Local Admin Access & Security
The University of Alberta is committed to providing a secure computing environment that supports the diverse and specialized needs of our academic and research communities. To protect the integrity of university data and systems, Information Services & Technology (IST) has refined how local admin access is managed on university-owned devices.
Understanding Local Admin Access
A local administrator account has unrestricted permissions to modify a computer’s operating system, install any software and access sensitive system areas. While these capabilities offer significant freedom, they represent a substantial security risk. If an account with administrative rights is compromised, an attacker gains immediate, wide-reaching access and could use it to attack other university systems and networks and steal research data.
To mitigate this risk, IST utilizes the Endpoint Privilege Management (EPM) tool. It allows us to move toward an on-demand model, ensuring you have the access you need when you need it. Most users will have more flexibility over their workstation, while others will see only a few sensitive actions restricted.
Myth vs Reality: Local admin access at the U of A
Myth: “IST is removing my ability to do my work.”
Reality: IST is managing risk, not removing capability. You retain the ability to perform your tasks; only the method of gaining access is changing to a more secure model.
Myth: “I will have to call IST for every small change.”
Reality: No. Most daily tasks, including installing low-risk software and managing peripherals like printers, are pre-authorized and require no IST intervention.
Myth: “Local admin access is being prohibited.”
Reality: There is no prohibition on administrative capabilities. Now there is a range of privileges that can be used to provide the necessary access to complete work while keeping some restrictions to reduce cybersecurity risk. IST will work with you to be sure your needs are met.
Myth: “This infringes on my academic freedom.”
Reality: Security safeguards academic freedom. By preventing unauthorized access and malware, we ensure your research, data and tools remain available and untampered with.
Managed Workstyles
To ensure every member of the university community can work effectively and securely, IST has established a role-based workstyle model.
Standard
Designated for general office use, browser-centric activities and primary administrative workloads, the Standard workstyle is optimized for roles that rely on a consistent suite of tools. Users can install and update pre-authorized, low-risk applications (such as Microsoft Office and Adobe Reader) and manage peripherals, such as home printers, without IST intervention. This level offers a zero-friction experience for daily university operations.
Not all software will be automatically permitted – you may need to request software installation by submitting a General IT Inquiry ticket through the U of A Service Portal.
Medium Flexibility
For professional staff whose roles require a broader range of software, the Medium workstyle provides enhanced flexibility. This configuration is intended for “power users” who need to install applications from a wider variety of known, verified publishers. It allows for a limited range of system setting modifications required for specialized office workflows.
High Flexibility
This workstyle is specifically designed for researchers, academic staff and software developers. We recognize that academic freedom requires the ability to test niche software, install tools from a variety of sources and modify advanced system settings to meet evolving research objectives. Under this workstyle, you maintain broad operational autonomy.
Administrator
In specific cases where full system control is a technical necessity, such as managing complex lab instrumentation, legacy research software or certain types of software development, the Administrator workstyle is applied. This workstyle is reserved for specialized functional requirements where administrative oversight is a core component of the role’s technical responsibilities.
These workstyles are pre-set based on the typical requirements of the university roles. However, IST is committed to a security partnership with all faculties and departments:
- When purchasing new computer equipment, IST will work with you to understand your needs and provision this account during initial setup wherever possible.
- As your research or professional needs evolve, your access can evolve with them. If your current configuration does not meet your requirements, IST provides a consultative review process to transition you to the appropriate level of flexibility.
To discuss your current workstyle or request a transition to a different access level, please submit a General IT Inquiry ticket through the U of A Service Portal.
Frequently Asked Questions
Why is this change necessary?
The risk profile for local admin accounts has changed. Modern threats allow malware to install silently and to bypass security protocols once access to local admin rights is gained. By aligning access with your actual workload, we reduce the opportunity for a threat actor to compromise a single machine and use it to attack other members of the university community.
Will I lose my current administrator account?
Changes have already affected some systems. No changes are being made to your current account as it works today. If your account today is not meeting your needs, please contact IST. Newly provisioned computer accounts for administrative roles will start as standard accounts, while academic accounts will have high flexibility.
How does this affect my research?
For most researchers, the impact is minimal. The High Flexibility workstyle is specifically intended to support the “niche” and evolving software needs of the research community without the delays of traditional IT support tickets.
But my work requires an administrator account. What’s the process?
If your workflow requires installing specialized software or modifying advanced settings, you can request a transition to a High Flexibility workstyle. IST will work with you to verify your requirements and ensure your system configuration supports your academic and professional goals. Requests for additional access requests can be made by submitting a General IT Inquiry ticket through the U of A Service Portal.
Who do I contact for questions regarding local admin access and workstyles?
If you have any questions or require further information, please contact IST by submitting a General IT Inquiry ticket through the U of A Service Portal.
Members of the U of A community can also request an information session. These sessions provide a deeper look at how managed workstyles enhance both individual and institutional resilience and offer a direct opportunity to discuss your specific technical needs with your team.