Skip to content
arrow_back
search
E8-RA-ML1.2 bolt ASD Essential Eight

Dedicated privileged accounts for admin tasks

Ensure admins use special accounts only for their admin work.

record_voice_over

Plain language

This control means that people who have extra powers to change important parts of an organisation's computer systems use special accounts only for those tasks. This is important because if they used the same account for everything, like checking email or browsing the web, it would be easier for cybercriminals to trick them and gain control over the organisation's critical systems.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Privileged users are assigned a dedicated privileged account to be used solely for duties requiring privileged access.
bolt ASD Essential Eight E8-RA-ML1.2
priority_high

Why it matters

Without separate privileged accounts, a phished standard login can be reused for admin actions, enabling rapid escalation and system takeover.

settings

Operational notes

Maintain separate privileged accounts; review membership and logons, and alert on privileged use from standard accounts or outside admin workflows.

Mapping detail

Mapping

Direction

Controls