Skip to main content
IT technician reviewing a software install request while an employee waits

Why Your Employees Shouldn’t Have Administrator Access to Their Computers

Picture this: an employee needs a printer driver installed on a Friday afternoon, and IT can’t get to it until Monday. To keep her working, someone gives her administrator access on her laptop. The printer works, the week ends, and nobody takes the access back. Months later she is still an administrator, which means every program she opens, and anyone who gets hold of her password, inherits that power.

That is how most administrator access starts. It is a reasonable request, a quick fix, and a permission that outlives the reason for it. Add a few more employees and a few more years, and nobody can say who is able to change what.

October is Cybersecurity Awareness Month, so it is a good time to look at one setting that is easy to fix. Employees should do their daily work from a standard account, and administrator rights should stay with IT.

What Administrator Access Lets Someone Do

An administrator has far more control over a computer than a standard user does. On Windows, members of the local Administrators group have Full Control permissions on the device, which is why Microsoft says it is “a best practice to limit the number of users in the Administrators group.” On a Mac, Apple explains that administrators can install and remove software, change settings and manage other users. Apple advises creating a standard account “to use when administrator privileges are not needed.”

In practice, an administrator can install drivers and services that keep running in the background, create or change user accounts, change permissions on files and folders, and change some security settings.

Local administrator access covers one computer. It is separate from administrator roles in Microsoft 365, which can reach accounts, email and files across the whole company. Microsoft’s advice for those roles follows the same idea: have as few global administrators as possible. Review both kinds of access on their own.

Why Permanent Administrator Access Raises Your Risk

A program starts with the permissions of whoever launches it. When an employee opens a fake installer or a bad attachment, that program can only do as much as the employee’s account allows. With a standard account, it hits a wall. By default, Windows asks a standard user for an administrator’s username and password before it makes a system-level change, and the employee has neither. An employee who is signed in as an administrator sees a prompt to choose Permit or Deny. On a busy afternoon, that is an easy click.

Apple puts it plainly: if a standard user’s security is compromised, “the potential harm is far more limited than if the user has administrator privileges.”

US guidance points the same way. CISA’s #StopRansomware Guide tells organizations to restrict user permissions to install and run software, and to separate administrator accounts from user accounts. CISA and the NSA also list “improper separation of user/administrator privilege” among their top ten cybersecurity misconfigurations. The underlying idea is called least privilege, which NIST defines as giving every user and system “the minimum system resources and authorizations” it needs to do its job.

What Staff Can Still Do With a Standard Account

Nearly everything an employee does all day works fine. That covers email, the web browser, Microsoft 365, approved business applications, online meetings, printing, and opening and saving files. They can also change personal settings that affect nobody else.

Some programs install for a single user without extra rights. Others need administrator approval because they add drivers, services or files in protected parts of the computer. Those installs deserve a second set of eyes, and they are usually where the habit of handing out admin access begins.

How We Handle Software Installs With AutoElevate

Removing admin rights only works if staff still have a quick way to get software installed. On Windows computers, we use AutoElevate, an endpoint privilege management tool from CyberFOX. In plain terms, it lets a technician, not the employee, decide which programs get administrator rights.

Here is how it works. A small agent on the computer watches for the Windows prompt that asks for an administrator password. When that prompt would appear, the employee sees a different dialog asking whether they want to proceed. If they do, the request goes to a technician along with details about the program. The technician allows or denies it and can leave a note that shows on the employee’s screen. If we allow it, that one program runs with elevated rights, and the employee never needs an administrator password.

We can also turn a decision into a rule. A rule can apply to one computer, one location, one company or every computer, so software we have already reviewed doesn’t need a fresh request each time. Rules work in the other direction as well. We can deny a program we don’t trust everywhere at once.

AutoElevate doesn’t make installs instant, and it doesn’t replace judgment. It puts a person, or a rule a person already approved, between the employee and the administrator prompt.

For our managed clients, we go a step further. We remove local administrator accounts altogether and use AutoElevate’s just-in-time admin account. When a technician needs administrator access to a Windows computer, AutoElevate creates a temporary administrator user for that login session and deletes it at logout. Nobody has to share an administrator password, and none sits on the computer waiting to be stolen.

Who Should Keep Administrator Access

Administrator rights belong with the people whose work calls for them: your IT provider, an internal IT person, or occasionally a specialist who runs one particular system. Owners and managers are not exempt. Owning the company doesn’t call for administrator rights on every laptop.

Anyone who does need those rights should get a separate administrator account and keep using a standard account for email and browsing. CISA’s guide says designated admin accounts should handle admin work only. If you keep a permanent administrator account, we also recommend a unique password on each computer, held by your IT provider and never shared with staff. One password reused everywhere opens every machine if it leaks.

How to Remove Administrator Rights Without Locking Anyone Out

Don’t strip every administrator account in one day. Someone still needs a working way to repair each computer. We recommend this order:

  • Check who has administrator access today. Review the local Administrators group on each Windows computer and the administrator users on each Mac, including old, shared, vendor and setup accounts.
  • Ask why each person has it. A clear business need should back every account that keeps the permission.
  • Confirm that IT has a working, protected administrator account on every device before you change anyone else’s.
  • Test the programs each person needs while signed in as a standard user.
  • Switch the employee to a standard account, then have them sign out and back in.
  • Tell staff where to send install requests and what to include: the program name, why they need it and the official download page.
  • Review access again whenever someone changes roles or leaves.

What This Will Not Fix

There are two honest tradeoffs. First, some older line-of-business software insists on administrator rights, often because it writes to protected parts of the computer. Test it before you change anything. Many times the answer is a vendor update, a setting, or permission for one folder. Occasionally an old program has no clean fix and needs its own plan, such as replacing it. Second, elevation adds a small step. Employees now wait for an approval where they once just clicked Yes. That wait is the price of having someone check the installer first, and staff accept it more easily when they know who to ask.

Standard accounts also don’t stop every attack. They limit what a bad program can change, and they work best alongside the rest of your defenses. We deploy Proofpoint for email security and standard MFA for clients, and our post All businesses should adopt MFA. Now explains why that matters. We also recommend current software updates, endpoint protection and backups you have tested. Staff still need to spot phishing, and The business owner’s complete guide to phishing is a good place to start.

The Bottom Line

Administrator access is easy to grant and easy to forget. Daily work doesn’t need it. Move employees to standard accounts, make sure IT has a protected way to get administrator access, and give staff one clear way to ask for software. You give up a little speed on installs. In return, a stolen password or a bad download can do far less damage.

Talk to Us

If you are not sure who has administrator rights on your company’s computers, we can help you find out. Our Cybersecurity page explains how we approach protecting small businesses, and we are happy to talk through how elevation approvals would work for your team. Book a time on my calendar and I’ll take a look at what you have in place today.

Frequently Asked Questions

It depends on the software. Programs that install only inside the employee’s own profile may not need approval. Software that changes protected system files, installs drivers or adds background services needs administrator credentials, which is where a request to IT comes in.

Normal business applications keep working. Older specialist programs are the exception, so test them before you change every computer.

No. It limits what many harmful programs can change, but it doesn’t prevent every attack. You still need software updates, endpoint protection, email security, MFA and tested backups.

Use a standard account for everyday work. When you need administrator access for an approved task, use a separate account and keep its password protected.

No. Local administrator access controls one computer. Microsoft 365 administrator roles can control cloud users, email, files and security settings across the company. Limit and review both.

It is an endpoint privilege management tool we use on Windows computers. When a standard user needs a program to run with administrator rights, they send a request. A technician allows or denies it, or an existing rule decides.