Skip to content
arrow_back
search
ISM-2010 policy ASD Information Security Manual (ISM)

Ensure SPNs Use Strong Encryption in AD Services

Service accounts in Active Directory must use strong encryption to secure their SPNs.

record_voice_over

Plain language

Service accounts in Active Directory are like special user accounts used by applications or services, not by people. Ensuring these accounts use strong encryption means that the data they handle is kept safe from prying eyes. If this isn't done, sensitive information could be intercepted and misused, leading to data breaches or loss of trust in your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.
policy ASD Information Security Manual (ISM) ISM-2010
priority_high

Why it matters

If SPN service accounts allow RC4/DES, attackers can Kerberoast and crack tickets to access services and data, causing breach and reputational harm.

settings

Operational notes

Audit SPN accounts for msDS-SupportedEncryptionTypes; require AES128/256, disable RC4/DES, and validate Kerberos ticket encryption after changes.

Mapping detail

Mapping

Direction

Controls