Why Remove Local Admin Rights?
Common risks associated with users having unlimited local admin rights
Removing Local Admin Rights Will Help Close the Gap On External Threats
Aside from the concern of an Employee accidentally taking a false step while having Admin privileges is what a malicious actor can do if they are able to compromise one of your user’s login credentials. When your users have Admin privileges potentially any access that is obtained can quickly escalate into a network wide issue. Attackers use native tools in Windows along with local Admin privileges to successfully manipulate local certificate stores to gain trust, bypass other security tools, and ultimately escalate their privileges to gain access to network admin credentials, secured files, data stores, and resources on your network allowing them to carry out any action remotely at will. This not only gives them the ability to gain access but to do so for extended periods of time while remaining undetected with ample opportunity to cover their tracks.