Skip to content
arrow_back
search
ISM-1839 policy ASD Information Security Manual (ISM)

Secure Account Properties in Active Directory

Do not use account fields that everyone can see to store passwords.

record_voice_over

Plain language

This control is about making sure people don't store passwords in places where they can be easily accessed by anyone who shouldn't have them, like general account information in Active Directory. The risk here is that if sensitive data like passwords are stored where just anyone can see them, it becomes much easier for them to be misused, leading to security breaches and potentially serious consequences for the organisation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Account properties accessible by unprivileged users are not used to store passwords.
policy ASD Information Security Manual (ISM) ISM-1839
priority_high

Why it matters

If passwords are stored in AD account attributes readable by unprivileged users, attackers can harvest credentials and escalate access, leading to broader compromise.

settings

Operational notes

Audit AD user attributes (e.g., description, comment, notes) and remove any stored passwords or secrets from fields readable by unprivileged users.

Mapping detail

Mapping

Direction

Controls