Skip to content
arrow_back
search
E8-RA-ML1.6 bolt ASD Essential Eight

Unprivileged accounts restricted from logging into privileged environments

Ensure that non-admin accounts cannot access admin-level systems.

record_voice_over

Plain language

This control ensures that regular users can't access systems where important administrative tasks are done. Imagine if a regular worker accidentally deleted important files or changed system settings. By restricting access, we prevent potential mistakes and protect the organisation from intentional harm.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Unprivileged accounts cannot logon to privileged operating environments.
bolt ASD Essential Eight E8-RA-ML1.6
priority_high

Why it matters

If unprivileged users can log on to privileged environments, attackers can pivot to admin sessions, elevating access and causing outages.

settings

Operational notes

Audit logon rights on privileged hosts (servers/admin workstations) and allow only admin accounts; deny standard users via GPO/PAM.

Mapping detail

Mapping

Direction

Controls