At a glance
Restricting administrative privileges is an effective way to protect systems, applications and sensitive information from cyber security threats. Users with administrative access can make significant changes to systems, bypass security controls and access sensitive data, making these accounts a valuable target for malicious actors. Learn how to identify when administrative privileges are required, assign access using the principle of least privilege, and regularly review accounts to ensure their access remains appropriate. This guidance is for IT administrators, cyber security practitioners, system owners and organisations responsible for managing privileged access. Apply these practices to reduce security risks, improve accountability and create a more secure and manageable operating environment.
Key actions
Give administrative access only to staff who need it to perform their duties.
Use separate administrator accounts for privileged tasks and give users only the level of access they require.
Review administrator accounts regularly and remove access when it is no longer needed, when staff change roles or when they leave the organisation.
Protect administrator accounts by limiting internet access and using secure system administration practices.
Introduction
Restricting administrative privileges is one of the most effective mitigation strategies in ensuring the security of systems. As such, restricting administrative privileges forms part of the Essential Eight from the Strategies to mitigate cyber security incidents.
This publication provides guidance on how to effectively restrict administrative privileges.
Why administrative privileges should be restricted
Users with administrative privileges for operating systems and applications are able to make significant changes to their configuration and operation, bypass critical security settings and access sensitive data. Domain administrators have similar abilities for an entire network domain, which usually includes all of the workstations and servers on the network.
Malicious actors often use malicious code (also known as malware) to exploit vulnerabilities in workstations and servers. Restricting administrative privileges makes it more difficult for malicious actors to elevate privileges, spread to other hosts, hide their existence, persist after reboot, obtain sensitive data or resist removal efforts.
An environment where administrative privileges are restricted is more stable, predictable, and easier to administer and support, as fewer users can make significant changes to their operating environment, either intentionally or unintentionally.
Approaches which do not restrict administrative privileges
There are a number of approaches which, while they may appear to provide many of the benefits of restricting administrative privileges, do not meet the intent of this mitigation strategy, and in some cases may actually increase the risk to an organisation’s network. These approaches include:
- simply minimising the total number of privileged accounts
- implementing shared non-attributable privileged accounts
- temporarily allocating administrative privileges to user accounts
- placing standard user accounts in user groups with administrative privileges.
How to restrict administrative privileges
The correct approach to restricting administrative privileges is to:
- identify tasks which require administrative privileges to be performed
- validate which staff members are required and authorised to carry out those tasks as part of their duties
- create separate attributable accounts for staff members with administrative privileges, ensuring that their accounts have the least amount of privileges needed to undertake their duties
- revalidate staff members’ requirements to have a privileged account on a frequent and regular basis, or when they change duties, leave the organisation or are involved in a cyber security incident.
To reduce the risks of using privileged accounts, organisations should ensure that:
- technical controls prevent privileged accounts from accessing the internet, unless explicitly required for the management of cloud services, in which case they are strictly limited to only what is required to undertake their duties
- system administration is undertaken in a secure manner by implementing the guidance in the Secure administration publication.
Further information
The Information security manual is a cyber security framework that organisations can apply to protect their systems and data from cyber threats. The advice in the Strategies to mitigate cyber security incidents, along with its Essential Eight, complements this framework.
Contact details
If you have any questions regarding this guidance you can write to us or call us on 1300 CYBER1 (1300 292 371).