Ask a fifteen person company who has administrator rights and you will get a shrug. The honest answer is almost everybody. Somebody needed to install a printer driver three years ago, so they were made an administrator, and nobody took it back. The owner is a global administrator in Microsoft 365 because that is how the last IT provider set it up. Nobody did anything wrong. This is what happens when a company grows faster than its paperwork.

Here is the part worth sitting with. An administrator account is not a job title. It is a ring of keys. When one gets phished, the attacker does not get one person’s email. They get everything that account can reach, which at a small company is usually all of it. The good news: this is one of the few security problems you can meaningfully fix in an afternoon, without buying a product and without making anyone’s workday worse.

Why Everyone Ends Up an Administrator

Nobody sets out to hand admin rights to the whole company. It accumulates. A new hire needs a design tool, so they get elevated “temporarily.” A vendor makes three people full administrators because that was the fastest way to finish an install. Someone leaves, and their permissions get handed to two other people. Five years of small, sensible decisions produce a company where privilege is the default and restriction is the exception.

The alternative has a real cost too. If only one person can approve software installs, that person becomes a bottleneck and work stops. Spreading admin rights around is not carelessness. It is a tradeoff resolved in favor of speed. The goal is to keep the speed and drop the exposure.

What One Phished Admin Account Actually Costs

When an ordinary account gets taken over, the damage is bounded. The attacker reads that person’s mail and opens whatever files that user could open. Bad, but survivable, and usually visible quickly.

An administrator account is a different category of event. In an April 2025 alert on credential exposure, CISA described what attackers do with valid credential material: they “escalate privileges and move laterally within networks,” they “access cloud and identity management systems,” and they “conduct phishing, credential-based, or business email compromise (BEC) campaigns.” At a thirty person company that means creating new accounts, turning off security settings, reading anyone’s mail, and changing where payroll deposits land.

The second cost is the one nobody budgets for: recovery. Cleaning up after a compromised standard account takes hours. Cleaning up after a compromised global administrator means assuming every account and every setting may have been touched. That is days, and it never happens during a slow week. Phishing is how most of these begin, and we have written about why blocking phishing remains so difficult even with good filtering in place.

The Two Account Rule

The highest value change here is boring and free. The people who administer your systems get two accounts: one for daily work, one for administration. CISA puts this plainly in its Cross-Sector Cybersecurity Performance Goals: “No user accounts always have administrator or super-user privileges. Administrators maintain separate user accounts for all actions and activities not associated with the administrator role.”

Think of a restaurant. The manager has a key to the safe, and that key does not ride on the same ring as the front door key. Your administrative account should have no mailbox anyone emails, no browsing history, and no habit of staying logged in all day. Almost every account takeover we see arrives through email or a browser. If your admin account never touches either, you have closed the most common road to it.

The Systems Where This Matters Most

You do not need to do this everywhere. Concentrate on the five systems where full control would end your week. Everywhere else, ordinary permissions are proportionate.

  • Your identity provider. Microsoft 365 or Google Workspace. The master key, because whoever controls it can reset passwords for every service that signs in through it.
  • Accounting, payroll, and banking. Where money actually moves, and where a changed account number does the most damage fastest.
  • Your backup system. Ransomware crews look for backups first. If the backup console shares credentials with everything else, your recovery plan is only as good as one password.
  • The tool that manages your computers. Whatever pushes software and updates across your fleet reaches every machine you own by design. That is the point, and the risk.
  • Your domain registrar and DNS. Small, forgotten, enormously powerful. Control here means control of your email and your website.

Just in Time Access, and the Laptop Question

“Just in time” access sounds like consultant vocabulary, but the idea is simple. Nobody holds administrator rights all the time. You request them, you get them for a short window, and they expire on their own. It is a hotel key card: it opens your room, but only for the nights you booked. Microsoft 365 and Google Workspace both offer versions of this in their administrative role settings, usually labeled privileged access or role activation.

Local administrator rights on laptops are a separate question, and here we part ways with some of our own industry. Removing them is a real control that earns its friction at a large enterprise. At a fifteen person company it is usually the wrong first move. Local admin on one laptop lets an attacker own that laptop. Global admin in your tenant lets them own the company. Do the cloud accounts first.

There is a middle path that works. Leave current staff alone, and set up every new computer with the user as a standard account from day one. Nobody loses anything they had, and across two or three years of hardware replacement the problem solves itself.

Cutting Privilege Without Creating a Ticket Queue

  1. List who has admin rights in those five systems. Do this before changing anything. Most owners are surprised, and the list makes the decision for you.
  2. Remove accounts for people who left. CISA’s performance goals call for revoking access by the departing employee’s last day. Forgotten admin accounts are the ones used against you.
  3. Give each admin a second account. No mailbox, a long unique password in a password manager, and strong multi-factor authentication turned on.
  4. Keep at least two people with real admin access. We have watched a company lock itself out of its own tenant because the only administrator was on a cruise.
  5. Write down the exceptions. If your designer truly needs to install fonts weekly, document it and move on. A policy with a written exception outlasts one everybody ignores.
  6. Review the list twice a year. Privilege creeps back. Twenty minutes in January and twenty in July keeps it from re-accumulating.

Notice what is not on that list. Nothing here requires your staff to file a ticket to do their job. NIST’s Small Business Quick-Start Guide, published in 2024, frames the goal as two questions: are we restricting access and privileges only to those who need it, and are we removing access when they no longer need it?

The Bottom Line

Admin rights spread because they solve real problems. The fix is not making your team ask permission for everything. It is separating the account someone uses to read email from the account that can rewrite your company, and being strict about that in the handful of systems that matter. A couple of hours of work, zero dollars of software, and it sits underneath most of the other things worth doing, which is part of why cybersecurity stopped being optional. If you are not certain who holds the keys right now, that is the finding, not the failure.

We help small and mid-sized businesses across Denton County sort out who has access to what, without turning anyone into a ticket filer. For a straight answer about your own administrator accounts, Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).