Terminology Index

Glossary

2953 terms

Open concept maps
L
31

Local Admin Restriction

Limiting which users have local administrator rights on endpoints, removing unnecessary admin access so a compromised user account or malware cannot easily gain full control of the machine. A high-impact hardening measure.

Local admin restriction means most users operate as standard users, with local administrator rights granted only where truly needed and ideally just-in-time. Because local admin lets malware install persistently, disable defenses, and harvest credentials, removing it sharply limits the damage from a compromised account or a successful phish. It is one of the highest-value, most-recommended endpoint hardening controls, reducing both attack surface and blast radius across an organization.

Introduced in: System Hardening Fundamentals

Examples

  • Having most employees run as standard users without local admin.
  • Granting local admin only where needed, ideally just-in-time.
  • Blunting malware impact by removing unnecessary admin rights.
M
1