Skip to content
arrow_back
search
ISM-1942 policy ASD Information Security Manual (ISM)

Restrict Domain Computers from Privileged Groups

Ensure that Domain Computers aren't part of privileged security groups for better security.

record_voice_over

Plain language

This control is about making sure that 'Domain Computers', which are computers recognised in the network directory, aren't added to groups with extra control or power. It's like making sure a regular employee doesn't have the keys to the CEO's office—they shouldn’t have that level of access, and if they do, it could lead to significant security problems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The Domain Computers security group is not a member of any privileged or highly-privileged security groups.
policy ASD Information Security Manual (ISM) ISM-1942
priority_high

Why it matters

If Domain Computers is added to privileged groups, any compromised machine account can be abused to gain domain admin-level control, enabling widespread data breach and outage.

settings

Operational notes

Regularly review AD group nesting and memberships so Domain Computers is never in privileged groups (e.g. Domain Admins/Administrators), and alert on any changes.

Mapping detail

Mapping

Direction

Controls