Local admin changes the consequence of compromise
Whether a user is a local administrator decides how bad it is when they click the wrong thing.
Without it, malicious code runs as that user, which is bad. With it, it can disable security tooling, install persistence, read credentials from memory and reach further. Removing local admin is one of the highest-value and most resented changes available, and the resentment is why it so often does not happen.
More on Endpoint security
- EDR visibility depends on the sensor being aliveSilence is not the same as safety
- Application allowlisting controls execution, not intentThe list checks the name
- Device compliance is a snapshot, not permanent healthA tick is a photograph
- Full-disk encryption protects a powered-off device bestAt rest means switched off
- USB controls are a system design problemDesign the socket, not the poster
- Patch compliance percentages can hide critical exceptionsWhat the number covers
