Skip to content
arrow_back
search
ISM-1926 policy ASD Information Security Manual (ISM)

Ensure Exclusive Usage of Microsoft AD Servers

Ensure Microsoft AD servers only run their intended roles, no additional apps unless security-related.

record_voice_over

Plain language

This control is about making sure that certain types of Microsoft servers, which help manage who can access what in your computer systems, are used only for their specific purposes. This matters because if these servers are used for other things, they could be more vulnerable to attackers who might gain access to your sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their designed role and no other applications or services are installed, unless they are security related.
policy ASD Information Security Manual (ISM) ISM-1926
priority_high

Why it matters

Multipurpose use of Microsoft AD servers increases attack surface, risking critical access controls and potential data breaches.

settings

Operational notes

Regularly audit server roles and maintain an inventory to ensure no unauthorised applications are installed on AD servers.

Mapping detail

Mapping

Direction

Controls