Skip to content
arrow_back
search
ISM-1949 policy ASD Information Security Manual (ISM)

Use Dedicated Accounts for AD FS Administration

AD FS servers should be managed using special accounts not shared with other systems.

record_voice_over

Plain language

You should use special accounts just for managing AD FS servers, instead of using the same accounts for other systems. This is important because if a hacker gains access to a shared account, they could control not just the AD FS server, but other systems too, leading to a wide-scale security breach.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Microsoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.
policy ASD Information Security Manual (ISM) ISM-1949
priority_high

Why it matters

Without dedicated AD FS admin accounts, a breach can escalate to other critical systems, increasing the risk of widespread compromise.

settings

Operational notes

Use a dedicated AD FS admin account only on AD FS servers; audit group membership and logons for cross-use regularly.

Mapping detail

Mapping

Direction

Controls