Blog › Article
Admin rights and user access control in practice
User access control is the control most small organisations think they have covered, because everyone has their own login. The requirement goes further: the right access, and no more, for the right people, for as long as they need it.
What the control asks for
- A process for creating and approving accounts, and for removing them when people leave or change role.
- People have only the access their job needs.
- Administrator accounts are separate from everyday accounts and used only for administration.
- Accounts that aren't used any more are removed or disabled.
- MFA on cloud services that offer it, for administrators and for users — an automatic-fail requirement.
Where it goes wrong
Everyone is a local admin
In many small estates, every user is an administrator on their own machine, usually because it was the quickest way to let someone install software once. It means any malware a user runs has full control of the machine.
Admin accounts used for everything
The IT lead reads email and browses on the same account that can change every system. One phishing link is then an administrator compromise.
Admin rights that never came back
Granted temporarily for a task, then forgotten. The number of administrators on a machine tends only to go up.
Shared local admin passwords
The same local administrator password on every machine, set once at build and never changed. One compromised machine gives the same access to all of them.
Leavers still active
An account left enabled after someone leaves, often with the permissions they had on their last day.
Access control is about what changes, not what was set up. Joiners, leavers and temporary exceptions all change who can do what. The control holds only if those changes are made, and reversed, as they happen.
Making it work
- Separate admin accounts. Give administrators a second account for admin work and use their normal account for everything else.
- Remove local admin from users. Provide a way to install approved software without handing out admin rights permanently.
- Unique local admin passwords. Tools such as Windows LAPS rotate a different local administrator password on each machine automatically.
- A leavers checklist. Disable the account on the day, remove it from cloud services, and recover shared credentials.
- Review regularly. Check who is a local administrator on each machine, and why, rather than assuming it hasn't changed.
Quick answers
Can users be local administrators under Cyber Essentials?
Only where their job genuinely needs it, and administrator rights should be used only for administration, not for day-to-day work.
Do admins need a separate account?
Administrator accounts should be used only for admin tasks, so in practice administrators need a separate everyday account for email and browsing.
Is MFA required for all users?
On cloud services that offer MFA, yes, for users and administrators. Missing it is an automatic fail.