Skip to content
arrow_back
search
ISM-1944 policy ASD Information Security Manual (ISM)

Configuration Changes in Active Directory Certificate Services

Ensure a specific security flag is not configured in Microsoft AD CS to maintain system integrity.

record_voice_over

Plain language

This control is about making sure a specific technical setting (a security flag) is not used in your company's certificate services. If this setting is wrongly enabled, it could allow attackers easier access to fake digital credentials, similar to ID badges, which might let them impersonate your systems or users. By ensuring this setting is turned off, you maintain your organisation's integrity and protect against identity-based attacks.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.
policy ASD Information Security Manual (ISM) ISM-1944
priority_high

Why it matters

If EDITF_ATTRIBUTESUBJECTALTNAME2 remains enabled on AD CS, attackers can request certificates with spoofed SANs, enabling impersonation and MITM.

settings

Operational notes

Audit each AD CS CA for EDITF_ATTRIBUTESUBJECTALTNAME2 and remove/disable it; document the change and re-check after CA updates or template changes.

Mapping detail

Mapping

Direction

Controls