Skip to content
arrow_back
search
ISM-1940 policy ASD Information Security Manual (ISM)

Restrict Service Accounts from Privileged AD Groups

Ensure service accounts are not part of high-level admin groups in Active Directory.

record_voice_over

Plain language

This control ensures that service accounts, which are special types of user accounts used by software programs to interact with your systems, do not have the same high-level privileges as human administrators in your network. By doing this, you reduce the risk of these accounts being misused or abused by attackers to gain control of your computer systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Service accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.
policy ASD Information Security Manual (ISM) ISM-1940
priority_high

Why it matters

If service accounts are placed in Domain/Enterprise Admins or similar groups, compromise of the account can lead to full domain takeover and major outages.

settings

Operational notes

Periodically audit AD group memberships for service accounts; alert on additions to Domain Admins, Enterprise Admins, or other privileged groups.

Mapping detail

Mapping

Direction

Controls