Why administrative access is an unnecessary risk
If someone in your organization has admin rights, they could easily add another local account and possibly install malicious software (even if unknowing). This may allow an attacker to gain a foothold over the system if they simply crack the credentials or manage to install malware. In most cases, regular employees rarely have a legitimate need for their job. Admin privileges, however, are sometimes granted informally to satisfy urgent business needs or client requests. This turns into a serious business risk.
How to grant temporary administrative access?
As an IT administrator, holding back admin access creates friction with the users. To overcome this, an EPM system helps. Endpoint privilege management (EPM) is a tool within PAM that helps grant temporary admin access to users based on approval.
When users requires access, they would be able to raise it as a request on their helpdesk and their manager or IT can approve the request by modifying the ticket.
The access would be controlled and monitored – meaning that the employee would not be able to add another local admin account to overcome their restrictions.
Revoke access after the requirements ends
Once your devs and users complete their tasks such as installing updates, by elevating one or more applications, their admin rights can be revoked. IT can also configure policies to ensure that the user can only access specific applications and block malicious ones.