Skip to content
arrow_back
search
ISM-1843 policy ASD Information Security Manual (ISM)

Annual Review of Unconstrained Delegation in AD Accounts

Annually review AD accounts for unnecessary delegation and remove if no business need.

record_voice_over

Plain language

This control is all about checking each year if any accounts in your Microsoft Active Directory (AD) system can delegate their tasks without restrictions. If they don’t need to, those rights should be removed. This matters because unnecessary delegation can create security risks, like unauthorised access to sensitive information, which can lead to serious privacy breaches or financial losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

User accounts with unconstrained delegation are reviewed at least annually, and those without an SPN or demonstrated business requirement are removed.
policy ASD Information Security Manual (ISM) ISM-1843
priority_high

Why it matters

Unnecessary unconstrained delegation on AD accounts can enable credential theft and lateral movement, leading to unauthorised access.

settings

Operational notes

At least annually, list AD accounts with unconstrained delegation and remove it unless an SPN and documented business need exist; alert on changes.

Mapping detail

Mapping

Direction

Controls