Insights › Essential Eight

Restricting Admin Privileges: Fewer Admins, Fewer Breaches

Conceptual illustration of a network with few highlighted admin keys and a locked control gate on a navy background.

Most cyber attacks don’t start with a master criminal breaking down your digital front door. They start with an ordinary account being tricked or stolen, and then quietly climbing. The prize an attacker is really after is administrative access: the accounts that can install software, change settings, reach every file and switch off the very controls meant to stop them. The fewer of those accounts you have, and the more tightly you hold them, the less damage any single compromise can do.

That’s the thinking behind restricting administrative privileges, one of the Australian Signals Directorate’s Essential Eight mitigation strategies. It sounds like a job for a large IT department, but the core idea is simple and it costs almost nothing to start. This guide explains what admin privileges are, why they’re such a target, and the practical steps an Australian small business can take to bring them under control.

What “administrative privileges” actually means

An administrator account is one that can make changes to a system rather than just use it. On a Windows laptop, an admin can install programs, turn off the firewall or create new user accounts. In Microsoft 365 or Google Workspace, a global administrator can reset anyone’s password, read any mailbox and change security settings for the whole organisation. Your accounting software, your website, your customer database and your network equipment all have their own admin roles too.

A standard (or “unprivileged”) account, by contrast, can do a person’s day-to-day work, like sending email, editing documents and using the line-of-business app, but can’t reshape the system underneath. Most people in your business only ever need a standard account. The trouble is that, out of convenience, admin rights tend to spread: the owner is an admin because they set everything up, the office manager was made an admin to install a printer once, and the old bookkeeper’s admin account was never switched off. Each of those is a spare key to the building, and most businesses have far more of them than they realise.

Why attackers hunt for admin accounts

When an attacker phishes a password or slips malware onto a device, what they’ve gained depends entirely on the account they’ve landed on. Compromise a standard user and the damage is contained to that person’s files and mailbox, which is bad but recoverable. Compromise an administrator and the attacker inherits everything that account can do: they can disable your antivirus, delete or encrypt backups, create new accounts to keep a foothold, and move sideways across your network. This is why ransomware crews and business email compromise scammers work so hard to escalate from a normal account to a privileged one.

Restricting admin privileges attacks that chain at its most valuable link. If far fewer accounts carry those powers, there are fewer targets worth escalating to, and a stolen everyday password gets an attacker much less. It also limits accidental damage: a well-meaning staff member can’t disable a security control or wipe a shared drive if their account was never able to in the first place.

Start with the principle of least privilege

The Essential Eight guidance boils down to a single principle: access should be strictly limited to only what a person or service needs to do their job. Everything else follows from that. Here’s how to put it into practice without a big project:

Give admins two accounts, not one

Here’s the change that does the most good for the least effort. Anyone who genuinely needs administrative access should have two separate accounts: a standard account for their everyday work, and a separate privileged account used only when they’re actually performing an admin task. The Essential Eight specifically calls for keeping privileged and unprivileged use apart, so that a compromise of someone’s day-to-day account doesn’t hand over the keys to the whole system.

In plain terms: you read email, browse the web and write quotes as “jenny”, and you only sign in as “jenny-admin” when you need to add a user or change a setting. If a dodgy link compromises the account you use all day, it lands on the standard one, the account that can’t do much harm. Pair each privileged account with multi-factor authentication, and use a unique, strong password for it that isn’t shared with the everyday account.

Keep privileged accounts off email and the web

The most common ways an account gets compromised are a phishing email and a malicious website or download. So one of the clearest rules in the ACSC guidance is that privileged accounts should not be able to read email or browse the web at all. Take away the two riskiest activities and you dramatically shrink the chance that an admin account is ever caught out.

For a small business, that mostly means discipline rather than expensive tooling: the admin account exists purely to do admin work, and you never use it to check email, click a link or install something you found online. Where your platform allows it, you can enforce this, for instance by not assigning a mailbox to the admin account, or blocking web access for it. Combined with application control, which stops unapproved programs running in the first place, this keeps the powerful accounts well away from the places attacks come from.

Review access regularly and switch off what’s unused

Admin access isn’t “set and forget”. People change roles, projects finish and staff move on, and every stale privileged account is a door left unlocked. The Essential Eight expects privileged access to be revalidated over time. As a benchmark, the maturity model looks for access to be reviewed and disabled if it hasn’t been reconfirmed within twelve months, and for accounts to be switched off after a period of inactivity.

You don’t need enterprise software to follow the spirit of this. Put a recurring reminder in the calendar (quarterly is a sensible rhythm for a small business) to walk back through your list of admins and confirm each one is still needed. Tie it firmly to your staff offboarding process, too: the day someone leaves, their privileged access should be revoked, not weeks later. An account nobody uses is exactly the kind of thing an attacker loves to find.

What “good” looks like as you grow

The steps above will move most small businesses a long way. As you grow, or if you’re working towards a higher Essential Eight maturity level for a tender or contract, there are stronger measures worth knowing about. Privileged access can be logged centrally and reviewed, so that unusual admin activity is spotted quickly. “Just-in-time” administration grants elevated rights only for the minutes an admin task takes and then removes them automatically. And larger organisations perform administration from dedicated, hardened machines (sometimes called secure admin workstations or jump servers) that are kept separate from the everyday computing environment.

Those are goals to grow into, not prerequisites. The point of restricting admin privileges isn’t to make your business harder to run; it’s to make sure that when something goes wrong, as it eventually will for someone, the blast radius is small. Fewer admins, tightly held and regularly reviewed, genuinely does mean fewer breaches.

Find out where you stand

Not sure how your admin accounts, or the rest of your security, stack up? Our free self-assessment walks you through 27 plain-English questions and maps your answers to the ACSC Essential Eight, ISO 27001 and SOC 2. It takes five to ten minutes, and you’ll get a personalised PDF report showing where you’re strong and where to focus next. Take the free assessment at securityscore.com.au and see your score today.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading