Skip to content
arrow_back
search
ISM-1932 policy ASD Information Security Manual (ISM)

Limit Service Accounts with SPNs in Active Directory

Reduce the number of special accounts to improve security in Active Directory.

record_voice_over

Plain language

This control is about reducing the number of special accounts, called service accounts, that have something called a Service Principal Name in Active Directory. By keeping the number of these accounts to a minimum, it helps prevent unauthorised access to important systems. If this isn't done, hackers could exploit these special accounts to access sensitive data and control your systems, which could lead to data breaches and operational disruption.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The number of service accounts configured with an SPN is minimised.
policy ASD Information Security Manual (ISM) ISM-1932
priority_high

Why it matters

Too many AD service accounts with SPNs increase Kerberoasting and credential theft risk, enabling lateral movement and broader domain compromise.

settings

Operational notes

Periodically inventory accounts with SPNs, remove unused SPNs, consolidate where possible, and retire unneeded service accounts to minimise attack surface.

Mapping detail

Mapping

Direction

Controls