Why Your Employees Shouldn't Have Administrator Access
Giving an employee administrator access often starts with a perfectly reasonable request.
They need to install a printer, update a specialist program, or change a setting on their computer. Giving them administrator access gets the job done.
The problem? That access usually stays long after the request has been completed.
We're looking at why employees usually don't need administrator access, the risks of using personal devices for work, what happens to your data when you cancel a cloud service, guest Wi-Fi, IT budgeting, computer replacement and more.
Why Your Employees Shouldn't Have Administrator Access
An administrator has significantly more control over a computer than a standard user.
Depending on the computer and how it's managed, administrator access can allow someone to:
Install and remove software
Add drivers for printers and other equipment
Create, change or remove user accounts
Change system settings
Change permissions on files and folders
Install services that continue running in the background
Make changes to some security settings
That can be useful when legitimate technical work needs to be done. But it also means that if an employee installs the wrong program — or someone takes control of their account — those same permissions can be used to make potentially harmful changes to the computer.
Microsoft recommends limiting the number of users with administrator privileges on Windows computers. Apple similarly recommends limiting administrative users on Macs and using standard accounts when administrator rights aren't required.
Standard accounts are suitable for everyday work
Employees don't need administrator access for most normal business tasks.
A standard account can still be used for things like:
Reading and sending email
Browsing the web
Working in Microsoft 365 or Google Workspace
Accessing approved business applications
Joining online meetings
Printing
Opening and saving files
Changing personal settings that don't affect other users
Some applications do require administrator approval to install or update, but that doesn't mean the employee needs permanent administrator access.
Your IT team can approve the installation, deploy an update remotely, or use a separate administrator account for the task.
Ideally, that administrator account should be reserved for approved technical work — not everyday email or web browsing — and protected with multifactor authentication where supported.
Check who has access now
Ask your IT provider to review the administrator accounts on your company computers.
Before removing access, make sure IT has a tested way to perform administrator tasks on every device.
The goal isn't to make employees' jobs more difficult. It's to give people the access they need to do their jobs without giving them — or any malicious software running under their accounts — more control than necessary.