CA-06CriticalMaximum Security
Restrict Admin Access to Privileged Access Workstations
Conditional Access control for Microsoft 365 and Entra ID
Why This Control Matters
Privileged Access Workstations (PAWs) are hardened devices dedicated to admin tasks. By restricting admin portals to PAWs, you prevent credential theft from compromised daily-use devices.
Expected State
When this control is compliant, your tenant should meet these criteria:
- 1Administrative portal access is restricted to designated PAW devices
- 2PAW devices have enhanced security controls (Credential Guard, AppLocker)
- 3Break-glass procedures exist for PAW unavailability
Enforcement
Default Mode
Strict
Zero-tolerance enforcement with immediate remediation
Auto-Remediation
Manual Only
Requires dedicated PAW infrastructure and device filters
Ready to implement this control?
TrueConfig continuously monitors your Microsoft 365 tenant for compliance with this and 50+ other security controls.