All articles

Remove administrator rights and eliminate critical vulnerabilities in your organisation

Removing administrator rights, or admin rights, does not only help reduce insider threats. Managing administrative privileges properly also improves protection against external threats.


Once you have ensured that all employees apart from a few system administrators have user profiles rather than administrator profiles, you can assess administrator rights on a case-by-case basis.

The guidelines below explain how removing administrator rights improves security across the board and how to do it effectively.

The guidelines:

  • What are the risks of using administrator rights?
  • Why unrestricted administrator rights are dangerous for both internal and external threats.
  • How removing administrator rights minimises risks.
  • Data and practical examples.
  • Best practices for minimising risks associated with administrative privileges.

Are you ready? Let's go!


What are the risks of using administrator rights?

Suppose you give everyone in your organisation administrator rights. What are the risks? Here are a few specific examples:

  • Installing malicious apps such as spyware or malware to steal money or data, or disrupt activities.
  • Outdated software is often forgotten and not removed from the system. This clutters systems because the software is no longer updated. It also creates unnecessarily large numbers of often critical vulnerabilities.
  • Creating backdoors that allow cybercriminals to install malicious apps or hack systems.
  • Opening or exporting sensitive data that can then be misused.
  • Making changes that lock legitimate users out of the system.
  • Publishing misleading or malicious information to cause a PR crisis.

Of course, a user would not necessarily do all this deliberately. But hackers can achieve it by manipulating someone with administrator rights, for example by sending a phishing email or replacing a USB stick with their own.

Manage administrator rights to neutralise insider threats

First, to be clear: even removing administrator rights from ordinary users in your organisation does not guarantee freedom from insider threats. You can simply never have complete control over every user's actions. Plenty of dangerous things remain that an employee can do accidentally or deliberately, even without administrator rights. For example:

  • Setting a weak password or one also used for other personal accounts.
  • Sharing a password with someone else.
  • Clicking unsafe links in emails or on the web.
  • Giving protected information to third parties, accidentally through cybercrime such as CEO fraud, or deliberately.
  • Browsing through files on a colleague's workstation while they are away, particularly dangerous if that colleague handles more sensitive information than the employee concerned.
  • Connecting an infected USB stick or external hard drive to a workstation.

Removing administrator rights is nevertheless the absolute starting point for preventing insider threats. It may not prevent every insider threat, but it is certainly a good start.

Why, then, do some organisations still automatically give administrator rights to all users? Several persistent myths exist.

  • We have installed antivirus software and a firewall, so there is nothing to worry about. They cannot touch us.
  • If administrators have to approve everything, they will spend hours a day doing so.

Admittedly, some myths contain a grain of truth. Of course it is sensible to install antivirus software and a firewall, but that is not enough. And of course system administrators spend time granting administrator rights, but that is nothing compared with the risks they help prevent this way. Privilege management software also minimises wasted time.

Manage administrator rights to neutralise external threats. Keep vulnerabilities out by removing administrator rights.

Managing administrator rights is not only about managing insider threats. It is also about closing security gaps commonly present in everyday business software and operating systems.

Fortunately, these systemic vulnerabilities are often discovered and fixed with a patch before a hack takes place. But if hackers identify them quickly, they exploit them before they can be detected and fixed.

An analysis of Microsoft security shows that, since 2015, its systems have contained more than 500 vulnerabilities classified as “critical” each year. In 2019, 668 vulnerabilities were reported across various Windows OS versions. This does not mean Microsoft products are poor or insecure; quite the opposite. System vulnerabilities are simply inevitable in products used by such a large group of people, and hackers do not rest until they find the gaps.

In short, risks are inevitable. All we can do is make them as small as possible by removing administrative privileges from ordinary users and granting them only on request and for a limited period.

Data and practical examples

How do you prevent your organisation from appearing in the news as a hacking victim? Unfortunately, the likelihood is greater than many organisations realise. Here are a few facts to give you an idea of the scale of the danger.

