Admin access on KAUST devices is restricted by default. You can request it, and it is granted when your role or your work genuinely requires it. This page explains how admin access works, who can request it, what you agree to, and how to submit a request.
Admin access gives you additional control over your KAUST device. With it, you can install software, change system settings, and adjust security settings.
Most people do not need it. KAUST IT grants only the access a role or task genuinely requires. This keeps every device more secure.
Admin access is added to your own KAUST account and applies only to the device you name on the request form. It does not apply to any other device.
These rules apply to every KAUST IT-managed device, including Windows, macOS, and Linux. They do not apply to personal devices. A personal device includes any BYOD, which stands for bring your own device. A BYOD is a laptop, tablet, or phone that you own yourself and use for work or study. KAUST IT does not manage personal devices and does not grant admin access on them.
For details on KAUST IT-managed device services and support, see KAUST IT Managed Devices.
Admin permission prompts on KAUST devices
On Windows and macOS, a prompt appears when an application needs additional permissions. On Linux, you run those commands in the terminal using sudo, a command that runs a single task with administrative permissions.
Windows

macOS

You do not need admin access to install software on a KAUST-managed device.
Self-Service Library
Windows and macOS
Approved software is available to install directly on your device. You do not need IT support and you do not need admin access.
Software Center
Windows
Self Service+
macOS
See Installing Software on Your KAUST Device for a full walkthrough, or browse the Software Catalog to see what is available.
Linux Devices
Ubuntu
Software Center and Self Service+ are not available on Linux. To install software on a KAUST-managed Linux device, submit a request through Software Support Services.
Requesting software
If the software you need is not in the self-service library, submit a request through Software Support Services. This applies to every platform, including Linux.
Contact IT before you install or buy an application, even when it is free. KAUST may already hold a license for it, or there may be an approved alternative that is safer and already supported.
Some applications need an Architecture Review and a Secure by Design assessment before they can be provided. These are security and compatibility checks that KAUST IT carries out before new software is approved. Allow additional time for these requests.
Third-party and add-in applications
Requesting admin access in order to install a blocked or unapproved third-party application is not the correct route. These requests follow a separate approval and whitelisting process. See Third-party Application Security for details.
Personal and BYOD devices: This process covers KAUST IT-managed devices only. KAUST IT does not manage or grant admin access on personal devices.
Admin access is available to the following groups when there is a clear and documented need.
| Who can request | What qualifies you |
|---|---|
| Faculty, staff, and researchers | Your role involves managing lab equipment, shared systems, or a specific assigned workstation. You also have a clear operational reason to need admin access. |
| Contractors (CWF) | You have been assigned a KAUST IT-managed device. Your contract or scope of work carries a documented technical requirement. |
| Students | You have been assigned a KAUST IT-managed device and have a clear technical or research requirement. Requests based on role alone, with no technical reason, are reviewed as exceptions. |
| Advanced or development work | Reviewed individually where no standard option applies. KAUST IT may offer a managed or centralized environment instead. |
High-risk scenarios
Some situations always require review by Information Security. This applies whatever type of access you request.
| Scenario | Why it is high-risk |
|---|---|
| High-privilege accounts | Attackers target people who already hold elevated roles. Phishing and privilege escalation are the most common methods. |
| Restricted research or high-value assets | Devices that hold or reach restricted data require tighter controls. This includes devices linked to export-controlled hardware or research. See also GPU and Export Controlled Components. |
| Shared workstations | When more than one person uses a device, there are more ways for an attacker to gain access. There is also a greater chance that an attack spreads across the network. |
Every request falls into one of three types. The type determines whether access is granted, what kind you receive, and how long it lasts.
| Type | What it means | Decision | What happens |
|---|---|---|---|
| One-time software installation | You need a single application installed, and you do not require admin access afterward. | Request declined | KAUST IT installs the application for you, either remotely or in person. No admin access is granted. |
| Complex or multi-step installation | The setup changes system settings, involves several steps, or requires admin access throughout the process. | Temporary access | Access is granted for a short, defined window. KAUST IT confirms the dates when your request is approved. Access is removed automatically when the window ends. To extend it, submit a new request with an updated reason. |
| Ongoing specialized or scientific use | Your work requires admin access continuously. This covers specialized, custom, or scientific applications that must run with additional permissions, or that interact with drivers, kernels, or other low-level settings. It also covers roles with a clear, documented technical need. | Extended access | A detailed technical reason is required. Information Security must review and approve the request. Access lasts up to one year. |
All admin access expires
Admin access is granted for a maximum of one year and is removed automatically unless it is reviewed and approved again. Access can be granted more than once. The review confirms that you still need it and that it still suits your work.
You are responsible for keeping track of your own expiry date. KAUST IT does not send a reminder before admin access ends. If you still need the access when your year is up, submit a new request.
Before admin access is granted, you must accept the Admin Access Terms and Conditions. They explain how admin access is intended to be used and what you are responsible for. They sit alongside KAUST's IT and Information Security policies rather than replacing them.
The ten terms are listed below. Please read the full text before you submit your request.
1. Use administrative access only when a task requires it
2. Think before you install software
3. Keep KAUST security and management tools running
4. Use administrative access only for approved purposes
5. Do not create additional accounts
6. Remote access tools require approval
7. Keep the software you install secure and up to date
8. Understand what happens if something goes wrong
9. Administrative access lasts for up to one year
10. Administrative access can be reviewed or removed
Read the Admin Access Terms and Conditions
Complete the Admin Access Rights form online. It covers KAUST IT-managed Windows, macOS, and Linux devices. Your requestor details are filled in automatically, and your request is routed based on the type of access you need.
