privileged access workstation request workflow
Workflow for requesting and provisioning Privileged Access Workstations (PAWs). Covers eligibility, the request steps, and usage rules. Use for admin PAW requests. Not for standard workstation provisioning.
TL;DR
PAWs go to admins who touch tier-0 systems: verify the admin role justifies it, provision a hardened dedicated device (no email, no web browsing), and enroll it in the PAW management policy. The rule is simple: privileged credentials only ever touch PAWs.
The error
(Access request; no error.)Steps
- Verify eligibility: the requester holds a privileged role (domain admin, Entra Global Admin, or equivalent). Expected: confirmed. PAWs are for privileged users, not a status device.
- Provision a dedicated hardened device: clean OS build, no email client, no general web browsing, application allowlisting. Expected: hardened per the PAW baseline.
- Enroll in the PAW device group with its strict compliance and Conditional Access policies. Expected: policies applied. The PAW policy should be stricter than the standard fleet.
- Brief the user on the rules: privileged accounts only on the PAW, no personal use, report loss immediately. Expected: acknowledged. The discipline matters more than the hardware.
- Record the assignment in inventory and the access ticket. Expected: documented.
When to use
- New privileged admins
- Tier-0 administration hardening projects
When not to use
- Standard user provisioning
- Admins without tier-0 duties (standard hardened laptop suffices)
Compatibility
- Any MDM; the concept is Microsoft's PAW model, adaptable elsewhere
Variants
Virtual PAW
A hardened VM can substitute where hardware is impractical, with the same usage rules.
Existing admin with a standard laptop
Migrate their privileged work to the PAW; do not let old habits persist.
Why it happens
Credential theft targets admin workstations. A PAW shrinks the attack surface to a single hardened device, so a compromised daily-driver laptop cannot yield domain admin.
Edge cases
- PAW loss is a security incident, not just a lost-device ticket.
- Audit PAW compliance separately; drift defeats the purpose.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_j9DqnrTmNe0HD2743XA-oQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.