No Result
View All Result
  • Login
Tuesday, June 23, 2026
theadvisertimes.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
theadvisertimes.com
No Result
View All Result
Home Market Analysis

Stop Running As Admin On Windows Daily

by theadvisertimes.com
5 months ago
in Market Analysis
Reading Time: 3 mins read
A A
0
Stop Running As Admin On Windows Daily
Share on FacebookShare on TwitterShare on LInkedIn


My computing career goes back to when Windows 3.1/3.11 was the dominant desktop OS and slowly being replaced by just-launched Windows 95. Novell NetWare was at its peak for file and print services and slowly losing market share to Windows NT. The enterprise was in a bit of a free-for-all when it came to security as the internet was certainly not as ubiquitous, so firewalls weren’t as common. Authentication could be touchy depending on what backend you were connecting to (NetWare, NT, Banyan VINES, or others), and in many environments, you had multiple logins. Endpoint security, or just “antivirus,” as it was referred to then, was gaining traction from vendors like ESET, McAfee, Norton, and Trend Micro but was far from widely adopted. And as much as admins may have tried to lock down desktops, if you were using the common OSes (DOS, Windows-on-DOS, OS/2, or even Mac), getting around restrictions such as hidden directories, kiosk menus, or even CMOS passwords meant having a floppy disk and a little knowledge.

Today, we have learned our security lessons, layering security from the application servers down to the browsers on the endpoint, and everything is much better protected.

Putting aside the laughter, the ability to secure the enterprise has improved, but one legacy practice that’s held on within the Windows endpoint space is running locally as administrator. Initially, this was just how Windows operated. Local users had full control of the endpoint, and even if they didn’t, working around those restrictions was easy. But since Windows 2000, there was a clear division between user and admin roles. This didn’t mean that an end user could easily run in user-only and operate effectively, however. Many applications weren’t written well for just the user space and needed either higher-level permissions or even full admin rights because they made system-level changes. Updates to apps usually required administrative permissions to install. Because of convenience and flexibility, many organizations allowed users to run as admins locally to enable users to install whatever applications they needed to do their job.

That last piece is what’s held on the longest. Poorly written apps, while still existing, have very little need to run in the admin space; modern app updates either use a background service update or don’t need admin permissions; and with the move to SaaS and web-based apps, requiring local admin rights in Windows has diminished except for the flexibility. Letting users run as a local admin on their workstations is still common in many enterprises because of the simple fact that controlling the delivery and installation of applications is time-consuming for the IT and security operations teams and end users. Testing applications and updates is also time-consuming, and maintaining application catalogs for the diversity of needs for even a 1,000-user business can be a full-time job. It’s easier to provide the mandatory and common production applications and let the users run whatever ancillaries they choose, hoping the EPP/EDR/XDR platform will catch all the bugs that may pop up in the apps.

The problem with this approach is that when a hacker compromises that user account, they can take up residence in that endpoint and run tools that will not trigger normal threat detection policies such as PowerShell and Command Prompt, WMI or rundll32.exe, or remote desktop tools. They have residence in the enterprise, so they can take their time to slowly probe for other weaknesses, establish residence on endpoints that are more vulnerable and less likely to be monitored for compromise (such as unsecured IoT devices), or with the spread of AI tools and agents, utilize the local AI functions on that endpoint to collect more data that could be beneficial to them.

Security leaders need to recognize that allowing users to be local admins on their corporate endpoints is a security gap that needs to be closed. Privileged identity management solutions can help you identify where users have too much access and monitor and control this. Allowlisting solutions or app control functions within your endpoint security solutions can let you manage and monitor the apps that are allowed to run on the endpoints. And as more applications move to web and SaaS, this should be easier than ever to achieve.

Forrester clients who want to dive deeper into this topic and discuss the approaches that they should take to close this gap can schedule an inquiry or guidance session with me.



Source link

Tags: adminDailyRunningstopWindows
ShareTweetShare
Previous Post

How private credit uses covenant-lite borrowing debt

Next Post

2025 inflation 2.6%; home prices resume rise

Related Posts

Ship and Debit Explained: Protecting Your Channel Margins

Ship and Debit Explained: Protecting Your Channel Margins

by theadvisertimes.com
June 22, 2026
0

Manual ship and debit workflows often lead to financial leakage of up to 8% of the total program value because...

The Canary In The CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing

The Canary In The CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing

by theadvisertimes.com
June 22, 2026
0

Databricks announced CustomerLake, a new customer data platform (CDP) offering, at its Data + AI Summit last week. Though widely...

