Skip to content
arrow_back
search
ISM-1841 policy ASD Information Security Manual (ISM)

Restrict Domain Joining to Admin Users Only

Only authorised users can add computers to the network to maintain security.

record_voice_over

Plain language

This rule ensures that only the right people, usually the IT folks with special permissions, can connect new computers to your company's network. It matters because if anyone could add devices, it could allow hackers to sneak in with unsafe computers and potentially cause data breaches or system failures.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unprivileged user accounts cannot add machines to the domain.
policy ASD Information Security Manual (ISM) ISM-1841
priority_high

Why it matters

Allowing unprivileged users to join devices can add untrusted hosts to the domain, enabling unauthorised access and increasing malware risk.

settings

Operational notes

Audit domain-join rights (e.g., AD 'Add workstations to domain') and restrict to approved admin groups; monitor domain-join events for misuse.

Mapping detail

Mapping

Direction

Controls