Skip to content
arrow_back
search
ISM-1845 policy ASD Information Security Manual (ISM)

Disable User Security Group Access in Active Directory

When a user is disabled, they lose access to all security groups.

record_voice_over

Plain language

Disabling a user's account in Active Directory means they will automatically lose access to all the security groups they were part of. This is important because leaving their access active, even when they no longer work for the organisation, can be a security risk, such as unauthorised access to sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When a user account is disabled, it is removed from all security group memberships.
policy ASD Information Security Manual (ISM) ISM-1845
priority_high

Why it matters

Inactive user accounts retaining AD security group memberships can enable unauthorised access to systems and data, increasing breach risk.

settings

Operational notes

When disabling a user in Active Directory, confirm they are removed from all security groups and regularly audit disabled accounts for lingering memberships.

Mapping detail

Mapping

Direction

Controls