What does restricting admin privileges mean?
Where it stops an attack.
- The attack A staff member’s everyday account is phished.
- Stopped here That account has no admin rights. Admin work needs a separate account that can’t read email.
- The result The attacker can’t switch off security tools or delete backups.
Admin privilege maturity levels
What changes at each level.
Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)
How to restrict admin privileges
Protection first, disruption last.
- 01
List every admin account
Microsoft 365, servers, devices, firewalls and line-of-business apps. Most businesses find more than they expected. - 02
Separate everyday and admin accounts
A standard account for email, a separate one for admin work. - 03
Remove standing local admin
Staff don’t need admin on their laptops. LAPS randomises local admin passwords. - 04
Review on a schedule
Revalidate access at least yearly and switch off accounts that go unused.
Common admin privilege mistakes
Where rollouts go wrong.
-
The owner as global admin
Directors often keep admin rights “just in case”, and they’re prime phishing targets.
-
Shared admin accounts
One password, three people, no record of who did what.
-
Forgetting cloud admins
Microsoft 365, accounting and practice platforms have admin roles too.