Skip to content
arrow_back
search
ISM-1838 policy ASD Information Security Manual (ISM)

Restrict UserPassword Attribute in AD Accounts

The UserPassword field should not be used to ensure account security.

record_voice_over

Plain language

In a nutshell, this control is about ensuring that the 'UserPassword' field in Active Directory (AD), which is a system many businesses use to manage user accounts, is not utilised to store actual passwords. This is important because mishandling passwords can lead to security breaches, putting sensitive data at risk and potentially harming your business’s reputation and finances.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The UserPassword attribute for user accounts is not used.
policy ASD Information Security Manual (ISM) ISM-1838
priority_high

Why it matters

If the AD UserPassword attribute is populated, attackers who read directory data could obtain credentials and compromise accounts, enabling unauthorised access and data loss.

settings

Operational notes

Periodically scan AD for any accounts with the UserPassword attribute set, block write access to it, and train administrators to never store passwords in directory attributes.

Mapping detail

Mapping

Direction

Controls