How American Interiors Removed Widespread Local Admin Rights
American Interiors faced a substantial security risk and were challenged in how best to address it. Niche software required local admin rights which meant changes could be made, including removing security tools whether intentionally or accidentally. It wasn’t until Rob Whitten came across ThreatLocker on the highway (really!) that he was able to solve the problem and remove one of the biggest risks to the company. In this interview Whitten talks about what his concerns were and why ThreatLocker solved that challenge and more.
Questions have been shortened. Answers are selected transcript excerpts, lightly edited to remove filler and repetition. Watch the full interview at the bottom of this article.
Why American Interiors Needed to Remove Admin Rights
Can you give us some background on yourself and American Interiors?
Rob Whitten: My name is Robert Whitten and I am the IT Director at American Interiors. We are a furniture dealer and interior solutions provider. I have been in IT for 20 plus years.
What challenges were you facing before working with ThreatLocker?
Rob Whitten: I started working here about roughly 13 years ago as a consultant. I worked for a third-party MSP and the first thing we were warned about was that everyone had local admin rights. If you know anything about cybersecurity, that's number one giant red flag; if you have admin rights on your system, you can do anything you want, including things you don't intend to.
That was a big issue, and we were also told by the software vendors that it's a very niche software that requires admin rights and there's nothing you can do about it; that's just the way it is. It was a massive headache, and every time we turned around, we were troubleshooting issues with someone doing things they shouldn't be doing.
I started down the path of trying to figure out how to make the software work with removing admin rights, assigning folder permissions, doing all the basic things you should do, and every time it would come up that the people can't work, because you can't do updates, they can't get the software to function, and IT would have to intervene and install the updates, or do things on the software which didn't make sense.
We tried our best trying to work around it, butwe had to give people admin rights. And people don't pay attention to UAC. As soon as UAC pops up, they go," yes, I want to continue working." They didn't care what's installing. "If I hit yes, I continue working, and everything's great."...Until it's not great.
Evaluating and Deploying ThreatLocker at American Interiors
How did you learn about ThreatLocker?
Rob Whitten: Our company moved into the Florida market in roughly 2020 during the height of COVID. And I just happened to be down there. We were trying out some other software and we were still dealing with giving admin rights to people. And were getting ready to onboard about,30-some new hires.
I was driving from Orlando to Tampa on I-4, and I saw a billboard for this company called ThreatLocker. I ended up doing some quick Googling, because I was curious what ThreatLocker could be.
At the time we were doing a proof of concept with another company and decided to reach out to ThreatLocker and see what they could do. I've never heard of them before, but hey, why not? Sometimes things come to you in the strangest hours.
What happened next, and how did you decide to work with them?
Rob Whitten: I ended up reaching out and speaking to a rep and he also put me in contact with one of the developers. We ended up going back and forth, and he set me up on a trial, and I was doing a proof of concept with one company and decided to also do proof of concept with ThreatLocker.
When I was going through the proof of concept with ThreatLocker, it was working very well. Oddly enough, I was actually a bit concerned, their UI and their settings are so simplistic. They made the UI seem so basic that you don't realize how advanced it really is, and what it can really do.
We had a security incident that happen in one of our offices. My team responded so quickly, but we had an employee who lost about a day's worth of work because of the incident. It was an incident that could have been avoided by not having local admin rights. Since my team responded so quickly, it could have been much worse.
I then took what happened and ran a proof of concept on the other vendor that we were looking at before I ran across ThreatLocker. It didn't stop it. Then I ran it on ThreatLocker; it was like it never even existed. Nothing changed. It blocked the file, it was like the file never existed!
I ended up making a phone call that day to the owner of our company and stating that if we would have rolled out the proof of concept the day before, this wouldn't have happened.
The nice thing is, the way leadership is at this company they invest in technology. He knew where I was coming from, he knew what I was talking about. I showed him the proof of concept and said, "Look, see what happened? It doesn't even exist. It's like, it never even happened. We could have saved hours of time, could have saved a day of work, could have saved a lot of things."
Without that incident, would you have had the same leadership support?
