Skip to content

Empowering Least Privilege Access with Entra ID and AdminByRequest

Empowering Least Privilege Access with Entra ID and AdminByRequest

Section titled “Empowering Least Privilege Access with Entra ID and AdminByRequest”

In the ongoing journey to secure organizational environments and mitigate risks, enforcing the principle of least privilege is paramount. Microsoft recently introduced new capabilities in Entra ID that significantly enhance our ability to manage local administrator privileges effectively. These enhancements, coupled with tools like AdminByRequest, can create a robust, secure, and streamlined approach to managing local administrator access.


Understanding the New Entra ID Capabilities

Section titled “Understanding the New Entra ID Capabilities”

When a computer is connected to Microsoft Entra ID, it typically associates two roles automatically:

RoleDefault AccessSecurity Risk
Global AdministratorsGranted local administrator access on connected devicesHigh - excessive privileges across all devices
Local Admins via Entra JoinThe user who performs device enrollment becomes local adminMedium - privilege creep for individual users

While this approach ensures operational flexibility, it often violates the principle of least privilege, creating potential security vulnerabilities. For example, excessive admin rights can lead to accidental system misconfigurations, malware infections, or privilege escalation attacks.


Thankfully, Microsoft has introduced new settings to address this challenge:

SettingOptionsBusiness Value
Global administrator role as local adminEnable/Disable default behaviorReduces attack surface by removing automatic admin rights
Registering user as local adminGrant to all users, selected users, or disable entirelyProvides granular control over device enrollment privileges

These capabilities enable IT teams to eliminate unnecessary local admin privileges and adopt a more secure, least-privileged access model.


The Role of AdminByRequest in Securing Local Admin Access

Section titled “The Role of AdminByRequest in Securing Local Admin Access”

While Entra ID’s new capabilities are a great step forward, organizations often require a more comprehensive solution for managing and auditing local administrator access. This is where AdminByRequest excels.

AdminByRequest is an endpoint privilege management (EPM) solution that eliminates standing local admin rights while providing users with a secure and controlled way to elevate privileges when necessary.


FeatureCapabilityBusiness Value
On-Demand Privilege ElevationUsers request temporary admin access for specific tasks with approval workflowsEliminates permanent admin rights while supporting operational flexibility
Comprehensive AuditingTracks every elevation request and admin action with detailed logsCreates detailed audit trail for compliance and security monitoring
Pre-Approved ApplicationsOrganizations create whitelists of applications that can run with elevated privilegesStreamlines workflows while maintaining security controls
Policy-Based ManagementDefine granular policies for specific users or groups under certain conditionsEnsures consistent privilege management across the organization
Break-Glass AccessIT admins can grant immediate emergency access without compromising long-term securityProvides critical access for urgent situations while maintaining audit trail
Integration CapabilitiesConnects with Microsoft Sentinel, ServiceNow, Slack/Teams for seamless workflowsEnables real-time monitoring and automated security processes

Strategic Benefits: Combining Entra ID and AdminByRequest

Section titled “Strategic Benefits: Combining Entra ID and AdminByRequest”

Combining Entra ID’s new settings with AdminByRequest creates a layered approach to privilege management:

Entra ID’s settings ensure only authorized users can become local admins, while AdminByRequest removes the need for permanent admin access altogether.

2. Comprehensive Auditing and Accountability

Section titled “2. Comprehensive Auditing and Accountability”

While Entra ID provides basic control, AdminByRequest delivers detailed logs and analytics, helping organizations meet compliance requirements like ISO 27001, SOC 2, and GDPR.

3. Security Without Sacrificing Flexibility

Section titled “3. Security Without Sacrificing Flexibility”

AdminByRequest ensures users can perform necessary tasks with elevated privileges while preventing misuse, malware infections, or accidental changes.

AdminByRequest’s seamless integration with Microsoft Entra ID and other tools means IT teams can quickly deploy and manage the solution without overburdening their resources.


Here’s a suggested strategy for implementing least privilege access using Entra ID and AdminByRequest:

StepActionOutcome
Review Default SettingsDisable global administrator and registering user roles as default local admins using Entra ID’s new settingsEstablishes secure baseline configuration
Implement AdminByRequestDeploy AdminByRequest to eliminate standing local admin rights across all devicesRemoves persistent security vulnerabilities
StepActionOutcome
Build Pre-Approved Apps ListIdentify commonly used applications that require admin rights and pre-approve them in AdminByRequestReduces approval delays and improves user experience
Configure Access PoliciesDefine granular policies for different user groups and scenariosEnsures appropriate access levels based on roles and responsibilities
StepActionOutcome
Monitor and AuditUse AdminByRequest’s logs and integration with tools like Sentinel to monitor admin activityEnables proactive threat detection and compliance reporting
Train Your TeamsEducate users about new workflows and the importance of least privilege accessEnsures successful adoption and reduces resistance to change

Key Takeaway: The combination of Entra ID’s enhanced privilege controls and AdminByRequest’s comprehensive EPM capabilities creates a robust security framework that eliminates standing admin rights while maintaining operational efficiency and ensuring regulatory compliance.


With cyber threats becoming more sophisticated, eliminating standing admin rights is no longer optional. Microsoft’s new Entra ID capabilities, combined with a robust solution like AdminByRequest, provide the tools necessary to enforce least privilege access while maintaining operational efficiency.

By adopting this dual approach, organizations can significantly reduce their attack surface, improve compliance, and enhance overall security. Now is the time to take control of local admin access and empower your organization to work securely.