Skip to content
arrow_back
ISM-1941policyASD Information Security Manual (ISM)

Restrict Computer Accounts in Privileged Security Groups

Ensure computer accounts aren't in highly privileged security groups like Domain Admins.

record_voice_over

Plain language

Computer accounts should never have the same high-level privileges as key IT personnel. If a computer account has these privileges, an attacker could use it to take control of your entire network, leading to potential data loss or business disruption.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.
policyASD Information Security Manual (ISM)ISM-1941
priority_high

Why it matters

If computer accounts enter privileged groups, attackers could exploit them to control your entire IT environment, leading to severe data breaches.

settings

Operational notes

Regular reviews and monitoring of highly privileged groups mitigate the risk of unauthorised access, ensuring security integrity is maintained.

build

Implementation tips

  • IT team should review existing security groups. Identify all accounts in high-level groups like Domain Admins to ensure no computer accounts have inappropriate access.
  • System administrators should establish clear policies. Define which accounts can be added to privileged groups and ensure these are human, not computer, accounts.
  • IT managers should schedule regular training. Provide staff with clear instructions on the risks of misconfiguring account privileges and avoid adding computer accounts to sensitive groups.
  • IT departments should use automated tools. Set up alerts or reports to identify any changes to privileged groups and inspect these changes immediately.
  • Security officers should conduct quarterly audits. Review group memberships to confirm only authorised personnel have access to high-privilege groups.
fact_check

Audit / evidence tips

  • Aska list of current members of high-privileged groups: Domain Admins, Enterprise AdminsLook atthe member names to ensure no computer accounts are includedGoodis a list with only human user accounts
  • Look ata section covering who can assign accounts to privileged groupsGooddetails clear restrictions and authorisation processes
  • Asklogs or reports showing recent changes in group memberships. Look to confirm how often computer accounts were added to or removed from privileged groupsGoodshows zero inappropriate changes
  • Look atrecent completion of courses or materials focusing on privilege managementGoodincludes completed training logs
  • Askdocumentation on automated monitoring setups for group membership changesLook atconfiguration settings and alert proceduresGoodincludes documented processes for immediate alert responses
link

Cross-framework mappings

How ISM-1941 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(1)expand_less
Annex A 8.15ISM-1941 requires preventing computer accounts from being members of highly privileged AD groups (e.g

E8

ControlNotesDetails
handshakeSupports(1)expand_less
E8-RA-ML2.7ISM-1941 requires that computer accounts are not placed into highly privileged AD security groups (e.g

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls