Skip to content
arrow_back
search
ISM-1842 policy ASD Information Security Manual (ISM)

Use Privileged Accounts for Domain Machine Addition

Special accounts are used for adding computers to the network for security purposes.

record_voice_over

Plain language

This control is about using special accounts with extra privileges to add computers to your network. It's like having a trusted person to do the important job of letting new devices join your secure group. If you don't use these trusted accounts, unauthorised devices could sneak in, causing data breaches or disrupting operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Dedicated privileged service accounts are used to add machines to the domain.
policy ASD Information Security Manual (ISM) ISM-1842
priority_high

Why it matters

If non-privileged accounts can add machines to the domain, unauthorised hosts may join, enabling credential theft and lateral movement.

settings

Operational notes

Use a dedicated privileged service account for domain joins, restrict who can use it, and routinely audit domain-add events for misuse.

Mapping detail

Mapping

Direction

Controls