Domain Computers Group Privilege Restriction
The Domain Computers group should not have any privileged access to maintain security.
Plain language
This control ensures that computers in a network don't have special access to sensitive areas. If this isn't done, malicious people could exploit those computers to steal data or cause harm.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Server Application HardeningOfficial control statement
The Domain Computers security group is not a member of any privileged or highly privileged security groups.
Why it matters
Without this control, computers in the network could be hijacked to access sensitive information, leading to security breaches and data loss.
Operational notes
Regularly review and update security group policies to maintain restrictions on the Domain Computers group, preventing unauthorised access.
Implementation tips
- IT team should review the membership of the Domain Computers group. Use user management tools to ensure it doesn't have privileged access.
- System owner must confirm that no computers have been added to high-level groups. Check configurations monthly and document findings.
- IT administrator should use monitoring tools to track changes. Set alerts for any change to the Domain Computers group's permissions.
- Managers should request regular security briefings from IT. Discuss the importance of keeping computers out of privileged groups and understand potential impacts.
- Audit staff should schedule routine checks. Use checklists to verify Domain Computers is limited to non-privileged access.
Audit / evidence tips
- Aska listing of current security group membershipsLook atgroup memberships to ensure Domain Computers isn't part of privileged groupsGoodA list showing Domain Computers in only basic access groups
- GoodLogs showing change history with authorised approvals
- Askto see permissions granted to the Domain Computers groupLook atexcessive permissions beyond standard computer needsGoodAccess levels appropriate only for basic machine operations
- Look atspecific mention of Domain Computer group restrictionsGoodPolicy clearly stating Domain Computers cannot join privileged groups
- Aska recent internal audit report on access management. Examine findings related to Domain ComputersGoodAudit confirms no unauthorised privileged group access
Cross-framework mappings
How ISM-1942 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.2 | ISM-1942 requires that the Active Directory **Domain Computers** group is not a member of any privileged or highly-privileged security gr... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.