Death of Fundamental Analysis? How Option Market Makers Now Dictate Spot Prices

Death of Fundamental Analysis? How Option Market Makers Now Dictate Spot Prices

by theadvisertimes.com
June 22, 2026
0

For nearly a century, equity valuations rested on a universally accepted economic playbook: analyze corporate earnings, project free cash flows,...

Report: South Africa Social Tensions Survey 2026

Report: South Africa Social Tensions Survey 2026

by theadvisertimes.com
June 22, 2026
0

South Africa has long been a destination for migrants from across Africa and beyond, drawn by economic opportunities, education, and...

Nuvei Makes Its B2B Cross-border Payment Move: The Payoneer Acquisition

Nuvei Makes Its B2B Cross-border Payment Move: The Payoneer Acquisition

by theadvisertimes.com
June 22, 2026
0

Nuvei’s planned $2.75 billion acquisition of Payoneer signals a broader shift in B2B cross-border payments. The market is moving from...

Guide to Volume Incentive Rebates (VIR) Optimization

Guide to Volume Incentive Rebates (VIR) Optimization

by theadvisertimes.com
June 21, 2026
0

Did you know that for many industrial distributors, rebate income accounts for between 40% and 70% of total net profit?...

Next Post
2025 inflation 2.6%; home prices resume rise

2025 inflation 2.6%; home prices resume rise

Israeli public’s assets under management exceed NS 4 trillion

Israeli public's assets under management exceed NS 4 trillion

  • Trending
  • Comments
  • Latest
Should You Offer a Concession to Get Your Apartment Leased Faster?

Should You Offer a Concession to Get Your Apartment Leased Faster?

June 15, 2026
6 Hotels Where Chase’s Points Boost Yields 2.5x

6 Hotels Where Chase’s Points Boost Yields 2.5x

May 22, 2026
Understanding risk remains a major investor blind spot: TIAA Institute

Understanding risk remains a major investor blind spot: TIAA Institute

June 5, 2026
Anthropic’s confidential S-1 signals summer AI IPO race could heat up fast

Anthropic’s confidential S-1 signals summer AI IPO race could heat up fast

June 2, 2026
Memorial Day 2026: Take Advantage of Food Freebies, Deals

Memorial Day 2026: Take Advantage of Food Freebies, Deals

May 23, 2026
9 Best Cheap Cell Phone Plans That Will Save You Money

9 Best Cheap Cell Phone Plans That Will Save You Money

June 3, 2026
Roku (ROKU) Has a CTV Operating-System and Ad Platform Bigger Than a Hardware Narrative

Roku (ROKU) Has a CTV Operating-System and Ad Platform Bigger Than a Hardware Narrative

0
Gen Z: if you want to succeed at work, you need to start friction-maxxing

Gen Z: if you want to succeed at work, you need to start friction-maxxing

0
266. “I carry the household, the bills, and the stress”

266. “I carry the household, the bills, and the stress”

0
Report: South Africa Social Tensions Survey 2026

Report: South Africa Social Tensions Survey 2026

0
The planning prospects who are ‘hidden in plain sight’

The planning prospects who are ‘hidden in plain sight’

0
Democrat Voters Pining for Change but Unwilling to Change

Democrat Voters Pining for Change but Unwilling to Change

0
Roku (ROKU) Has a CTV Operating-System and Ad Platform Bigger Than a Hardware Narrative

Roku (ROKU) Has a CTV Operating-System and Ad Platform Bigger Than a Hardware Narrative

June 23, 2026
Gen Z: if you want to succeed at work, you need to start friction-maxxing

Gen Z: if you want to succeed at work, you need to start friction-maxxing

June 23, 2026
266. “I carry the household, the bills, and the stress”

266. “I carry the household, the bills, and the stress”

June 23, 2026
Lies, Damn Lies, and the History of Capitalism

Lies, Damn Lies, and the History of Capitalism

June 23, 2026
7 Benefits of Starting Retirement Savings Early

7 Benefits of Starting Retirement Savings Early

June 23, 2026
CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc

CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc

June 23, 2026
theadvisertimes.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Roku (ROKU) Has a CTV Operating-System and Ad Platform Bigger Than a Hardware Narrative
  • Gen Z: if you want to succeed at work, you need to start friction-maxxing
  • 266. “I carry the household, the bills, and the stress”
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • About Us
  • Contact Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.