Skip to content
arrow_back
search
E8-RA-ML1.1 bolt ASD Essential Eight

Validating privileged access requests upon initial request

Check and approve requests for admin access to systems and data at the start.

record_voice_over

Plain language

This control is about making sure anyone who asks for special admin access to your systems gets checked out first. It's like making sure someone's ID and reasons are verified before giving them the keys to your house. Without it, someone could sneak in and potentially wreak havoc by stealing sensitive information or causing damage.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Requests for privileged access to systems, applications and data repositories are validated when first requested.
bolt ASD Essential Eight E8-RA-ML1.1
priority_high

Why it matters

Unchecked admin access requests can lead to unauthorised changes or data breaches, exposing sensitive info and harming the organisation.

settings

Operational notes

Validate each privileged access request at submission (requester identity, business need, approver authority, scope and duration) and record the approval decision in logs.

Mapping detail

Mapping

Direction

Controls