Rob Whitten: Honestly, yes. It would have been a little bit longer, but the nice thing is, I'd been barking up this tree since I started with this company about local admin rights from the time I was a consultant. Probably every 6 months, I was bringing it up. "It's a problem, it's a red line, we need to take care of it." Everyone knew it, leadership all knew it' it wasn't anything that was out of the ordinary.
Up to this point, every proof of concept I've done had always had some kind of compromise, some kind of issue, something you have to trade off. And ThreatLocker didn't have that compromise. It does have a compromise in a way, but it's not the compromises of other methods.
If you want to remove admin access from most people, then you have to rely on IT tickets, help desk people to do things for you, use privilege accounts to escalate things. With ThreatLocker you can write policies, and the problem is solved before it's even begun.
If you want to have a policy on how someone can update their software, you write the policy, and it just applies when they go to update it. It's this automatic elevation. The trade-off for time isn't really there until you run across the unknown. When you run across the unknown, though, ThreatLocker makes it so easy to write a policy that you can deploy a policy to the whole organization within 5 minutes.
What was the implementation like?
Rob Whitten: I expected a big, big thing because it's a big software. It touches everything in the system. It was deployed within 24 hours.
We have an RMM, so we leveraged that to install the application. We also used the RMM to run scripts to remove admin rights, local admin rights from everybody. And then we let ThreatLocker build the basic generic policies using its learning mode and then we went in and tailored those policies down, and hit the secure button, and that was it!
When people go to install their software, instead of being able to hit yes, and away they go, they get greeted with a ThreatLocker prompt that says "request" instead of "yes." From a change management perspective, it didn't really change that much, because it's still the same area, same prompt, just a different button.
How American Interiors Uses ThreatLocker Today
You've had it in place for six or seven years now?
Rob Whitten: We're going on 7 years now. I can't think of how bad it would be if it wasn't deployed at this point. This year alone, we have hired about 25% of the company. From that kind of growth and being able to manage that from an IT standpoint, if we had to manage local admins for every single person, that would be a nightmare.
Have there been significant changes to the platform and how you use it?
Rob Whitten: There has been some changes, but from a standpoint for basic functionality, not really. I did learn quite a bit about how ThreatLocker works. We deployed it, and we got it for one single feature, which was the whole privilege escalation thing.
But after we deployed it, we discovered it could do much more and we discovered a lot more features of it that we didn't see in the proof of concept, because we weren't focused on that. We were focused on one thing and one thing only, the big red flag. But afterwards, we discovered it can block network, it can actually control what systems can talk to.
How would you explain your use of ThreatLocker and its benefits today?
Rob Whitten: Whenever someone has an issue, someone has something going on, the first place I go is ThreatLocker. It's changed my methodology of troubleshooting, and the reason is because the unified logging system is so good at logging every single thing on a system that it tells me more in a single place than Windows Event Viewer does.
That's not what we deployed it for, we didn't even think about that being a thing back then.
ThreatLocker University is very well documented, really well rolled out, and it took me a year to go on there and learn about it. And then I started unlocking more features of ThreatLocker and going, "wow, I didn't know it could do that."
If we had a user lose a file on a file system somewhere. "Where were you last saving that file?" I no longer have to ask them that question anymore. I just go to the unified log; it's logged everywhere they touch that file at and I can tell them exactly where they saved the file at.
Is there anything we haven't covered that you'd like to share?
Rob Whitten: You have to talk to your account manager. With ThreatLocker, whenever you're talking to the account manager, he or she is going to come across some little new tidbit of something coming out. And then you check it out, and you're like, "wow, that's actually really kind of cool. Why isn't there a big publication about this?" Normally, there's not.
They have a whole beta portal you can log into and you can just check out all the new features, and they're constantly working on stuff.
I've only ever put in a few tickets with ThreatLocker. Their response time has been amazing, to the point where I didn't understand how they did it. I understand how they do it now, because they have so many people who are standing by, waiting to talk to somebody.
Watch the full interview between Dorene Rettas and Rob Whitten below:

