Bring all engineers with privileged access to other systems into a consistent, auditable security posture — managed endpoints, consistent EDR, least-privilege local admin, and zero-trust network access.
A cybersecurity policy change requires a list of local admin exceptions within ~2 weeks. Beyond that immediate deliverable, the current state is inconsistent: CrowdStrike deployment to workstations is uneven, there is no Engineering-managed endpoint management for Mac, SSLVPN is still the primary remote access method, and local admin is granted broadly. This plan consolidates those gaps into a single initiative driven by ET Engineering Directors.
Audit current local admin grants across in-scope engineers
Resolve exception approval authority (Engineering Directors, Security, or both)
Categorize each engineer as standing exception (essential to job function) vs. temporary/JIT-eligible
Submit local admin exception list to cybersecurity with per-user business justification, named approval authority, and 6-month review cadence — complete
Decide Mac endpoint management approach
Evaluate JIT elevation tooling for both Mac and Windows
Which remaining Phase 0 items are complete? The exception list was submitted, but the standing of the other Phase 0 deliverables — approval authority resolution, standing vs. JIT categorization, Mac endpoint management decision, and JIT tooling evaluation — is unconfirmed. Status stays draft until they are.
What JIT elevation mechanism will be used for Windows?
What JIT elevation mechanism will be used for Mac? (Privileges.app, JAMF Connect, other?)
Will Engineering get a dedicated JAMF instance or a scoped partition of the enterprise instance?
About the Cloudflare One Client — the client formerly called WARP; reports OS version, disk encryption status, and installed-application presence for posture evaluation
Aligned local admin exception process with Access Control Standard: per-user justification, approval authority as Phase 0 deliverable, standing vs. JIT categorization, 6-month review cadence
2026-07-24
draft
Review pass: marked the local admin exception list as submitted; added an open question covering the four unconfirmed Phase 0 deliverables that keep this plan in draft; corrected WARP to its current name, Cloudflare One Client; added References; corrected created to the first changelog date