Skip to content
arrow_back
search
ISM-1834 policy ASD Information Security Manual (ISM)

Ensure No Duplicate SPNs in Active Directory

Make sure there are no duplicate identifiers for network services in the organisation's Active Directory system.

record_voice_over

Plain language

This control is about making sure there aren't any repeat identifiers for network services in our organisation's Active Directory system. If there are duplicates, it can confuse the system and potentially allow unauthorised access to sensitive information, leading to security breaches or disruptions in services.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Duplicate SPNs do not exist within the domain.
policy ASD Information Security Manual (ISM) ISM-1834
priority_high

Why it matters

Duplicate SPNs can break Kerberos integrity, letting attackers request tickets for the wrong account and impersonate services to gain access.

settings

Operational notes

Run setspn -X regularly to find duplicate SPNs, then remove or correct them so each SPN maps to only one AD account.

Mapping detail

Mapping

Direction

Controls