Skip to content
arrow_back
search
ISM-1920 policy ASD Information Security Manual (ISM)

Prevent Self-enrollment on Untrusted Devices

Users cannot set up multi-factor authentication on devices that aren't trusted to ensure data security.

record_voice_over

Plain language

This control ensures that people in your organisation can't set up extra security measures, like multi-factor authentication, on devices that aren't trusted by the company. This is important because untrusted devices could be insecure or compromised, which means sensitive data could be at risk of being stolen if accessed from one of these devices.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When multi-factor authentication is used to authenticate users to online services, online customer services, systems or data repositories – that process, store or communicate their organisation's sensitive data or sensitive customer data – users are prevented from self-enrolling into multi-factor authentication from untrustworthy devices.
policy ASD Information Security Manual (ISM) ISM-1920
priority_high

Why it matters

Allowing MFA self-enrolment from untrusted devices increases the risk of account takeover and unauthorised access to sensitive services and data.

settings

Operational notes

Require MFA enrolment only from trusted, managed devices (e.g., domain-joined/MDM compliant) and block enrolment from unknown endpoints; review trusted device rules regularly.

Mapping detail

Mapping

Direction

Controls