These are the terms you accept when you request administrative access on a KAUST device. Please read them before you submit your request. They apply for as long as you hold administrative access.
Administrative access gives you more control over your KAUST device. It allows you to install software and make system-level changes that are normally restricted.
This access can be necessary for some work, research, teaching, or study activities. However, it also gives you the ability to make changes that could affect the security, stability, or support of your device.
Having the technical ability to make a change does not necessarily mean you are permitted to make it.
The one thing to know before you accept
If a problem is caused by a change you make using administrative access, our ability to troubleshoot it may be limited. In some cases the safest or quickest solution is to reimage the device, which means reinstalling the operating system and returning the device to its standard supported configuration. This is explained in full in term 8 below.
Your administrative access applies only to the KAUST device assigned to you. It is added to your own KAUST account and covers only the device you identify on the request form. It does not apply to any other device.
By accepting administrative access, you agree to use it responsibly and to follow these terms.
These terms sit alongside KAUST's IT and Information Security policies rather than replacing them. Where something is not covered here, those policies still apply. You can read them on the KAUST Policy Site (login required).
Administrative access is added to your existing KAUST account on the device assigned to you.
Use administrative access only when a task actually requires it, such as installing or configuring approved software.
For everyday activities such as email, web browsing, Teams, and other routine work, continue working as you normally would. If a prompt asks for administrative permission and you were not expecting it, decline it.
Working this way helps protect your device if you accidentally open a malicious file, visit an unsafe website, or run harmful software.
Administrative access allows you to install software that would normally be restricted. It does not change which software is allowed on a KAUST device.
Install only software that KAUST IT has approved. Before installing anything, make sure you:
Installing illegal or unlicensed software is strictly prohibited. So is cryptomining software, which uses your device's processing power to generate cryptocurrency, and peer-to-peer (P2P) software, which shares files directly between computers over the internet. The same applies to any other unauthorized software.
Free software still needs to be checked. Contact IT before you install or buy an application, even when it is free. KAUST may already hold a license for it, or there may be an approved alternative that is safer and already supported.
If you are unsure whether software is permitted, check with KAUST IT before installing it.
Your device will continue to be protected and managed by KAUST IT after you receive administrative access.
Do not disable, uninstall, modify, or interfere with any of the following:
Tampering with any of these is strictly prohibited.
Administrative access may give you the technical ability to change or remove some of these protections. It does not give you permission to do so.
Use administrative access only for approved business or academic purposes. Do not use it for personal projects, private work, or anything outside the reason your request was approved for.
You may use IDEs, which are the applications developers write and test code in, along with scripting tools, command-line utilities, development environments, and similar tools, when they are required for an approved purpose.
You are responsible for using these tools securely and in line with KAUST information security policies.
Take particular care when running scripts, commands, or code obtained from the internet or from another person. Administrative access can allow these actions to make significant changes to your device.
Creating additional local standard or administrator accounts on your device is strictly prohibited.
If you have a legitimate need for another account, or for a different account setup, contact IT so the right solution can be reviewed.
Do not install or use unauthorized remote access or remote control software without prior approval from KAUST IT. This is software that lets another person or system take control of your device from somewhere else.
These tools can create serious security risks if they are not properly managed.
If you need remote access for your work, contact IT before you install or configure anything. KAUST already provides approved ways to work remotely. See Remote Network Access (VPN).
You are responsible for software and configuration changes you make using administrative access.
Software you install must be kept up to date with current security patches and configured securely. A security patch is an update released by the software maker to fix a known weakness.
Do not ignore security updates simply because an application continues to work without them.
KAUST IT will still support your device after you receive administrative access.
However, administrative access allows you to make changes that KAUST IT would normally control or prevent. This can sometimes make a problem more difficult to troubleshoot, or leave the device in a configuration that KAUST IT cannot safely support.
If a problem is caused by software or configuration changes made using administrative access, our ability to troubleshoot the issue may be limited.
In some cases, the safest or quickest solution may be to reimage the device. Reimaging means reinstalling the KAUST-managed operating system and returning the device to KAUST's standard, supported configuration.
If something stops working after you make a change, submit a request through Device Repair and Maintenance.
Administrative access is granted for a maximum of one year.
Your access will automatically expire unless the requirement is reviewed and approved again.
This does not mean that administrative access can only be provided once. The review confirms that you still need the access and that it remains appropriate for your work.
You are responsible for keeping track of your own expiry date. KAUST IT does not send a reminder before administrative access ends. If you still need the access when your year is up, submit a new request.
KAUST IT may decline, review, suspend, or remove administrative access if:
Violating these Admin Access Terms and Conditions may be reported to Human Resources or Student Affairs.
Administrative access is intended to give you the flexibility you need while keeping your device, your data, and the wider KAUST environment secure.
You are not expected to be a cybersecurity expert. You are expected to use reasonable care when making changes with administrative access.
If you are unsure whether you should install something, run something, disable something, or change a system setting, contact IT before making the change.
It is much easier for us to answer a question before a change is made than to recover a device afterward.
By accepting this request, you confirm that you have read, understood, and agree to follow these Admin Access Terms and Conditions.
Plain-language definitions for the terms used on this page.
| Term | What it means |
|---|---|
| Administrative access | Also called admin access or admin rights. Permission to install software, change system settings, and adjust security settings on a device. It is added to your own KAUST account and applies only to the device you were approved for. |
| Antivirus software | Software that detects and removes viruses and other malicious programs. |
| Cryptomining software | Software that uses a device's processing power to generate cryptocurrency. It is not permitted on KAUST devices. |
| Device firewall | A control built into your device that decides what is allowed to connect to it and what it is allowed to connect to. |
| Endpoint detection and response (EDR) | Security software that watches for suspicious activity on a device and alerts Information Security so it can be investigated. |
| IDE | Integrated development environment. The kind of application developers use to write, run, and test code. |
| KAUST IT-managed device | A laptop, desktop, or workstation issued by KAUST and managed by KAUST IT. Personal devices are not KAUST IT-managed. |
| Peer-to-peer (P2P) software | Software that shares files directly between computers over the internet. It is not permitted on KAUST devices. |
| Reimage | Reinstalling the KAUST-managed operating system on a device and returning it to KAUST's standard, supported configuration. Anything not backed up beforehand is lost. |
| Remote access software | Software that lets another person or system take control of a device from somewhere else. It needs approval from KAUST IT before it is installed or used. |
| Security patch | An update released by a software maker to fix a known weakness. Installing patches promptly is one of the most effective ways to keep a device secure. |
Admin Rights at KAUST
How admin access works, who can request it, and how to submit a request
Installing Software on Your KAUST Device
Install approved software yourself, without admin access
Third-party Application Security
Approved plugins, add-ins, and app whitelisting process
Antivirus at KAUST
Endpoint protection on all KAUST-managed devices
KAUST Policy Site
IT and Information Security policies and procedures (login required)