Skip to content
arrow_back
search
E8-RA-ML1.4 bolt ASD Essential Eight

Limit privileged accounts to essential online service access

Only allow privileged accounts the minimum access needed for online duties.

record_voice_over

Plain language

This control is about making sure that people with special access to your systems can only use those privileges for their job-related activities online. It's important because it stops unauthorised persons from taking advantage of these accounts to cause harm or steal information.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Privileged accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.
bolt ASD Essential Eight E8-RA-ML1.4
priority_high

Why it matters

If privileged accounts have unnecessary online service access, attackers can abuse stolen credentials or tokens to access cloud/SaaS admin portals and sensitive data.

settings

Operational notes

Maintain an approved list of online services each privileged account may use, review it routinely, and remove any SaaS, email, or cloud console access not required for duties.

Mapping detail

Mapping

Direction

Controls