Skip to content
arrow_back
search
ISM-1933 policy ASD Information Security Manual (ISM)

Restrict DCSync Permissions on Service Accounts

Ensure service accounts with SPNs can't simulate domain controller operations.

record_voice_over

Plain language

This control is all about making sure certain service accounts in your organisation's computer network don't have too much power. These accounts often need to do specific tasks but if they can pretend to be a domain controller, it could allow someone to steal or change sensitive data. Keeping these permissions in check prevents major security risks.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Service accounts configured with an SPN do not have DCSync permissions.
policy ASD Information Security Manual (ISM) ISM-1933
priority_high

Why it matters

If SPN service accounts have DCSync rights, attackers can replicate AD data, steal credentials and compromise the domain.

settings

Operational notes

Audit SPN service accounts and confirm they lack DCSync/replication rights (Get-ADPermission), removing any found.

Mapping detail

Mapping

Direction

Controls