Skip to content
arrow_back
search
ISM-1844 policy ASD Information Security Manual (ISM)

Prevent Non-Controller Accounts from Delegating Services

Ensure non-domain controller accounts can't be used to delegate services in Active Directory.

record_voice_over

Plain language

This control is about ensuring that computer accounts which are not managing the overall network (non-domain controllers) don't have permission to sneakily use services they shouldn’t in your organisation through Microsoft Active Directory. If we're not careful here, someone might exploit these accounts to access sensitive information or even disrupt your business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Computer accounts that are not Microsoft AD DS domain controllers are not trusted for delegation to services.
policy ASD Information Security Manual (ISM) ISM-1844
priority_high

Why it matters

If non-domain controller computer accounts are trusted for delegation, attackers can impersonate services, escalate privileges and move laterally.

settings

Operational notes

Audit AD delegation (Trusted for delegation/Constrained) and ensure only domain controllers are permitted; remove delegation from all others.

Mapping detail

Mapping

Direction

Controls