Skip to content

Our admins manage from their regular laptop, that feels unsafe.

A Privileged Access Workstation (PAW) is a hardened device used only for admin tasks: no mail, no browsing, no Office. Stops a phishing mail from instantly compromising domain admin rights.

Try this first

  1. 1Build a clean Windows 11 image with BitLocker, Defender for Endpoint and a tight baseline. No Office, no Slack, no browser plugins.
  2. 2Join to a separate security tier: tier-0 PAW for DC/AD admin only, tier-1 for server admin, tier-2 for workstation admin.
  3. 3Network zone: PAW only reaches AD, admin VLANs, vendor portals. No mail, no general internet (or via a specific proxy).
  4. 4Admin accounts are usable only from the PAW. On the normal laptop the account is unusable for admin tasks (deny logon to this computer GPO).
  5. 5Make it workable: a second laptop has a cost, a stolen domain admin costs more. For SMB one PAW shared by two admins with good logging is sometimes enough.

When to bring us in

For SMBs without budget for a second device, a Hyper-V VM with the same restrictions on the main machine is a stopgap. Not ideal (host compromise = VM compromise) but better than nothing.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.