Skip to content
arrow_back
search
E8-RA-ML2.3 bolt ASD Essential Eight

Privileged environments are not virtualised within unprivileged environments

Ensure that secure environments are not run within less secure ones.

record_voice_over

Plain language

This control is about making sure that our secure computer environments aren’t run within less secure ones. Imagine putting a secure, locked box inside a flimsy, open one. If someone breaks into the outer box, they could easily get into the inner one. This control keeps our most important parts of the system safe from prying eyes and potential attacks.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Privileged operating environments are not virtualised within unprivileged operating environments.
bolt ASD Essential Eight E8-RA-ML2.3
priority_high

Why it matters

Running privileged VMs inside unprivileged hosts increases the chance a host compromise leads to privileged environment takeover and data exposure.

settings

Operational notes

Audit hypervisor and VM configs to ensure privileged environments are never nested or hosted within unprivileged environments; remediate any exceptions found.

Mapping detail

Mapping

Direction

Controls