Skip to content
arrow_back
ISM-1935policyASD Information Security Manual (ISM)

Prevent Unconstrained Delegation in Domain Services

Ensure computer accounts do not allow unrestricted delegation to protect security.

record_voice_over

Plain language

Unconstrained delegation is a setting that, if misconfigured, can allow attackers to impersonate others in your network. It's crucial to prevent this to avoid sensitive information being exposed or systems being misused by those who shouldn't have access.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2024

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Computer accounts are not configured for unconstrained delegation.
policyASD Information Security Manual (ISM)ISM-1935
priority_high

Why it matters

Unconstrained delegation could let attackers impersonate privileged users and access domain resources, exposing sensitive data and compromising critical systems.

settings

Operational notes

Audit AD computer accounts for "Trust this computer for delegation" and ensure unconstrained delegation is disabled; investigate and remediate any accounts with it enabled.

build

Implementation tips

  • IT team should review the current delegation settings on server accounts to ensure they are not set for unconstrained delegation. This involves using administrator tools to check each server's properties and ensure that sensitive configurations are disabled.
  • System administrators need to document each server's delegation settings. They should capture which servers have constrained delegation enabled and keep a record in a secured document.
  • Managers should verify that all team members responsible for server management understand the risks associated with unconstrained delegation. Host a training session to explain these risks and the importance of configuring delegation correctly.
  • The IT manager should schedule regular audits of the server settings. Use a checklist detailing the correct configurations and check each server aligns with these security practices.
  • System owners should implement a change management process. This ensures any changes to delegation settings are documented and approved by a responsible person before being applied, preventing accidental exposures or misconfigurations.
fact_check

Audit / evidence tips

  • AskThe server configuration audit logs: Request logs that detail changes to server settings concerning delegationGoodShows logs with approved changes and dates indicating regular audits
  • AskDocumentation on delegation settings: Obtain the record that lists the delegation settings of each serverGoodIncludes a detailed list with each server clearly marked
  • AskTraining records: Request evidence of training sessions conducted on the risks of unconstrained delegationGoodContains dates, list of attendees, and topics covered
  • AskChange management records: Request proof of change management processes for delegation settingsGoodIncludes dates, detailed change descriptions, and responsible approvers
  • AskA report on security incidents: Request any incident reports related to delegation settingsGoodIncludes resolved incidents with actions taken to prevent future occurrences
link

Cross-framework mappings

How ISM-1935 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.9ISM-1935 mandates that Active Directory computer accounts are not configured for unconstrained delegation, a specific security measure to...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls