Giving employees administrator access can seem like the easiest way to get things done. It can also create a significant security risk for your business.

It often starts innocently enough.

An employee needs to install a printer, update a specialist application or change a setting on their computer. IT gives them administrator access so the job can be completed quickly.

The problem?

That access often stays in place long after the original task is finished.

From that point on, the employee can install software, change important system settings and make other changes that would normally require IT approval.

If their account is compromised, those same permissions could potentially be used by an attacker.

That is why, as a general rule, employees should use standard accounts for their day-to-day work, with administrator access restricted to those who genuinely need it.

What does administrator access actually allow?

An administrator has significantly more control over a computer than a standard user.

Depending on how the device is configured and managed, administrator access can allow someone to:

  • Install and remove software
  • Install printer and hardware drivers
  • Create, change or remove user accounts
  • Change system settings
  • Change permissions on files and folders
  • Install background services
  • Change certain security settings

On Windows, users who are members of the local Administrators group have extensive control over that computer. Microsoft recommends limiting the number of users with this level of access.

The same principle applies to Mac computers, where administrator accounts can install software, manage users and change system settings.

Local administrator isn’t the same as Microsoft 365 administrator

It’s also important to understand that local administrator access and Microsoft 365 administrator access are different things.

Local administrator access gives someone control over a particular computer.

Microsoft 365 administrator roles can provide access to areas such as users, email, files, security settings and other parts of your cloud environment.

Both types of access should be carefully controlled and regularly reviewed.

Why permanent administrator access increases your risk

The biggest problem with administrator access isn’t necessarily the employee themselves.

It’s what happens if something they run is malicious or compromised.

Imagine an employee receives an email containing what appears to be a legitimate software update. They download it and, when Windows asks for administrator approval, they click Yes.

The software may now have permission to make changes to the computer that a standard user wouldn’t normally be able to make.

The same risk can apply when someone downloads a fake installer, visits a compromised website or installs software from an untrusted source.

Administrator access can therefore turn a relatively small security incident into something much more serious.

Standard accounts add an important layer of protection

With a standard user account, an employee can still carry out the vast majority of their normal work.

They can:

  • Send and receive email
  • Browse the internet
  • Use Microsoft 365 or Google Workspace
  • Access approved business applications
  • Join Teams and other online meetings
  • Print
  • Open and save files
  • Change personal settings

But when something requires administrator privileges, IT gets involved.

That creates an opportunity to check what is being installed, where it came from and whether it is actually required.

Microsoft describes using a standard account as the recommended and more secure way to use Windows.

“But my staff need to install software”

This is one of the most common reasons businesses give employees administrator access.

And it’s understandable.

People need to get their jobs done.

But giving everyone permanent administrator rights isn’t the only solution.

There are several better approaches.

1. Let IT install approved software

An employee can raise a request with IT, who can install the application remotely or provide the required administrator approval.

This also gives IT the opportunity to verify that the software is legitimate and supported.

2. Use managed software deployment

For businesses with managed devices, approved applications and updates can often be deployed centrally.

This removes the need for employees to install software themselves and makes it easier for IT to maintain consistent software across the business.

3. Approve individual installations

If an employee needs a particular application, IT can review the request and provide the necessary administrator credentials without giving the employee the administrator password.

4. Use separate administrator accounts

For employees who genuinely need administrator access as part of their role, consider giving them a separate administrator account.

Their normal account remains a standard account for email, browsing and everyday work.

The administrator account is only used when the additional permissions are actually required.

Who should have administrator access?

Administrator access should be limited to people who genuinely need it.

That might include:

  • Internal IT staff
  • Your managed IT provider
  • Approved technical employees
  • Software specialists responsible for particular systems

And yes, that includes business owners and directors.

Being the owner of the company doesn’t mean you need administrator rights on every computer.

In fact, business owners are often high-value targets for attackers, making strong access controls particularly important.

Don’t forget administrator passwords

There’s another important consideration.

Never use the same local administrator password across every computer.

If an attacker obtains that password from one device, they may be able to use it to access others.

Each computer should have a unique administrator password, ideally managed through an appropriate password or device-management solution.

How to remove administrator access safely

If your business currently gives employees administrator access, don’t simply remove everyone’s permissions overnight.

You need to understand what is currently being used and make sure IT retains a secure way to manage every device.

A sensible process is:

1. Find out who has administrator access

Review the administrator accounts on your Windows PCs and Macs.

Don’t forget old employee accounts, shared accounts and accounts created during the original setup.

2. Understand why they have it

For every employee with administrator access, ask:

“What do you actually need this permission for?”

Needing to install an application once every few months isn’t necessarily a good reason for permanent administrator access.

3. Make sure IT still has access

Before removing permissions, make sure your internal IT team or IT provider has a secure administrator account that works on each device.

4. Test your applications

Some older or poorly designed applications may have been built expecting administrator permissions.

Test important business applications using a standard user account before making the change across the business.

5. Remove unnecessary permissions

Once everything has been checked, remove employees from the local Administrators group or change their account to a standard user.

6. Give employees a simple way to request help

Make sure staff know who to contact when they need software installed or a system setting changed.

The objective isn’t to make people’s jobs harder.

It’s to put a sensible control around changes that could affect the security of your business.

Does removing administrator access stop malware?

No.

And it’s important not to treat it as a complete security solution.

Removing unnecessary administrator access reduces what many malicious programs can change, but it doesn’t prevent every type of cyber attack.

Your business should still have appropriate:

  • Endpoint protection
  • Security updates and patching
  • Email security
  • Multi-factor authentication
  • Secure backups
  • Access controls
  • Security awareness training

Administrator access is simply one important layer in a broader security strategy.

The bottom line

If everyone in your business has administrator access, it’s worth asking whether they really need it.

For most employees, the answer will be no.

Using standard accounts for everyday work and restricting administrator privileges to those who genuinely need them can reduce the potential impact of malware, compromised accounts and accidental changes.

And you don’t have to work this out on your own.

Netserve can review the administrator access across your business, identify unnecessary permissions and help you put a safer approach in place, without making life harder for your employees.

If you’re not sure who currently has administrator access to your business computers, get in touch with the Netserve team and we’ll help you review it.