Skip to content
arrow_back
search
ISM-1930 policy ASD Information Security Manual (ISM)

Prevent Storing Passwords in Group Policy Preferences

Ensure passwords are not saved in Group Policy to enhance security.

record_voice_over

Plain language

This rule is about making sure that no one saves passwords inside the system settings of your organisation’s network. It's crucial because if someone malicious gains access, they could easily find these passwords and use them to break into your secure systems, putting sensitive information at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Passwords are prevented from being stored in Group Policy Preferences.
policy ASD Information Security Manual (ISM) ISM-1930
priority_high

Why it matters

If passwords are stored in Group Policy Preferences, attackers can decrypt them from SYSVOL and rapidly escalate privileges across the domain.

settings

Operational notes

Audit GPP for cpassword entries and remove/replace them; use LAPS/managed service accounts and restrict SYSVOL access and replication.

Mapping detail

Mapping

Direction

Controls