Skip to content
FioSec Consulting

Identity Security · Case study

When everyone is an admin, so is the attacker

Local administrator rights everywhere and shared admin credentials meant one compromised account could take the whole environment with it. FioSec rolled out least privilege and privileged access management without grinding day-to-day IT to a halt.

The situation

The organization

An organization where administrator rights had accumulated for years: staff had local admin on their machines, IT shared powerful accounts, and nobody had rolled it back because everything seemed to depend on it.

What prompted it

Admin rights had been handed out for convenience for years: to fix a printer, install an application, get a project unstuck. The result was an environment where a single phished user could hold administrator control, and shared admin credentials meant powerful actions could not be traced to a person. Everyone knew it was a problem; nobody wanted to be the one who broke IT by fixing it. The organization brought in FioSec to roll it back safely.

What FioSec did

Each step maps to a layer of the Layered Defence model: vendor-agnostic by design, described by the control it delivers rather than any one product.

  1. Discover who has what

    We mapped where administrative rights actually lived: local admin on endpoints, shared accounts, and the service accounts nobody logs into but everything depends on.

  2. Least privilege, staged

    Rights were removed in stages, starting where the risk was highest, with the workflows that legitimately need elevation identified first, so removing admin did not mean breaking the business.

  3. Privileged access management

    Administrator accounts were separated from everyday logins and brought under privileged access management: credentials vaulted instead of shared, and powerful sessions accountable to a person.

  4. Elevation when needed, not always

    Where staff genuinely need elevated rights, they get them for the task rather than carrying them permanently, so privilege exists when justified and expires when the work is done.

The outcome

A phished everyday account no longer comes with administrator control of the environment.

Privileged actions are traceable to individuals instead of a shared password.

Day-to-day IT kept working throughout the rollout: the point was to remove risk, not productivity.

Facing something similar?

Tell us where you are today and we’ll help you map the right next step. No obligation.