Skip to content
arrow_back
search
E8-RA-ML3.1 bolt ASD Essential Eight

Limit privileged access to what is necessary for duties

Ensure privileged access is granted only when needed to perform specific duties.

record_voice_over

Plain language

Limiting privileged access means making sure that employees only have access to the systems and information they need to do their jobs, nothing more. This is important because if someone were to misuse or accidentally provide excess access, it could lead to sensitive data being exposed or malicious activities happening within the organisation.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Privileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their duties.
bolt ASD Essential Eight E8-RA-ML3.1
priority_high

Why it matters

If privileged access isn’t limited to duty needs, compromised or misused admin accounts can enable unauthorised changes and broad data exposure.

settings

Operational notes

Perform scheduled reviews of privileged/admin roles and service accounts; remove excess rights and grant only the minimum permissions required for each duty.

Mapping detail

Mapping

Direction

Controls