Skip to content

Restrict administrative privileges

Making sure only the people who need admin rights have them, and only when they need them.

The case for it

What you lose without restricted admin privileges.

An attacker who compromises a regular user can encrypt that user's files. An attacker who compromises an administrator can encrypt the organisation. Keeping the number of admin accounts small, named and logged is the most effective thing you can do after application control.

Where you need to be

What each maturity level asks of restricted admin privileges.

The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.

ML1 The 2026 baseline

Privileged accounts are limited to designated privileged duties. Privileged accounts can't access the internet, email, or web services.

ML2 Regulated or audited

Privileged accounts are validated every 12 months and when there's a change in duty. Secure admin workstations are used for privileged tasks. Just-in-time administration is implemented for cloud services.

ML3 Defence or sensitive

Privileged activities are logged centrally. Privileged account credentials are protected by memory integrity and credential guard.

Not sure which level you should aim for?

Three questions about your regulatory position and the data you keep will point you at the right target.

Take the maturity picker

The rollout

Setting up restricted admin privileges in your environment.

The number of admin accounts comes down to the named people who demonstrably need one. Admin accounts are kept separate from day-to-day accounts, so a phished email does not hand an attacker full control. Cloud services move to just-in-time elevation, and privileged accounts stop reading email and browsing the web. Every privileged action is logged centrally and reviewed.

Free self-assessment

No email required.

Score yourself on all eight controls.

Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.

Take the self-assessment

Asked on client calls

Questions we get about restricted admin privileges.

Do I still need admin on my own laptop?
What about our IT person? Don't they need admin everywhere?
How fast is just-in-time elevation?

The maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit