Skip to content
arrow_back
search
ISM-1941 policy ASD Information Security Manual (ISM)

Restrict Computer Accounts from Privileged Groups

Ensure computer accounts don't have high-level admin privileges within Active Directory.

record_voice_over

Plain language

This control is about making sure that the computer accounts in a network don't have too much power. Think of a computer account like a key card. If every computer has a key card for the CEO's office, that's risky. Instead, give them access only to the areas they need. If this isn't done, a compromised computer could act like the CEO's key card, gaining access to sensitive information and potentially causing harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.
policy ASD Information Security Manual (ISM) ISM-1941
priority_high

Why it matters

If computer accounts join Domain/Enterprise Admins, a compromised host can obtain full domain privileges, enabling broad data access and service disruption.

settings

Operational notes

Audit Domain/Enterprise Admins and similar groups to confirm no computer accounts are members; remove any found and investigate how membership occurred.

Mapping detail

Mapping

Direction

Controls