Skip to content
arrow_back
search
ISM-1928 policy ASD Information Security Manual (ISM)

Secure and Encrypt Backups of AD Servers

Microsoft AD server backups must be secure, encrypted, and only accessible to backup admins.

record_voice_over

Plain language

This control is about making sure backups of important Microsoft Active Directory servers are properly encrypted and only accessible to those who are supposed to handle them. This matters because if backups are not secure, they could be stolen or tampered with, leading to potential leaks of sensitive information and disruptions in operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted, stored securely and only accessible to backup administrator accounts.
policy ASD Information Security Manual (ISM) ISM-1928
priority_high

Why it matters

If AD server backups are not encrypted or tightly restricted, attackers can extract directory data or CA private keys and compromise identities and trust.

settings

Operational notes

Confirm AD/AD CS/AD FS/Entra Connect backups are encrypted and stored securely; restrict access to backup admin accounts and review access quarterly.

Mapping detail

Mapping

Direction

Controls