DEV-122 - Require SAW for Admin Actions
Implementation Effort: High – Requires procuring and provisioning dedicated Secure Admin Workstations, defining Conditional Access policies, and changing admin workflows.
User Impact: Medium – Administrators must perform all privileged actions from a designated SAW device, changing their daily workflow.
Overview
A Secure Admin Workstation (SAW), also known as a Privileged Access Workstation (PAW), is a hardened device dedicated exclusively to performing administrative tasks. By requiring all privileged actions to originate from a SAW, organizations create a clean-source environment that significantly reduces the risk of credential theft, malware injection, and lateral movement from compromised general-purpose workstations.
This supports Verify explicitly by ensuring that admin sessions originate from a trusted, hardened device with known security posture. It supports Assume breach by isolating privileged operations from everyday browsing, email, and productivity activities where compromise is most likely. Without SAW enforcement, a compromised admin workstation gives attackers direct access to management planes.