Setting Up Privileged Access Workstations (PAWs)

A step-by-step guide to implementing secure administrative workstations

What are Privileged Access Workstations (PAWs)?

Privileged Access Workstations (PAWs) are hardened and dedicated computers used to perform sensitive tasks or access critical data and systems. They are a crucial component of the Administrative Tier Model, primarily used for Tier 0 administration.

Why Use PAWs?

PAW Setup Checklist

  1. Procure dedicated hardware for PAWs
  2. Install a clean operating system (latest Windows Server or Windows 10 Enterprise)
  3. Apply the latest security updates and patches
  4. Implement full-disk encryption (e.g., BitLocker)
  5. Configure UEFI Secure Boot
  6. Enable Windows Defender Application Control (WDAC) or AppLocker
  7. Implement network isolation for PAWs
  8. Configure Multi-Factor Authentication (MFA)
  9. Install and configure necessary management tools
  10. Implement auditing and monitoring

Detailed Setup Instructions

1. Hardware Procurement

2. Clean OS Installation

3. Security Updates

4. Full-Disk Encryption

5. UEFI Secure Boot

6. Application Control

7. Network Isolation

8. Multi-Factor Authentication

9. Management Tools

10. Auditing and Monitoring

Best Practices for PAW Usage

Warning: Never connect PAWs to untrusted networks or use them for non-administrative purposes.

Maintaining PAWs

Tip: Consider implementing a separate update and patch management process for PAWs to ensure thorough testing before deployment.





Scroll to Top