Signing in
Enter your KAUST email address to begin. For example, Naif Alqahtani would enter naif.alqahtani@kaust.edu.sa.
You are then taken to the KAUST sign-in page, where you enter your KAUST username and password. Your username is not the same as your email address. Naif would sign in with the username alqahtnd.
Complete a separate form for each device. If you are not certain that you need admin access, read Getting Software on a KAUST Device above first, because most software does not require it.
The request form
| Field | What to enter |
|---|---|
| Are you the custodian? | Select Yes if the device is assigned to you. Select No if you are requesting for a shared device, or on behalf of someone else. Yes is selected by default. |
| Justification (required) | Explain the exact task, role, or system that requires admin access. Name the application, the workflow, or the technical requirement. Vague answers take longer to review and may be declined. |
| Tag# (required) | Select your device from the list. The tag number is printed on a label attached to the device. Admin access applies only to the device you select here. If your device is not listed, contact IT before you complete the form. |
| Operating System (required) | Select the system running on the device: Windows, macOS, or Linux. See Operating Systems at KAUST if you need to check your version. |
| Terms and Conditions | You must check this box before the form can be submitted. It confirms that you have read and agree to the Admin Access Terms and Conditions. Read the full text before you submit. |
Approval workflow
Your request is reviewed in the following order. Not every step applies to every request.
Step 1: every request
Asset custodian
The person responsible for the device record. They review your reason and confirm that it is valid.
Step 2: every request
KAUST IT
Reviews technical feasibility and compliance with KAUST standards.
Step 3: extended and high-risk
Information Security
Approves extended access, high-risk cases, and exceptions.
Access is provided through central identity management and applies only to the device you were approved for. No local administrator accounts are created on your device.
Information Security logs and monitors all admin access activity on KAUST-managed devices. KAUST IT may remove your access at any time if you do not follow the terms, if the access is used for activities that were not approved, if it creates an unacceptable security risk, or if you no longer need it. All access is removed automatically when its approved period ends.
Security and management tools remain active
Every KAUST-managed device runs antivirus software, endpoint detection and response (EDR) software that watches for suspicious activity, a device firewall that controls what can connect to and from your device, and KAUST IT management tools.
Admin access may give you the technical ability to change or remove some of these protections. It does not give you permission to do so. Any attempt to disable, uninstall, modify, or interfere with them is flagged for review.
If something goes wrong
KAUST IT continues to support your device after admin access is granted. However, admin access allows you to make changes that KAUST IT would normally control or prevent. That can make a problem harder to diagnose. It can also leave the device in a configuration that KAUST IT cannot safely support.
Where a problem is caused by a change made using admin access, there may be less that KAUST IT can do to resolve it. In some cases the safest and fastest option is to reimage the device. Reimaging means reinstalling the KAUST-managed operating system and returning the device to its standard supported configuration.
Your accountability
You are responsible for every action carried out under admin access on your device. Misuse may result in immediate removal of access. It may also be reported to Human Resources or Student Affairs where appropriate.
KAUST Policy Site (login required)
Can I install software without admin access?
Yes. On Windows, use Software Center. On macOS, use Self Service+. On Linux, or for anything not available in self-service, submit a request through Software Support Services and KAUST IT will install it for you.
Is temporary admin access available?
Yes. It is available for a complex or multi-step installation. It runs for a short, defined window, and KAUST IT confirms the dates when your request is approved. Access is removed automatically when the window ends. To extend it, submit a new request before your current access ends.
Does admin access expire?
Yes. All admin access is granted for a maximum of one year and is then removed automatically. Access can be granted again, but the reason must be reviewed and approved before your current access ends. You are responsible for keeping track of your own expiry date, because KAUST IT does not send a reminder. Temporary access for a single installation ends much sooner.
Who approves extended admin access?
Information Security. The asset custodian and KAUST IT review the request first. A detailed technical reason is always required, and the access still lasts one year at most.
Where can I read the terms I am agreeing to?
The Admin Access Terms and Conditions page publishes the full text. You accept these terms on the request form, and they apply for as long as you hold admin access.
How long does a request take to process?
It depends on the type of request and the number of approvals required. A clear, specific reason reduces review time considerably. Contact the IT Service Center for an update on a request you have already submitted.
What if my request is declined?
KAUST IT will advise you on the alternatives available. If you would like the decision reviewed again, contact IT with further detail on why you need the access.
What happens if something breaks after I make a change?
Submit a request through Device Repair and Maintenance. KAUST IT continues to support your device. If the problem was caused by a change you made using admin access, it may take longer to resolve. In some cases, reimaging the device is the fastest safe route back to a working configuration.
Does this apply to my personal device?
No. This process covers KAUST IT-managed devices only. KAUST IT does not manage or grant admin access on personal or BYOD devices.
Why is admin access restricted on KAUST devices?
Unrestricted admin access makes it far easier to change something by accident, install malware, or lose data. KAUST IT limits access on every managed device to protect your work and the wider KAUST environment.
Admin Access Terms and Conditions
What you agree to when admin access is granted
KAUST IT Managed Devices
Device services, support coverage, and security compliance
Installing Software on Your KAUST Device
Self Service+ and Software Center guide for Windows and macOS
Software Catalog
Browse KAUST-licensed and approved software
Operating Systems at KAUST
Supported OS versions and lifecycle status
Third-party Application Security
Approved plugins, add-ins, and app whitelisting process
GPU and Export Controlled Components
Procurement approval for export-regulated hardware
Antivirus at KAUST
Endpoint protection on all KAUST-managed devices
KAUST Policy Site
IT and Information Security policies and procedures (login required)