Nano Solutions

Restrict administrative privileges

Restrict administrative privileges is the Essential Eight mitigation strategy limiting privileged access to what users need, separating privileged from unprivileged environments, and preventing privileged accounts from reaching the internet, email and web services — with the explicit exception of accounts authorised to administer online services.

Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).

On this page 5 sections
  1. What is required, and where
  2. When privileged accounts may access online services
  3. What counts as a privileged account
  4. Commonwealth implementation
  5. How this strategy supports backup protection

Restrict administrative privileges at a glance

What each maturity level requires

Requirements are cumulative: Level Three means everything in Levels One and Two as well. Each level links to that requirement on the matrix.

  1. ML1 Maturity Level One

    Restrict administrative privileges, Maturity Level One: Privileged access requests validated when first requested (ISM-1507)
  2. ML2 Maturity Level Two

    Restrict administrative privileges, Maturity Level Two: Administrative activities via jump servers; privileged environments not virtualised within unprivileged ones
  3. ML3 Maturity Level Three

    Restrict administrative privileges, Maturity Level Three: Secure Admin Workstations and just-in-time administration
New requirements start here Carries the level below Score yourself with the self-assessment, or look a term up in the glossary.

This strategy limits what privileged accounts can reach and how administrators perform sensitive work. Its controls cover approval, separation, expiry, credentials, logging and administrative workstations.

What is required, and where

Maturity Level One requires:

  • privileged access requests validated when first requested
  • dedicated privileged accounts used solely for privileged duties
  • privileged accounts prevented from accessing the internet, email and web services, with the online-services exception below
  • separate privileged and unprivileged operating environments
  • unprivileged accounts prevented from logging on to privileged environments
  • privileged accounts prevented from logging on to unprivileged environments, except for local administrator accounts

Maturity Level Two adds:

  • privileged access to systems, applications and data repositories disabled after 12 months unless revalidated
  • privileged access to systems and applications disabled after 45 days of inactivity
  • administrative activities conducted through jump servers
  • privileged environments not virtualised within unprivileged environments
  • break glass, local administrator and service account credentials that are long (at least 30 characters), unique, unpredictable and managed
  • privileged access, account-management and security-group-management events centrally logged

Level Two also requires logs to be protected and internet-facing server logs to be analysed. Incidents must be reported to the chief information security officer (CISO) and ASD, and the incident response plan must be enacted.

Maturity Level Three adds:

  • Secure Admin Workstations
  • just-in-time administration
  • privileged access limited to only what is required
  • Credential Guard, Remote Credential Guard, Local Security Authority (LSA) protection and memory integrity
  • log analysis expanded to non-internet-facing servers and workstations

See the requirements matrix for every control at each maturity level.

When privileged accounts may access online services

The internet restriction in the Essential Eight Maturity Model reads, in full:

Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.

The exception allows explicitly authorised accounts to administer online services. ASD's Essential Eight assessment process guide gives accounts used to manage cloud services as an example.

A second control limits authorised privileged accounts to what users and services require for their duties. The exception is therefore scoped, not a blanket exemption.

This permits administration of services such as AWS or Azure. It does not permit unrestricted browsing or email from a privileged account.

What counts as a privileged account

The Information Security Manual defines a privileged account by what it can do, not by its title:

User accounts that have the capability to modify system configurations, account privileges, event logs or security configurations. This also applies to user accounts that may only have limited privileges but still have the ability to bypass some system controls. A privileged user account may belong to a person or a service.

The definition includes service accounts and accounts with narrow permissions that can bypass a control. An inventory limited to domain administrators is therefore incomplete.

Commonwealth implementation

ASD's Commonwealth Cyber Security Posture in 2025 puts restrict administrative privileges at 46% of Commonwealth entities at Maturity Level Two or above in 2024–25. MFA was the only strategy with a lower result. Administrative privileges had fallen to 31% in 2023–24.

These controls change day-to-day administrative workflows: separate accounts and environments, time-limited access, jump servers and managed credentials. The Commonwealth figures show the implementation result, but do not identify which of those requirements caused it.

How this strategy supports backup protection

Administrative privileges are what an attacker escalates to. The adversary descriptions in the Essential Eight Maturity Model set out the progression. At Level Two, if compromised accounts have special privileges "they will exploit it, otherwise they will seek user accounts with special privileges". Such an adversary "may also destroy all data (including backups) accessible to a user account with special privileges."

That is why this strategy and regular backups tighten in parallel. The backup requirements at Levels Two and Three are written specifically to survive a compromised privileged account.

Sources

All ASD source documents →

Common questions

Does the Essential Eight ban administrators from using the internet?

No. The requirement prevents privileged accounts from accessing the internet, email and web services while explicitly excluding "those explicitly authorised to access online services". ASD's assessment guide confirms that "some privileged user accounts, such as those used to manage cloud services, may have access to the internet". The authorisation must be explicit and access strictly limited to what is required.

How long can a privileged account stay active?

From Maturity Level Two, privileged access to systems, applications and data repositories must be disabled after 12 months unless it is revalidated. The 45-day inactivity rule applies to privileged access to systems and applications, not data repositories. Maturity Level One requires requests to be validated when first made.

What does ASD mean by long credentials for break glass accounts?

At least 30 characters. From Maturity Level Two, credentials for break glass, local administrator and service accounts must be long, unique, unpredictable and managed. ASD's FAQ defines "long" as a minimum of 30 characters.

Do we need dedicated physical hardware for Secure Admin Workstations?

No. ASD confirms that "dedicated physical workstations are not strictly required when implementing SAWs". A virtualised approach still has to meet the model's Secure Admin Workstation and operating-environment separation requirements. ASD also notes that Secure Admin Workstations and Privileged Access Workstations are "different names for the same concept". SAWs are a Maturity Level Three requirement.

  • Essential Eight requirements matrix

    What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

  • Application control

    Application control restricts execution to an organisation-approved set. ASD treats it as one of the most effective controls for preventing malicious code from running.

  • Multi-factor authentication

    MFA was the lowest-performing Essential Eight strategy across Commonwealth entities in 2024–25. ASD is specific about which factors and implementations count.

Essential Eight

Need this assessed rather than explained?

We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.