Skip to main content
CUI

Documentation - V-243467

V-243467

Active Directory Domain Security Technical Implementation Guide

CAT I

Title

Membership to the Domain Admins group must be restricted to accounts used only to manage the Active Directory domain and domain controllers.

Description

<VulnDiscussion>The Domain Admins group is a highly privileged group. Personnel who are system administrators must log on to Active Directory systems only using accounts with the level of authority necessary. Only system administrator accounts used exclusively to manage an Active Directory domain and domain controllers may be members of the Domain Admins group. A separation of administrator responsibilities helps mitigate the risk of privilege escalation resulting from credential theft attacks....

Fix Text (Documentation Requirement)

Create the necessary documentation that identifies the members of the Domain Admins group. Ensure that each member has a separate unique account that can only be used to manage the Active Directory domain and domain controllers. Remove any Domain Admin accounts from other administrator groups.

Documentation Status

Select the document that satisfies this documentation requirement. Upload new document

Cancel

Last updated: 2026-02-09 18:37:06

Linked to: USNS Montford Point eMASS Security Plan (SP)

CUI