Skip to content
arrow_back
search
ISM-1836 policy ASD Information Security Manual (ISM)

Require Kerberos Pre-Authentication for User Accounts

All user accounts need extra verification when logging in for better security.

record_voice_over

Plain language

This control means that every user account in the organisation needs to have extra verification when logging in, known as Kerberos pre-authentication. This matters because it adds a layer of security to prevent unauthorised access - imagine if someone could easily break into your email or work systems because your account doesn’t have enough protection.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

User accounts require Kerberos pre-authentication.
policy ASD Information Security Manual (ISM) ISM-1836
priority_high

Why it matters

Without Kerberos pre-authentication, attackers can perform offline password guessing (AS-REP roasting), risking unauthorised access to sensitive data.

settings

Operational notes

Enforce Kerberos pre-authentication on all user accounts and regularly audit AD/IdP settings to detect any accounts with pre-auth disabled.

Mapping detail

Mapping

Direction

Controls