Skip to content
arrow_back
search
ISM-1929 policy ASD Information Security Manual (ISM)

Ensure LDAP Signing on AD DS Domain Controllers

Make sure AD servers use secure communication to prevent unauthorised access.

record_voice_over

Plain language

This control ensures that communications with Active Directory servers, which help manage user access in your organisation, are secure. If this isn't done, unauthorised people could spy on or tamper with communications, leading to potential data breaches or unauthorised access to sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.
policy ASD Information Security Manual (ISM) ISM-1929
priority_high

Why it matters

If LDAP signing is not enforced on AD DS domain controllers, attackers can tamper with LDAP traffic to gain unauthorised access.

settings

Operational notes

Confirm Domain Controllers enforce LDAP signing via Group Policy and re-check regularly to detect drift after updates or changes.

Mapping detail

Mapping

Direction

Controls