Cloud Security Stack
Tools and buyer guides

Tools

Privileged access workstations: worth it or theatre?

A dedicated hardened device for administrative work. When it genuinely reduces risk, and when it becomes an expensive laptop nobody uses.

10 min read · Reviewed 22 August 2026 · Criteria published. Written from deployment work.

The problem it solves

An administrator reads email, browses the web and holds Global Administrator on the same machine. If that machine is compromised through any ordinary route, the attacker inherits the administrative session.

A privileged access workstation breaks that link: administration happens on a device that does not do email or general browsing, so the ordinary compromise routes do not reach it.

Why they fail

Because carrying two laptops is genuinely annoying, and because the moment one urgent task cannot be done on the hardened device, someone does it on the normal one. Within a few months the control exists on paper and not in practice.

The failure is never technical. It is that the design ignored how the work actually happens.

What makes one actually get used

01

Scope it to a genuinely small group

The handful of people who hold tier zero privilege. Extending it to everyone with any admin role is how the programme collapses.

02

Make it the only way to reach the admin portals

Conditional Access requiring a specific device filter for administrative roles. If the normal laptop still works, the hardened one will not be used.

03

Solve the awkward cases before rollout

Teams calls, the ticketing system, documentation. If the admin has to switch devices mid-incident, the design has failed.

04

Consider a cloud PC instead of hardware

A dedicated Cloud PC reached only from a compliant device gives most of the isolation without a second laptop to carry. Cheaper, and far more likely to survive.

The verdict

Our pick

Yes for tier zero, and use a Cloud PC rather than a second laptop

It preserves the isolation that makes the control work while removing the reason people abandon it.

Who should skip

Skip it entirely if you have not yet removed standing privilege. Privileged Identity Management is cheaper, faster, and reduces more risk than hardening the device that holds permanent access.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.