Skip to content
arrow_back
search
E8-RA-ML2.2 bolt ASD Essential Eight

Privileged access is disabled after 45 days of inactivity

Disable admin accounts if unused for 45 days to improve security.

record_voice_over

Plain language

This control is about ensuring that admin accounts don't sit around unused for too long. If an administrator hasn't used their access for 45 days, their account should be turned off. This is important because old admin accounts could be a way in for hackers if they aren't managed properly.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Privileged access to systems and applications is disabled after 45 days of inactivity.
bolt ASD Essential Eight E8-RA-ML2.2
priority_high

Why it matters

If privileged accounts remain enabled beyond 45 days of inactivity, attackers can exploit forgotten admin credentials to gain elevated access and persist undetected.

settings

Operational notes

Set up alerts for privileged accounts approaching 45 days inactivity, then automatically disable access (or require reauthorisation) and record actions for audit.

Mapping detail

Mapping

Direction

Controls