Sound Networks IT Support
Sound Networks IT Services
IT Support
Managed IT Services
Cyber Security
AI
Insights
Company

Request free IT audit

This site uses cookies for functionality and analytics Manage Close

Why employees shouldn't have administrator access

Administrator access can make installing software and changing settings easier, but leaving it enabled permanently creates unnecessary security risks. For everyday work, employees should use a standard account, with administrator access reserved for approved IT tasks.

What administrator access allows

An administrator has significantly more control over a computer and may be able to:

  • Install or remove software and drivers
  • Change system settings and permissions
  • Create or remove user accounts
  • Install background services
  • Change certain security settings

Microsoft and Apple both recommend limiting the number of users with administrator privileges. It's also important to distinguish local administrator access from Microsoft 365, Google Workspace, network or server administrator accounts. These should all be reviewed separately.

Why permanent administrator access is risky

Software normally runs with the permissions of the person who launches it. If that person has administrator rights, a malicious or compromised program may be able to make changes across the computer. For example, an employee could unknowingly approve a fake software update or malicious attachment. With administrator access, the program may then be able to install components, change settings or access other users' data.

Additional Protection

A standard account provides an additional layer of protection. When administrator approval is required, IT can review the request before entering the required credentials.

How employees can work without administrator access

Standard accounts are suitable for most everyday tasks, including:

  • Email and web browsing
  • Microsoft 365 and Google Workspace
  • Approved business applications
  • Online meetings
  • Printing
  • Opening and saving files

If software requires administrator approval, IT can install it remotely, use managed software deployment or approve the individual request. Employees who genuinely need administrator privileges can use a separate administrator account, rather than having administrator rights on their everyday account.

Who should have administrator access?

Administrator access should be limited to people who genuinely need it, such as:

  • Internal IT staff
  • Your IT provider
  • Approved technical employees
  • Specialists responsible for specific systems

Business owners should also use standard accounts for everyday work. Avoid using the same administrator password across multiple computers. If that password is compromised, an attacker could potentially use it to access other devices. Each computer should have a unique administrator password or use a password management system.

How to remove administrator access safely

Before removing privileges:

  • Check who has administrator access on each computer.
  • Confirm why they need it and whether there is a genuine business requirement.
  • Make sure IT has a separate, protected administrator account.
  • Test important software to ensure it works with a standard account.
  • Change employees to standard accounts once checks are complete.
  • Give staff a clear process for requesting software installations or changes.
  • Review access regularly, particularly when employees change roles or leave.

Don't simply remove every administrator account. Make sure there is always a secure way for IT to manage and recover each device.

Frequently Asked Questions

Can standard users install software?

Sometimes. Software that installs within a user's profile may not require administrator approval. Applications that install drivers, services or protected system files normally will.

Will removing administrator access stop employees working?

Normal business applications should continue to work. Specialist or older software should be tested before making the change.

Does removing administrator access stop malware?

No, but it can limit what malware is able to change. It should be combined with security updates, endpoint protection, email security, MFA and tested backups.

Should business owners have administrator access?

For everyday work, use a standard account. If administrator access is required, use a separate account and keep its credentials protected.

Is local administrator access the same as Microsoft 365 administrator access?

No. Local administrator access controls an individual computer, while Microsoft 365 administrator roles can control cloud users, email, files and security settings. Both should be limited and regularly reviewed.

Need help reviewing administrator access?

If you're unsure who has administrator access across your business or whether employees actually need it, your IT provider can review the accounts and help reduce unnecessary privileges.

Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Need Help?