I often find myself talking with the business owners I work with, explaining why certain restrictions are in their best interest to follow. One topic that has come up recently is giving everyone in the business full administrative permissions on their respective workstations.
On the one hand, it makes sense… that way, the user doesn’t need to bother with support to install an update or add software. However, the other side is the one to pay close attention to, because granting these permissions across the board is a great way to leave your business uniquely vulnerable.
Let’s talk about why this is the case, and how restricting your admin rights helps you prevent this issue.
Let’s consider how privileges and permissions work on a computer. When a user logs in, the permissions granted to their profile determine how everything else runs. Those permissions extend to the programs, processes, and scripts their profile can execute.
If these privileges are properly restricted, the damage that a standard user could inadvertently cause is similarly limited. Let’s say James accidentally downloads an infected file. If James is an average user with the right account privileges, malware can only go so far. The damage it can potentially do is limited.
If James was granted admin privileges out of convenience, it’s a very different story:
That brings us to the absolute scariest part of this whole equation: network proliferation.
Malware rarely stays on one computer if it can help it. Once hackers gain local admin control on one machine, they use specialized tools to pull stored passwords from its system memory. If your network uses identical local admin credentials across multiple machines—or if that user has privileges elsewhere—attackers use special techniques to quietly leap from computer to computer, hopping across your network until they reach your servers or domain controller.
What starts as a single bad click can quickly become a full-blown, company-wide ransomware event.
This is often the first question I’m asked when I recommend pruning admin privileges. Many business owners are worried about how their team will respond if their access to their workstation is suddenly restricted. There are concerns about lost productivity or their employees starting to feel distrusted
Fortunately, these business owners are jumping straight to the nightmare scenario… terrifying, but usually unrealistic. For most users, removing this access will have zero impact on their actual workplace responsibilities. This is a key element of the Principle of Least Privilege.
The Principle of Least Privilege can be summed up as follows: everyone has exactly the access permissions needed to accomplish their responsibilities, nothing more. This balance is important because it hits that critical midpoint between security and productivity.
Making these adjustments is relatively simple, should you follow the right approach:
Removing local admin rights is one of the single most effective, cost-efficient security controls you can implement today. It instantly neutralizes a large percentage of everyday cyberthreats before they can spread through your network.
If you aren't sure who has administrative access on your network, or if you want help setting up a streamlined permission structure that keeps your team both secure and productive, we are here to help. To discuss locking down your network endpoints or setting up a comprehensive security assessment for your business, call us at (954) 739-4700.
Comments