Monitor

Blog › Article

6 October 2026 · Article

Admin rights and user access control in practice

User access control is the control most small organisations think they have covered, because everyone has their own login. The requirement goes further: the right access, and no more, for the right people, for as long as they need it.

What the control asks for

Where it goes wrong

Everyone is a local admin

In many small estates, every user is an administrator on their own machine, usually because it was the quickest way to let someone install software once. It means any malware a user runs has full control of the machine.

Admin accounts used for everything

The IT lead reads email and browses on the same account that can change every system. One phishing link is then an administrator compromise.

Admin rights that never came back

Granted temporarily for a task, then forgotten. The number of administrators on a machine tends only to go up.

Shared local admin passwords

The same local administrator password on every machine, set once at build and never changed. One compromised machine gives the same access to all of them.

Leavers still active

An account left enabled after someone leaves, often with the permissions they had on their last day.

Access control is about what changes, not what was set up. Joiners, leavers and temporary exceptions all change who can do what. The control holds only if those changes are made, and reversed, as they happen.

Making it work

Quick answers

Can users be local administrators under Cyber Essentials?

Only where their job genuinely needs it, and administrator rights should be used only for administration, not for day-to-day work.

Do admins need a separate account?

Administrator accounts should be used only for admin tasks, so in practice administrators need a separate everyday account for email and browsing.

Is MFA required for all users?

On cloud services that offer MFA, yes, for users and administrators. Missing it is an automatic fail.