Terminology Index
Glossary
2953 terms
Local Admin Restriction
Limiting which users have local administrator rights on endpoints, removing unnecessary admin access so a compromised user account or malware cannot easily gain full control of the machine. A high-impact hardening measure.
Local admin restriction means most users operate as standard users, with local administrator rights granted only where truly needed and ideally just-in-time. Because local admin lets malware install persistently, disable defenses, and harvest credentials, removing it sharply limits the damage from a compromised account or a successful phish. It is one of the highest-value, most-recommended endpoint hardening controls, reducing both attack surface and blast radius across an organization.
Introduced in: System Hardening Fundamentals
Examples
- Having most employees run as standard users without local admin.
- Granting local admin only where needed, ideally just-in-time.
- Blunting malware impact by removing unnecessary admin rights.
