Restrict administrative privileges
Administrative (admin) accounts can install software and change security settings — which makes them the first thing attackers hunt for. This control keeps admin rights to the few people who need them, separates admin accounts from everyday accounts, and keeps privileged access reviewed and logged.
It is control 5 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
A stolen admin account can undo every other defence, so questions about admin-account separation and review appear on most cyber-insurance questionnaires.
Maturity Level 1 — the baseline
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Is a request checked and approved before anyone is given admin access to your systems?
ACSC requirement: “Requests for privileged access to systems, applications and data repositories are validated when first requested.”
Do people with admin rights use a separate admin account for admin work, and a normal account for everyday work?
ACSC requirement: “Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.”
Are admin accounts blocked from browsing the web and reading email (unless explicitly authorised)?
ACSC requirement: “Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.”
Maturity Level 2 — the common target
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Is admin access automatically disabled if it hasn't been used for 45 days?
ACSC requirement: “Privileged access to systems and applications is disabled after 45 days of inactivity.”
Are passwords for built-in admin, service and emergency accounts long, unique, unpredictable and stored securely?
ACSC requirement: “Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.”
Is admin activity (privileged sign-ins and actions) recorded in a central log?
ACSC requirement: “Privileged access events are centrally logged.”
Maturity Level 3 — advanced
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Is admin access granted only temporarily when needed ('just-in-time'), rather than standing all the time?
ACSC requirement: “Just-in-time administration is used for administering systems and applications.”
These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).