Skip to content
Menu

Essential Eight restrict administrative privileges

Fewer admin accounts, kept away from email and the web.

Only the people who need admin rights get them, on separate accounts that can’t read email or browse the web, and the access is reviewed.

A wall-mounted key cabinet, open, above a shelf holding one laptop kept apart for administration work.

At a glance

Control
05 of 08 · Limit the impact
Stops
Attackers taking full control of your systems
Typical tools
Microsoft Entra ID, Privileged Identity Management, LAPS
Effort
Medium
  1. The attack A staff member’s everyday account is phished.
  2. Stopped here That account has no admin rights. Admin work needs a separate account that can’t read email.
  3. The result The attacker can’t switch off security tools or delete backups.

Admin privilege maturity levels

What changes at each level.

ML1 Maturity Level 1. ML2 Maturity Level 2. ML3 Maturity Level 3.
Granting access Checked when first requestedAdds: removed after 12 months unless revalidated, and after 45 days unusedAdds: limited to what each duty needs
Admin accounts Separate accounts, blocked from email and the web unless authorised No change No change
Where admin work happens A separate admin environmentAdds jump servers. Admin environment never a virtual machine inside a standard oneAdds Secure Admin Workstations and just-in-time access
Break glass, local admin and service account passwords Not required Long, unique and managed No change
Credential protection Not required Not required Credential Guard, Remote Credential Guard, LSA protection and memory integrity on
Logging Not required Admin sign-ins and account changes logged centrally. Internet-facing server logs analysedAdds analysis of workstation and internal server logs

Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)

How to restrict admin privileges

Protection first, disruption last.

  1. 01

    List every admin account

    Microsoft 365, servers, devices, firewalls and line-of-business apps. Most businesses find more than they expected.
  2. 02

    Separate everyday and admin accounts

    A standard account for email, a separate one for admin work.
  3. 03

    Remove standing local admin

    Staff don’t need admin on their laptops. LAPS randomises local admin passwords.
  4. 04

    Review on a schedule

    Revalidate access at least yearly and switch off accounts that go unused.

Common admin privilege mistakes

Where rollouts go wrong.

  • The owner as global admin

    Directors often keep admin rights “just in case”, and they’re prime phishing targets.

  • Shared admin accounts

    One password, three people, no record of who did what.

  • Forgetting cloud admins

    Microsoft 365, accounting and practice platforms have admin roles too.

Admin privilege questions

What clients ask before we start.

Should the business owner have admin access?
Do staff need admin rights to install software?
What is just-in-time administration?

Find out where you stand on admin privileges.

Book a free 45-minute Essential Eight review with a Perth engineer. You get your maturity on all eight controls and what to fix first. The report is yours to keep.

Or call (08) 9467 2269

What’s bugging you
Staff

A Perth engineer, not a salesperson, replies within one business day.

We hold ISO/IEC 27001:2022 certification from BSI, certificate IS 840964.