CA-06CriticalMaximum Security

Restrict Admin Access to Privileged Access Workstations

Conditional Access control for Microsoft 365 and Entra ID

Why This Control Matters

Privileged Access Workstations (PAWs) are hardened devices dedicated to admin tasks. By restricting admin portals to PAWs, you prevent credential theft from compromised daily-use devices.

Expected State

When this control is compliant, your tenant should meet these criteria:

  • 1Administrative portal access is restricted to designated PAW devices
  • 2PAW devices have enhanced security controls (Credential Guard, AppLocker)
  • 3Break-glass procedures exist for PAW unavailability

Enforcement

Default Mode
Strict

Zero-tolerance enforcement with immediate remediation

Auto-Remediation
Manual Only

Requires dedicated PAW infrastructure and device filters

Ready to implement this control?

TrueConfig continuously monitors your Microsoft 365 tenant for compliance with this and 50+ other security controls.