Why Your Employees Shouldn't Have Administrator Access

Giving an employee administrator access often starts with a perfectly reasonable request.

They need to install a printer, update a specialist program, or change a setting on their computer. Giving them administrator access gets the job done.

The problem? That access usually stays long after the request has been completed.

We're looking at why employees usually don't need administrator access, the risks of using personal devices for work, what happens to your data when you cancel a cloud service, guest Wi-Fi, IT budgeting, computer replacement and more.

Why Your Employees Shouldn't Have Administrator Access

An administrator has significantly more control over a computer than a standard user.

Depending on the computer and how it's managed, administrator access can allow someone to:

  • Install and remove software

  • Add drivers for printers and other equipment

  • Create, change or remove user accounts

  • Change system settings

  • Change permissions on files and folders

  • Install services that continue running in the background

  • Make changes to some security settings

That can be useful when legitimate technical work needs to be done. But it also means that if an employee installs the wrong program — or someone takes control of their account — those same permissions can be used to make potentially harmful changes to the computer.

Microsoft recommends limiting the number of users with administrator privileges on Windows computers. Apple similarly recommends limiting administrative users on Macs and using standard accounts when administrator rights aren't required.

Standard accounts are suitable for everyday work

Employees don't need administrator access for most normal business tasks.

A standard account can still be used for things like:

  • Reading and sending email

  • Browsing the web

  • Working in Microsoft 365 or Google Workspace

  • Accessing approved business applications

  • Joining online meetings

  • Printing

  • Opening and saving files

  • Changing personal settings that don't affect other users

Some applications do require administrator approval to install or update, but that doesn't mean the employee needs permanent administrator access.

Your IT team can approve the installation, deploy an update remotely, or use a separate administrator account for the task.

Ideally, that administrator account should be reserved for approved technical work — not everyday email or web browsing — and protected with multifactor authentication where supported.

Check who has access now

Ask your IT provider to review the administrator accounts on your company computers.

Before removing access, make sure IT has a tested way to perform administrator tasks on every device.

The goal isn't to make employees' jobs more difficult. It's to give people the access they need to do their jobs without giving them — or any malicious software running under their accounts — more control than necessary.

lori walker