New Site
(limehawk.io)
LIMEHAWK - Managed IT

Locked Out of Client PC: Emergency Local Admin via RMM

Home>Incident Reports>Locked Out of Client PC: Emergency Local Admin via RMM
Endpoints
92
Security incident
Assessment
Why we couldn't just reset the domain admin
Resolution
Technical details
Outcome
Key takeaways
Takeaway
RMM running as SYSTEM is break-glass access for when the domain itself is compromised — it's the one thing an insider can't easily reach if they're not in your RMM tenant.
Takeaway
we now deploy this script as part of every client onboarding, so a break-glass local admin exists on every endpoint from day one.
Takeaway
unique passwords per machine stop lateral movement cold — one compromise is one machine, not the whole fleet.
Takeaway
insider threats can't disable what they don't control; keep your management plane outside the client's identity provider.

Need help with something like this? Contact us

Related