Skip to content
arrow_back
search
E8-RA-ML2.5 bolt ASD Essential Eight

Long, unique, and managed credentials for admin accounts

Ensure admin account credentials are strong, unique, and well-managed.

record_voice_over

Plain language

This control is all about making sure that the passwords or keys admin accounts use are really hard to guess or crack. If these passwords are weak or reused across systems, someone trying to break in could take over your entire network. Think of it like having a super strong lock on the most important door to your house.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.
bolt ASD Essential Eight E8-RA-ML2.5
priority_high

Why it matters

Weak or shared admin credentials let attackers brute-force or reuse passwords to gain privileged access, move laterally, and rapidly compromise critical systems.

settings

Operational notes

Audit break glass, local admin and service account credentials for length, uniqueness and rotation; store in an approved password vault and disable shared/reused passwords.

Mapping detail

Mapping

Direction

Controls