Skip to content
arrow_back
search
ISM-1936 policy ASD Information Security Manual (ISM)

Prevent Usage of sIDHistory in User Accounts

Ensure user accounts do not use the sIDHistory attribute for security purposes.

record_voice_over

Plain language

The sIDHistory is a technical feature in computer systems that helps during migrations by retaining old permissions. However, keeping it can become a backdoor for hackers. If we don't switch this off, unauthorised people might sneak into secure areas of our systems, leading to data breaches or disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The sIDHistory attribute for user accounts is not used.
policy ASD Information Security Manual (ISM) ISM-1936
priority_high

Why it matters

If sIDHistory is populated, attackers can abuse inherited legacy SIDs to escalate access and access data, leading to unauthorised changes, data breaches and service disruption.

settings

Operational notes

After migrations, verify sIDHistory is blank on all user accounts and enforce a process to prevent future population. Monitor AD changes and periodically report any non-empty sIDHistory values.

Mapping detail

Mapping

Direction

Controls