Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Identity & Access Management - Why It’s Time To Remove Local Admin Rights For The Safety Of Organisations
Identity & Access Management Articles Data Protection

Why It’s Time To Remove Local Admin Rights For The Safety Of Organisations

Dilki RathnayakeBy Dilki RathnayakeAugust 24, 2023Updated:August 24, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Staying Safe Online
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The idea of removing local admin rights from every single user in your organisation is likely to spark strong reactions. But local admin privileges are like juicy colourful fruit waiting to be picked by threat actors and used to penetrate a network, so give me a chance to explain its importance.

The need – and urgency – to remove powerful privileges from ‘regular’ business users’ endpoints, is considerable. Ordinary users at work don’t need full access to their systems, let alone the ability to execute arbitrary code with elevated privileges. That’s far too dangerous.

The challenge though? These rights still need to be given to a small number of users with very specific business needs.

The support desk, the team responsible for maintaining the infrastructure, the database administrators, and the backup operators. These employees certainly need high-level access to keep a business running smoothly. However, security teams lack the time and resources to manually grant the additional permissions required. Also, they’d need to do it all the time.

This doesn’t mean privileged users have to be local admins. If an account with such permissions falls into the wrong hands, malicious actors can cause irreparable damage, including changing or disabling configurations, accessing and deleting data, as well as encrypting files. Basically, they can access, modify or leak all the company’s secrets.

The bottom line is, with full admin rights, even the most dedicated and well intentioned employee has too much control over an organisation’s digital environment, putting critical data and identity security systems in jeopardy.

Eliminating local admin rights across the board

An attack doesn’t succeed or fail based on gaining admin rights AP1, and attackers may ultimately slip past some endpoint defence-in-depth layers. However, taking steps to remove local admin rights across the board, and enforcing least privilege at the endpoint (and everywhere else), will make it much harder for attackers to achieve their goals.

Removing these rights as an identity security measure is not a radical security measure. However, restricting users to working with standard user accounts has a significant impact on identity security. You might think reducing administrative privileges would create friction for users and make security even more difficult? In reality, not doing so hurts an organisation more than it helps.

A pragmatic approach to identity security

Identity security issues can be solved with a well-rounded endpoint privilege manager. This manager can remove local admin rights and then, based on policies, elevate certain programs or tasks in a transparent manner so prompts aren’t seen by users, and they don’t feel the need to ask IT for assistance. In special cases, the user can request elevation, which can be approved without ever needing to connect to a machine remotely. On the backend, an effective endpoint privilege manager will even integrate with an IT ticketing system for smooth workflows and fast elevations.

Just adopting any endpoint privilege manager isn’t enough either. Organisations need to ensure the solution they adopt is as seamless as possible to integrate with their existing layers of defence. If all users start without admin rights, then systems need to be set up to automatically to elevate end-user privileges, in real-time and with little or no involvement from a helpdesk. But then the next task is to really tailor those elevation policies to the roles that users carry, so that every user or role have just enough privileges for frictionless work and at the same time the attack surface is minimal.

Organisations should also ensure they don’t rely solely on reducing administrative rights for all of their identity security needs. Measures need to be put in place to block ransomware by tightly controlling application permissions based on precise, conditional business rules. With credential and security tokens-based attacks on the rise, they also need to protect against credential and cookie theft as well as web session hijacking by safeguarding credential stores – in browsers, third-party applications or the operating system itself, which helps deter attackers while reducing the attack blast radius.

Removing local admin rights for all users is certainly not a one-and-done job. This is an ongoing process that should focus on improving the user experience by giving the right people and the right apps, the right access to the right resources at the right times. However, this process can be greatly simplified with a tool that provides full visibility and control over privileged actions on endpoints. Only then can it be considered a strong identity security measure that complements other tools as part of a defence-in-depth cyber security strategy.

Dilki Rathnayake
Dilki Rathnayake

Dilki Rathnayake is a cybersecurity content writer and the Managing Editor at Information Security Buzz, with a BSc in Cybersecurity and Digital Forensics. She is skilled in computer network security and Linux system administration. Dilki has also led awareness programs and volunteered for communities promoting best practices for online safety.

  • Dilki Rathnayake
    The new rules of war have no rules
  • Dilki Rathnayake
    AI Malware Arrives: Google Uncovers a New Wave of Adaptive Attacks
  • Dilki Rathnayake
    Out of Office, Not Out of Mind: Staying Cyber-Smart Over the Holidays
  • Dilki Rathnayake
    The Real Purpose of the UK’s Online Safety Act: An Expert Explains

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}