Skip to content
arrow_back
search
ISM-1846 policy ASD Information Security Manual (ISM)

Restrict Pre-Windows 2000 Access Group Membership

Ensure no user accounts are added to the obsolete security group for better system security.

record_voice_over

Plain language

This control is about ensuring that outdated security rules aren't used in your computer systems. If you leave these outdated rules in place, it could make it easier for someone to get unauthorised access to sensitive information or parts of your computer network. This could put your organisation's data and operations at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The Pre-Windows 2000 Compatible Access security group does not contain user accounts.
policy ASD Information Security Manual (ISM) ISM-1846
priority_high

Why it matters

Leaving users in the Pre-Windows 2000 Compatible Access group can allow broad legacy read access, increasing risk of unauthorised data exposure.

settings

Operational notes

Periodically query Active Directory for members of the Pre-Windows 2000 Compatible Access group and remove any user accounts so the group remains empty.

Mapping detail

Mapping

Direction

Controls