Skip to content
arrow_back
search
E8-RA-ML1.7 bolt ASD Essential Eight

Prevent privileged accounts from accessing unprivileged environments

Ensure privileged accounts can't be used in unsecured setups to limit risk.

record_voice_over

Plain language

This control ensures that accounts with special privileges can't be used in unsafe situations. Imagine having a special key to your business; if you use it in a risky area or environment, someone could copy it and use it to break into your business. This control stops privileged accounts from being used in unprotected environments, which can prevent potential security breaches.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Privileged accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
bolt ASD Essential Eight E8-RA-ML1.7
priority_high

Why it matters

Using privileged accounts in unsecured environments risks exposing credentials to malware, enabling attackers to escalate access and compromise systems.

settings

Operational notes

Enforce logon restrictions so privileged accounts cannot access unprivileged workstations; review logs and alert on any blocked sign-in attempts.

Mapping detail

Mapping

Direction

Controls