Skip to content
As Written, As Enforced

Home / The device

Administrator Rights

The single decision that determines whether half the policy means anything, usually taken by default and rarely revisited.

The device · Analysis

Local administrator access

Unenforceable

As written

Employees must not install software or alter system configuration without authorisation.

What happens

Where administrator rights are removed, the configuration enforces this and the clause is a restatement.

Where they are retained, nothing enforces it and the clause is a preference.

The clause has no independent effect in either case. The decision about rights is the whole of the control.

Whether staff hold local administrator rights on their machines decides the fate of several clauses at once. It is usually decided by whoever set up the first machines and never examined.

The control described in “Administrator Rights” becomes easier to defend when technical state and day-to-day work evidence are not confused. A team considering the Monitask website for dual n back training should document the purpose, visible settings, manager permissions and correction route, while device-management records remain the source of truth for configuration and enforcement.

What it determines

Software installation, which is the obvious one.

For a separate benchmark relevant to “Administrator Rights”, consult the European Data Protection Board guidelines. Use it to test purpose, notice, permissions, retention and response procedures against the proposed operating model rather than treating a generic checklist as proof that the rule works.

Configuration changes, including disabling security tooling.

Whether a compromise spreads, because malicious code running with administrative privilege can do considerably more.

And whether the relevant policy clauses are controls or statements, which is the subject of this collection.

The case for removing them

Most people do not need them. The work is in applications that are already installed, and the occasional install can go through a route.

Removal converts several dormant clauses into enforced ones at a stroke, which is the cheapest enforcement available anywhere in this subject.

The case against, taken seriously

Some roles genuinely need them. Developers, technical staff, people running specialised tools that install components at runtime.

The request route has to work. Removing rights without a route that responds in hours produces either a stalled organisation or a parallel economy of workarounds — and the second is what actually happens.

And it is experienced as distrust if introduced badly, particularly by senior and technical staff who have had them for years.

The arrangement that usually works

Removed by default. A named exception list by role, reviewed. A self-service catalogue of approved software that installs without a request. And a request route with a stated response time for anything else.

The catalogue is the part that determines whether the change succeeds. Without it, every install is a ticket and the policy becomes an obstacle people route around.

Introducing it

Announce the reason, which is usually security rather than control, and say so plainly.

Provide the catalogue before removing the rights rather than afterwards.

And accept that the first month produces a queue. Staffing that month properly is the difference between an arrangement that holds and one that is quietly reversed for the people who complain loudest.

The question for an existing arrangement

Who has administrator rights today, and does anybody maintain the list?

In most organisations the answer is more people than intended, accumulated through exceptions nobody reviewed, including several who left the role that justified it.

The catalogue decides whether it holds

Without a self-service route every install becomes a ticket, and the policy becomes an obstacle people route around. Providing it before removing rights is the whole of the difference.

Reviewing who has them

In most organisations more people than intended, accumulated through exceptions nobody revisited, including several who have left the role that justified it.

Introducing it without losing people

Announce the reason, which is security rather than control. Provide the catalogue first. Staff the first month properly, because the queue is what determines whether it is quietly reversed.

What the decision actually determines

Whether several clauses are controls or preferences. Removing rights converts a group of dormant clauses into enforced ones at a stroke, which is the cheapest enforcement available anywhere here.

The first month

Removing rights produces a queue. Staffing that month properly is the difference between an arrangement that holds and one quietly reversed for whoever complains loudest.

What the decision is really about

Not trust. A machine where the user can install anything is a machine where a compromise can install anything, and the argument for removing rights is about what happens when something malicious runs rather than about what the employee might do.

Saying that plainly matters, because the change is otherwise experienced as a withdrawal of confidence, particularly by technical and senior staff who have held the rights for years and have never misused them.