Administrator access can make installing software and changing settings easier, but leaving it enabled permanently creates unnecessary security risks. For everyday work, employees should use a standard account, with administrator access reserved for approved IT tasks.
An administrator has significantly more control over a computer and may be able to:
Microsoft and Apple both recommend limiting the number of users with administrator privileges. It's also important to distinguish local administrator access from Microsoft 365, Google Workspace, network or server administrator accounts. These should all be reviewed separately.
Software normally runs with the permissions of the person who launches it. If that person has administrator rights, a malicious or compromised program may be able to make changes across the computer. For example, an employee could unknowingly approve a fake software update or malicious attachment. With administrator access, the program may then be able to install components, change settings or access other users' data.
A standard account provides an additional layer of protection. When administrator approval is required, IT can review the request before entering the required credentials.
If software requires administrator approval, IT can install it remotely, use managed software deployment or approve the individual request. Employees who genuinely need administrator privileges can use a separate administrator account, rather than having administrator rights on their everyday account.
Administrator access should be limited to people who genuinely need it, such as:
Business owners should also use standard accounts for everyday work. Avoid using the same administrator password across multiple computers. If that password is compromised, an attacker could potentially use it to access other devices. Each computer should have a unique administrator password or use a password management system.
Before removing privileges:
Don't simply remove every administrator account. Make sure there is always a secure way for IT to manage and recover each device.
Sometimes. Software that installs within a user's profile may not require administrator approval. Applications that install drivers, services or protected system files normally will.
Normal business applications should continue to work. Specialist or older software should be tested before making the change.
No, but it can limit what malware is able to change. It should be combined with security updates, endpoint protection, email security, MFA and tested backups.
For everyday work, use a standard account. If administrator access is required, use a separate account and keep its credentials protected.
No. Local administrator access controls an individual computer, while Microsoft 365 administrator roles can control cloud users, email, files and security settings. Both should be limited and regularly reviewed.
If you're unsure who has administrator access across your business or whether employees actually need it, your IT provider can review the accounts and help reduce unnecessary privileges.

























