cause other serious issues.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

User accounts are provisioned with the minimum privileges required.
policy ASD Information Security Manual (ISM) ISM-1833
priority_high

Why it matters

If AD user accounts have excessive group memberships or delegated rights, misuse or compromise can enable unauthorised access to sensitive data and systems.

settings

Operational notes

Periodically review AD user group memberships and delegated permissions against role needs; promptly remove elevated or stale access when duties change or staff leave.

Mapping detail

Mapping

Direction

Controls