Graduation Caps being thrown in the air
Programs and Services » Tech20 » Race4Fifteen » Lap 4: Restrict local admin access on all devices

Lap 4: Restrict local admin access on all devices

Why it matters: Restricting local admin access  is a security practice that restricts users (students and staff) from having full administrative control over their school-issued devices. This means they can use the tools and apps they need but cannot install software, change system settings, or make high-level modifications. 

Main Points 

  • Managing and controlling Admin Privileges
  • Protects devices from threats like viruses, ransomware, and unauthorized software. 
  • Reduces IT issues by preventing accidental changes that break or slow down devices. 
  • Safeguards student and staff data by minimizing risk from unapproved apps or downloads. 
  • Ensures compliance with cybersecurity and data privacy standards. 
 
Actions to Take: 
  • Audit and Review Access: Regularly check who has admin rights and remove unnecessary access. 
  • Assign Standard User Roles:
    • Give staff limited access as per their roles.
    • Reserve admin rights for IT only. 
  • Enforce Access Policies: Use tools like Group Policy (Windows) or Admin Console settings to lock down devices.

 

Related Resources:  

 

Cybersecurity Security Plan Controls  

Texas Cybersecurity Framework: AC,PT,CM 

NIST Cybersecurity Framework: AC,PT,CM 

 Center for Internet Security (CIS) v8: 5.4  

CISA Cybersecurity Performance Goal (CPGs: 2.E  

K12six Essentials Cybersecurity Protection: 2.1  

TEA cyber initiative: Yes FY25