Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Golden opportunity to tame application privileges current page
Link copied

Golden opportunity to tame application privileges

Oct 20, 2017
Author:
John Dunn
Blog banner default
Golden opportunity to tame application privileges
John Dunn

What is it about Windows XP that has made getting rid of an obsolete operating system so difficult? On the face of it, it should be no contest; XP is inherently less secure than its successors, will no longer receive essential updates, cybercriminals target it more often, and it doesn’t even support the latest secure applications. These factors add up to higher support costs and risk.

Despite this, a hardcore of businesses will continue to use it beyond April's cut-off date in order to support legacy applications they can't do without. Organizations facing this situation are in a bit of a bind, aware they must somehow keep XP on secure life support while planning for the inevitable migration to Windows 7 or 8 later on.

Securing XP while migrating to a completely different OS is a big ask but there are plenty of short term fixes on offer, including visualization and isolation, backed up by incredibly pricey extended support contracts at up to $200 a seat. These will do the job but they also turn XP into a patient demanding expensive full time care.

The alternative is to minimize the risks associated with XP using privilege management. This approach not only cuts XP’s security exposure on PCs where it remains still in use but gives organizations a powerful tool to aid their Windows 7 migration roll-out and security going forward.

Securing XP

The weakness of XP was its assumption that admin rights were an affordable luxury. Many programs needed them to work, as did laptop users making simple changes to settings such as adding printers. Pragmatically, admins granted admin rights because it made life easy, creating a hole cybercriminals exploited to install malware.

A least privilege system supporting XP in addition to Vista, Windows 7 and 8 provides an integrated way to lock down admin rights through Windows Group Policy, distributing them only when really needed while creating an audit trail of events. In XP’s case, this doesn’t remove all risk (for instance OS or application vulnerabilities) but it does greatly reduce the attack surface to the absolute minimum and gives admins some visibility on how the OS is being used in real time.

Migrating to Windows 7

The same benefits of least privilege apply to Windows 7 and 8 too, but the strategic gain from a system such as Avecto's Defendpoint is the advantages it offers during the migration process itself.

When moving from XP to 7 it is essential to look at the bigger picture. Users are going to have to cope with User Account Control (UAC) prompts as standard users, throwing up time management challenges for users and admins alike. The admins, meanwhile, will need to model which applications are in use and by whom, and which need admin rights and when.

This underlines the way that privilege management can be a powerful tool for understanding what is actually happening on the network as a way of getting more visibility on the security risks. Think of it as a radical rationalization, pulling out old and unused apps, stripping privileges back to a minimum on an application by application basis and smoothing out complexity. Increasingly, this is what migration means on modern networks.

The shift from XP to Windows 7 is hard work but it doesn't have to be a killer. XP can be supported in a locked-down state using the same technology used to manage new Windows 7 or 8 seats. The critical thing is not to waste the potential offered by the end of Windows XP to reform application and user security. This opportunity comes along once in a generation.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • Privilege Guard 2.8 Anti-tamper Protection
    Oct 20, 2017 Privilege Guard 2.8 Anti-tamper Protection
    Blog
    1m
  • From FBI Raid to CTO, Free Mountain Dew, and Hacker and Security Culture: Marc Maiffret’s ModernCTO Conversation
    Mar 28, 2022 From FBI Raid to CTO, Free Mountain Dew, and Hacker and Security Culture: Marc Maiffret’s ModernCTO Conversation
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.