Organisations face an increasingly complex cyberthreat landscape, making robust endpoint controls and privilege management critical to safeguarding operations across devices and applications. Theshan Mudaly, Senior Solutions Engineer, BeyondTrust, tells us how organisations can implement endpoint privilege management to reduce attack surfaces, improve efficiency and maintain productivity without compromising security.

It is not news that we are under constant attack. Businesses, citizens and governments are all worried about the cyberthreat landscape. In a study concentrating on the second half of 2024, the worldwide incidence of email-based attacks was found to have skyrocketed — a 197% increase on the same period in 2023. The same research found that in December, the United Arab Emirates (UAE) ranked first in ‘percentage of blocked malicious URLs at the endpoint’ (16.2%) and joint first with Singapore and Italy in malware targeting.
Endpoints are where many, if not most, cyberincidents begin. In the digital-first age, to protect economic activity, we must protect our endpoints. In recent years, as we have come to learn more about the central role of the user in cyberbreaches, endpoint privilege management solutions, sometimes referred to as privilege elevation and delegation management (PEDM) solutions, have grown in popularity.
PEDM solutions allow organisations to automate the dos and don’ts of user activity while preserving productivity. By combining privilege management, application control and centralised administrative control, the enterprise ensures each user has the precise subset of privileges necessary to do their job optimally. Admin rights are assigned sparingly, only to those who cannot perform without them. In the past, these rights would have been handed out across many unnecessary users. This was done for the convenience of IT teams who had neither the time nor resources to design a privileges framework, but it led to IT environments riddled with low-level user accounts that had access to even the most sensitive areas.
The user problem
This practice extended to the assigned laptops and desktops of users. They could execute, install, run or change anything on their devices. And because it was so easy for them to do so, it became possible for them to install something by accident, or for something to be installed on their behalf without their knowledge. Threat actors begin with low-level employees, hijacking their credentials and moving laterally across an environment. Lateral movement is unencumbered where admin rights have been assigned to these low-level accounts. Malware can then run with elevated privileges, security agents can wave through harmful traffic, and software can be installed and executed with zero oversight.
All of this is bad enough before we consider the impact of cloud and multi-cloud environments. Today’s major cloud infrastructure platforms can grant a combined total of 40,000 permissions to identities, half of which are considered high risk. Endpoint privilege management is a direct response to this complexity, providing users with just enough access, at just the right time, for just long enough, to remain productive.
Endpoint privilege management reduces the attack surface for endpoints and applications. The least-privilege approach alone has been shown historically to have mitigated 75% of Microsoft’s critical vulnerabilities. PEDM also improves operational efficiency, which is good news for IT and security teams who will not be assigned a further mountain of work in the interest of enhanced security.
Rather, they will become beneficiaries of the stricter policies through centralised, policy-based management of privileged access. Endpoint privilege management also relieves organisations of a significant portion of their compliance burden because of its ability to provide detailed audit logs while enforcing the principle of least privilege. Additionally, stricter privilege management will help organisations qualify for cyberinsurance at a time when providers commonly ask about privilege levels and whether users have local admin rights on their PCs.
The ideal platform
When searching for the ideal PEDM platform, organisations must review their endpoint ecosystem to identify its unique security needs. They must then balance those needs with those of operational productivity. In competitive commercial spaces, where some risk is always expected, the modern UAE business will aim for a minimisation of the attack surface mixed with an overall improvement in admin efficiency.
To achieve this — and leave users in a position where they can do their daily work without constantly hopping security fences — we start with the basics we have learned so far. Remove default local admin rights, control root access, and implement least privilege and zero-trust security. Whatever PEDM platform is procured must allow for the major OSes — Windows, macOS and Linux — as well as all types of endpoints, including desktops and servers. And it must do so without compromising user activity.
Endpoint privilege management should allow security and admin teams to proactively restrict installation of applications. In general, the more granular this control is, the better for productivity, but each organisation will have its own red lines. These installation controls are an extension of the principle of least privilege, which, as we have seen, limits the risk of lateral movement by an attacker. To be successful, attackers eventually must run code and install tools. More advanced threat actors may opt for stealthy approaches like fileless attacks and living-off-the-land (LotL) exploits. PEDM and least privilege are ideally placed to prevent attackers having the necessary permissions to do anything that is useful to them and harmful to the organisation.
Secure at last
The new privilege-management environment should always respect the need for productive work. Ideally, it should help users work more efficiently. The needle that solutions must thread is giving the right access at just the right time for only the time needed to do the task at hand, and to do so without any noticeable degradation in workflow. The best solutions will speed up compliance officers’ work by simplifying audit processes and will smooth out systems integration so that businesses’ past security investments are not wasted.
Across the threat landscape, dangers constantly multiply and evolve. The approach of locking down architecture in a preventative posture has evolved into a zero trust mentality where least privilege reigns. What we do next matters. But whatever steps we take, PEDM must be among them. For when we diligently manage the main points of failure, we strengthen the entire digital estate.


