Skip to content
arrow_back
search
ISM-1939 policy ASD Information Security Manual (ISM)

Limit Domain and Enterprise Admin Group Memberships

Reduce the number of users in highly privileged groups for better security.

record_voice_over

Plain language

This control is about making sure only a small number of people have access to the most powerful and sensitive parts of your computer network. If too many people are in these special groups, it increases the risk of someone accidentally or intentionally causing harm to your system, which could lead to loss of important data or system downtime.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly-privileged security groups is minimised.
policy ASD Information Security Manual (ISM) ISM-1939
priority_high

Why it matters

Excessive membership of Domain/Enterprise Admin groups increases risk of full domain compromise, data breaches, and major service disruption if an account is misused or stolen.

settings

Operational notes

Audit Domain Admins/Enterprise Admins regularly, remove non-essential accounts, and use time-bound elevation (e.g. PAM) so standing privileged group membership is minimised.

Mapping detail

Mapping

Direction

Controls