Skip to content
arrow_back
search
ISM-1938 policy ASD Information Security Manual (ISM)

Restrict Domain Computers Group in Active Directory

Prevent Domain Computers from changing anything in Active Directory for security.

record_voice_over

Plain language

This control ensures that regular computers in a network domain can't make changes to the overall directory, which is like the network's map or blueprint. It's important because if any computer could alter this map, chaos could ensue, potentially leading to data loss, breaches, or unplanned outages.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.
policy ASD Information Security Manual (ISM) ISM-1938
priority_high

Why it matters

If Domain Computers can write to AD objects, compromised PCs can alter directory settings, disrupt authentication, and enable persistence or privilege escalation.

settings

Operational notes

Review AD ACLs to ensure Domain Computers has no write/modify rights on objects; alert on any changes and remediate by removing inherited or delegated permissions.

Mapping detail

Mapping

Direction

Controls