Skip to content
arrow_back
search
ISM-1927 policy ASD Information Security Manual (ISM)

Restrict Access to Microsoft Active Directory Servers

Only privileged users should access key Microsoft servers for security.

record_voice_over

Plain language

This control is about making sure only the right people have access to key Microsoft servers like Active Directory, which are critical for managing your computer systems. If these servers are accessed by the wrong people, it could lead to serious problems, such as a potential data breach, loss of sensitive information, or disruptions to your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to privileged users that require access.
policy ASD Information Security Manual (ISM) ISM-1927
priority_high

Why it matters

Unauthorised access to AD DS/CS/FS or Entra Connect servers can enable credential theft, certificate abuse and full domain compromise, disrupting critical business services.

settings

Operational notes

Restrict logon (RDP/console) to AD DS/CS/FS and Entra Connect servers to approved admins only; regularly review group membership, logon rights and access logs.

Mapping detail

Mapping

Direction

Controls