Skip to content
arrow_back
search
ISM-1952 policy ASD Information Security Manual (ISM)

Prevent Synchronisation of Privileged Accounts

Ensure privileged accounts aren't synced between Microsoft AD DS and Entra ID for security reasons.

record_voice_over

Plain language

This control means you should not let accounts with special access or powers be automatically copied between your local computer systems and Microsoft's cloud systems. Doing so is important because if someone gains unauthorised access to these powerful accounts, they could cause significant harm by accessing sensitive information or disrupting operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.
policy ASD Information Security Manual (ISM) ISM-1952
priority_high

Why it matters

Unauthorised sync of privileged accounts between AD DS and Entra ID could lead to compromised credentials and elevated risks of data breaches or operational disruptions.

settings

Operational notes

Regularly audit account sync configurations to ensure privileged accounts remain unsynced, protecting against potential security cross-contamination.

Mapping detail

Mapping

Direction

Controls