Skip to content
arrow_back
search
E8-RA-ML2.7 bolt ASD Essential Eight

Centrally log privileged account and group management events

Ensure logs of admin account and group changes are stored in one place.

record_voice_over

Plain language

Imagine all the important door keys in your business on one keychain. If you lose that keychain, someone could access everything. Similarly, if changes to your admin accounts aren't logged in one central place and someone gets into those accounts, it could mean trouble. Logging these changes helps you track and respond quickly to anything suspicious.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Privileged account and group management events are centrally logged.
bolt ASD Essential Eight E8-RA-ML2.7
priority_high

Why it matters

Without central logging, unauthorised privileged account or group changes can go undetected, enabling persistence, fraud or sabotage.

settings

Operational notes

Centrally collect admin account/group change events and alert on unexpected adds/removes to privileged groups and sudden privilege grants.

Mapping detail

Mapping

Direction

Controls