Skip to content
arrow_back
search
ISM-1935 policy ASD Information Security Manual (ISM)

Prevent Unconstrained Delegation in Domain Services

Ensure computer accounts do not allow unrestricted delegation to protect security.

record_voice_over

Plain language

Unconstrained delegation is a setting that, if misconfigured, can allow attackers to impersonate others in your network. It's crucial to prevent this to avoid sensitive information being exposed or systems being misused by those who shouldn’t have access.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Computer accounts are not configured for unconstrained delegation.
policy ASD Information Security Manual (ISM) ISM-1935
priority_high

Why it matters

Unconstrained delegation could let attackers impersonate privileged users and access domain resources, exposing sensitive data and compromising critical systems.

settings

Operational notes

Audit AD computer accounts for "Trust this computer for delegation" and ensure unconstrained delegation is disabled; investigate and remediate any accounts with it enabled.

Mapping detail

Mapping

Direction

Controls