Admin tools are part of the privileged access path
The laptop and the tooling used to administer critical systems are part of those systems' security, whether or not anybody treats them that way.
An administrator working from a machine that also reads email and browses the web has connected the most dangerous account to the most common way in. The credentials, the session and the keystrokes are all available to anything running on that device. Separating administrative work onto its own trusted machine is unglamorous and closes a very well-trodden route.
More on Authorisation and privilege
- Least privilege decays over timeNobody hands the old one back
- Break-glass access should be exceptional and noisyLoud on purpose
- Privilege boundaries matter more than job titlesRead the account, not the business card
- Permission inheritance can hide excessive accessGranted upstairs, arrives downstairs
- Wildcard permissions widen blast radiusOne character, a much bigger circle
- Deny rules can create hard guardrailsOne no ends it
