Skip to content
arrow_back
search
ISM-1835 policy ASD Information Security Manual (ISM)

Restrict Delegation of Privileged Active Directory Accounts

Ensure privileged accounts are marked as sensitive and cannot be delegated to maintain security.

record_voice_over

Plain language

This control is about making sure that certain high-level accounts in your system, like those with the power to make big changes, can't have their access easily transferred to others. This matters because if someone maliciously gets control of one of these accounts, they could cause serious harm to your business, like stealing sensitive data or bringing your systems down.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Privileged user accounts are configured as sensitive and cannot be delegated.
policy ASD Information Security Manual (ISM) ISM-1835
priority_high

Why it matters

Without this control, attackers could abuse delegation to compromise critical Active Directory accounts, leading to data breaches or system takedowns.

settings

Operational notes

Regularly audit privileged AD accounts to confirm “Account is sensitive and cannot be delegated” remains enabled, and alert on any changes to this setting.

Mapping detail

Mapping

Direction

Controls