Restrict Computer Accounts in Privileged Security Groups
Ensure computer accounts aren't in highly privileged security groups like Domain Admins.
Plain language
Computer accounts should never have the same high-level privileges as key IT personnel. If a computer account has these privileges, an attacker could use it to take control of your entire network, leading to potential data loss or business disruption.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Server Application HardeningOfficial control statement
Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.
Why it matters
If computer accounts enter privileged groups, attackers could exploit them to control your entire IT environment, leading to severe data breaches.
Operational notes
Regular reviews and monitoring of highly privileged groups mitigate the risk of unauthorised access, ensuring security integrity is maintained.
Implementation tips
- IT team should review existing security groups. Identify all accounts in high-level groups like Domain Admins to ensure no computer accounts have inappropriate access.
- System administrators should establish clear policies. Define which accounts can be added to privileged groups and ensure these are human, not computer, accounts.
- IT managers should schedule regular training. Provide staff with clear instructions on the risks of misconfiguring account privileges and avoid adding computer accounts to sensitive groups.
- IT departments should use automated tools. Set up alerts or reports to identify any changes to privileged groups and inspect these changes immediately.
- Security officers should conduct quarterly audits. Review group memberships to confirm only authorised personnel have access to high-privilege groups.
Audit / evidence tips
- Aska list of current members of high-privileged groups: Domain Admins, Enterprise AdminsLook atthe member names to ensure no computer accounts are includedGoodis a list with only human user accounts
- Look ata section covering who can assign accounts to privileged groupsGooddetails clear restrictions and authorisation processes
- Asklogs or reports showing recent changes in group memberships. Look to confirm how often computer accounts were added to or removed from privileged groupsGoodshows zero inappropriate changes
- Look atrecent completion of courses or materials focusing on privilege managementGoodincludes completed training logs
- Askdocumentation on automated monitoring setups for group membership changesLook atconfiguration settings and alert proceduresGoodincludes documented processes for immediate alert responses
Cross-framework mappings
How ISM-1941 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| Annex A 8.15 | ISM-1941 requires preventing computer accounts from being members of highly privileged AD groups (e.g | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| E8-RA-ML2.7 | ISM-1941 requires that computer accounts are not placed into highly privileged AD security groups (e.g | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.