Abstract

I often find myself talking with the business owners I work with, explaining why certain restrictions are in their best interest to follow. One topic that has come up recently is giving everyone in the business full administrative permissions on their respective workstations.

On the one hand, it makes sense… that way, the user doesn’t need to bother with support to install an update or add software. However, the other side is the one to pay close attention to, because granting these permissions across the board is a great way to leave your business uniquely vulnerable.

Let’s talk about why this is the case, and how restricting your admin rights helps you prevent this issue.

Why Is It So Important to Restrict Admin Privileges?

Let’s consider how privileges and permissions work on a computer. When a user logs in, the permissions granted to their profile determine how everything else runs. Those permissions extend to the programs, processes, and scripts their profile can execute.

If these privileges are properly restricted, the damage that a standard user could inadvertently cause is similarly limited. Let’s say James accidentally downloads an infected file. If James is an average user with the right account privileges, malware can only go so far. The damage it can potentially do is limited.

If James was granted admin privileges out of convenience, it’s a very different story:

  • System defenses get neutered – Once malware gets admin privileges, it’ll turn off your endpoint security first. It will disable Windows Defender, firewalls, and monitoring tools before your employees know it.
  • Deep roots get planted – Admin access also allows software to write directly to sensitive system directories and the registry. This means that the bad guys can install hidden rootkits, alter boot sequences, and create brand-new, unauthorized user accounts that persist even after a reboot.
  • Credentials get harvested – Once a machine is fully compromised, attackers harvest the stored credentials from the computer’s memory.

That brings us to the absolute scariest part of this whole equation: network proliferation.

Malware rarely stays on one computer if it can help it. Once hackers gain local admin control on one machine, they use specialized tools to pull stored passwords from its system memory. If your network uses identical local admin credentials across multiple machines—or if that user has privileges elsewhere—attackers use special techniques to quietly leap from computer to computer, hopping across your network until they reach your servers or domain controller.

What starts as a single bad click can quickly become a full-blown, company-wide ransomware event.

“Won’t Stripping Admin Rights Paralyze My Team?”

This is often the first question I’m asked when I recommend pruning admin privileges. Many business owners are worried about how their team will respond if their access to their workstation is suddenly restricted. There are concerns about lost productivity or their employees starting to feel distrusted

Fortunately, these business owners are jumping straight to the nightmare scenario… terrifying, but usually unrealistic. For most users, removing this access will have zero impact on their actual workplace responsibilities. This is a key element of the Principle of Least Privilege.

The Principle of Least Privilege can be summed up as follows: everyone has exactly the access permissions needed to accomplish their responsibilities, nothing more. This balance is important because it hits that critical midpoint between security and productivity.

How to Design Functional Endpoint Security

Making these adjustments is relatively simple, should you follow the right approach:

  1. Audit your current permissions – You need to know who has what level of access in your organization—including “temporary” vendor accounts and former employees’ accounts. None of these should have admin permissions, which we’ll address soon.
  2. Separate workhorse accounts from Admin accounts – Let’s assume that one of your team members legitimately needs admin rights to complete their responsibilities. They should have two accounts: one for daily use and one for administrative needs.
  3. Utilize modern privilege management tools – Endpoint Detection and Response (EDR) tools let you create lists of trusted applications. Applications on these lists can have their permissions automatically elevated so updates can be installed.
  4. Communicate with your staff – Be transparent with your team about why you’re implementing these adjustments. If your staff understands it is a security layer designed to protect their livelihoods, they’re less likely to interpret it as a lack of trust in their abilities.

Protecting Your Business Without the Headache

Removing local admin rights is one of the single most effective, cost-efficient security controls you can implement today. It instantly neutralizes a large percentage of everyday cyberthreats before they can spread through your network.

If you aren’t sure who has administrative access on your network, or if you want help setting up a streamlined permission structure that keeps your team both secure and productive, we are here to help. To discuss locking down your network endpoints or setting up a comprehensive security assessment for your business, call us at 888-748-2525.

ABOUT THE AUTHOR

The Hidden Risks of Giving Employees Local Admin Rights

Rafiq Masri

With over 25 years of experience in Information Technology, Rafiq is one of the most accomplished, versatile and certified engineer in the field. He has spent the past 2 ½ decades administering and supporting a wide range of clients and has helped position Network Management, Inc. as a leader in the IT Managed Services space.

Rafiq has built a reputation for designing, building and supporting top notch IT infrastructures to match the business objectives and goals of his clients.

Embracing the core values of integrity, innovation, and reliability, Rafiq has a very loyal client base with some customer relationships dating back 20+ years.

Rafiq holds a bachelor’s degree in Mechanical Engineering from the University of Michigan and has completed graduate programs in Software Engineering and Business at Harvard and George Mason University. Rafiq is a former founder and CEO of Automation, Inc. in Ann Arbor, Michigan as well as a valued speaker on entrepreneurship and technology at industry events such as ExpoTech and others.