Do you have local admin rights?

This discussion came up at work recently & the majority of the admins I work with do want to have local admin rights to their wkstns. However, majority of them do have elevated admin privileges when using their token. I really don't think it is necessary to have local admin rights on your workstation as it does create a weakness on your network with that system. So, if that system was to become compromised via malware, phishing, etc, then the attacker could pivot off your system to gain access to other systems.
What does your company do or enforce?
A local telemarketing company was forced to shutdown recently due to being hit with some ransomware encryption (I believe, not for certain) because maybe their backups were not working or didn't have a disaster recovery plan in place...maybe their admins had local admin rights on their boxes?? who knows, I just know it devastated a lot of employees (approx. 300) right before xmas. I don't know the specifics, but I wonder if their IT company just had their hands tied due to restricted IT budgets to have safeguards in place or if they just had an incompetent security posture in place. I believe they had their own IT staff but it could have been outsourced to a local MSP.
What does your company do or enforce?
A local telemarketing company was forced to shutdown recently due to being hit with some ransomware encryption (I believe, not for certain) because maybe their backups were not working or didn't have a disaster recovery plan in place...maybe their admins had local admin rights on their boxes?? who knows, I just know it devastated a lot of employees (approx. 300) right before xmas. I don't know the specifics, but I wonder if their IT company just had their hands tied due to restricted IT budgets to have safeguards in place or if they just had an incompetent security posture in place. I believe they had their own IT staff but it could have been outsourced to a local MSP.
CompTIA A+, Network+, i-Net+, MCP 70-210, CNA v5, Server+, Security+, Cloud+, CySA+, ISC² CC
Tagged:
Comments
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
Forum Admin at www.techexams.net
--
LinkedIn: www.linkedin.com/in/jamesdmurray
Twitter: www.twitter.com/jdmurray
Security+, eJPT, CySA+, PenTest+,
Cisco CyberOps, GCIH, VHL,
In progress: OSCP
One interesting product that we're testing out here is Beyondtrust's product at our org: https://www.beyondtrust.com/endpoint-privilege-management I'm not sure if anyone here else has this product running in their environment but it's mainly for the developer use case.
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
Wow, had a flashback to my colleague in 2001 who used to do this to solve issues as "recommended by the vendor". True story.