  • 63% of all data breaches result from weak or stolen passwords. If users had not had administrator rights, the consequences would not have been as severe.
  • 74% of all data breaches result from misuse of accounts with administrator rights.
  • It may have been the most foolish decision ever, but Equifax chose “admin” as both the username and password for a database, after which a massive data breach occurred.
  • Facebook featured prominently in the news with scandals and data breaches arising from misuse of administrator rights.
  • In May 2019, Linksys routers leaked all historical data because administrator rights had been set automatically.
  • Marriott lost the financial details of more than 400 million users over a four-year period. Better monitoring of unauthorised access through administrator rights management would have revealed the breach much earlier.

I could go on. Data breaches appear in the news every day. Reports often discuss technical details and methods used by hackers, such as DNS hijacking, a Trojan or malware, but rarely explain how it came to that: hackers gained entry by misusing an account with administrator rights.

Best practices for managing administrator rights securely

How can you manage administrator rights securely and productively for both users and system administrators? Below, we outline several methods: the best practices.

#1. Encourage an environment with as few administrator rights as possible

Developing a good security culture within your organisation comes down to granting as few administrator rights as possible. This does not mean imposing a strict “need to know only” policy. Internal transparency encourages employees to look beyond their own desks, better understand their tasks and assignments, and work more effectively towards the ultimate goal. Avoid unintentionally creating a culture dominated by secrecy, and focus on protecting genuinely sensitive information.
A strictly “need to know” policy will cause overall productivity to plummet.

#2. Automate the elevation and removal of administrator rights

Automation is by far the most effective way to grant administrative privileges to end users across your organisation or remove those rights without system administrators having to spend vast amounts of time on it.

Reliable privilege management software automates the process of users requesting administrative access and system administrators granting or refusing those rights.

#3. Ensure administrators follow up every grant of administrator rights unless removal is automated

If you choose to elevate and remove administrator rights manually, make sure system administrators arrange the removal of those rights as soon as they grant administrative privileges to an end user.

The recommended timeframe is 5 to 15 minutes, giving a user enough time to install the software they need. It is also sensible for the system administrator to record exactly which software is installed. Because privilege management is not automated, there is a risk of accidentally installing a corrupt file.

#4. Have procedures in place for quarantining an endpoint

What does it mean for your organisation if an account is hacked from within? Are you sure that account cannot be used to carry out actions affecting your organisation's security?

Ensure your internal policies and technical security measures allow your system to revoke any privilege quickly and quarantine the compromised endpoint. An automated privilege management program is the fastest and most effective way, but it can also be done manually.

#5. Make sure superuser accounts are secure too

Superuser accounts belong to system administrators who can, among other things, install any software, access all data and elevate or remove other users' administrator rights.

Organisations need one or two system administrators to manage other users' permissions securely. At the same time, procedures must protect their accounts. If one administrator's account is hacked, how well can your organisation resolve the situation?

Agree a crisis management procedure with the CTO, IT manager or security manager and the system administrators specifically for this scenario. For example, make one administrator's activities transparent to another so they can trace each other's steps, leaving breadcrumbs. This supports accountability and prevents administrative tasks being carried out remotely. Allow other system administrators to revoke the compromised administrator account's privileges very quickly in the event of a hack.

Check now!

If all or some users in your organisation have access to administrator rights, check the status of those rights as soon as possible. Create a map of users' administrator rights and a procedure for granting them. Removing administrator rights by default is an important starting point for protecting your organisation against critical internal vulnerabilities.

Preferably use specialist software to manage administrator rights properly. Always remain vigilant. It is good to trust your employees, but ensure damage remains limited if an employee's account is hacked.

Make sure you have more than one system administrator. Ensure administrators can limit the damage if one of these superusers is compromised. Stay informed about the latest threats and events.

Removing administrative privileges is only a first step towards better security, but it is a very important one. If you act quickly and develop a coherent internal policy for elevating administrator rights, you are at least heading in the right direction.

This blog was written in collaboration with Miriam Cihodariu, Communications and PR Officer at Heimdal Security.

 


Back to all articles