
The Problem With “Just Give Them Admin”
It usually starts with something innocent. An employee needs to install a printer driver, update a piece of specialist software, or tweak a system setting. Granting them administrator access gets the job done quickly — but the access rarely gets taken away.
From that point on, the employee can approve software installations and make system-level changes without IT ever knowing. If they install the wrong program, or if their account gets compromised, those elevated permissions become a serious problem for the whole business.
The fix is straightforward: employees should use standard accounts for everyday work, and administrator access should be reserved for approved IT tasks only. This is exactly what the ACSC recommends as part of the Essential Eight — specifically under the Restrict Administrative Privileges control.
What Administrator Access Actually Allows
On Windows, members of the local Administrators group have full control over that machine. Microsoft’s own guidance recommends keeping that group as small as possible. With administrator access, a user can:
- Install and remove software
- Add or update device drivers
- Create, modify, or delete user accounts
- Change system and security settings
- Modify file and folder permissions
- Install background services
Mac computers work the same way. Apple recommends limiting administrative users and using a standard account whenever elevated rights aren’t needed.
One important distinction: local administrator access applies to a single device only. It’s completely separate from Microsoft 365 admin roles, which can control cloud users, email, SharePoint, security settings, and more. Both types of access need to be reviewed — but they’re not the same thing.
Why Permanent Admin Access Increases Your Risk
When an employee runs software under an administrator account, that software inherits their permissions. If they’re tricked into approving a fake update or running a malicious installer, the program can install system components, alter settings, or affect other users’ data — without needing to ask for anything extra.
Windows does include User Account Control (UAC) as a safeguard, but an employee signed in as an administrator can approve those prompts themselves. A standard user, by contrast, is prompted for separate administrator credentials — which creates a natural checkpoint.
Standard accounts also mean IT gets to review software requests before anything is installed. That’s a chance to verify the source, check the version, and confirm the software is appropriate for the business. CISA’s StopRansomware guidance specifically calls out controlling local administrator access as a key defence against ransomware.
Standard Accounts Are Fine for Everyday Work
A standard account handles the full range of normal business tasks without issue:
- Reading and sending email in Outlook
- Working in M365 apps — Word, Excel, Teams, SharePoint
- Web browsing and online meetings
- Accessing approved business applications
- Printing and managing personal files
If a particular application requires admin rights to run, the right response isn’t to permanently elevate the employee’s account. IT can adjust the application’s configuration, grant access to specific folders, or use Intune to deploy updates centrally — without handing over admin credentials.
How to Handle Software Without Giving Out Admin Access
Let IT install and deploy software
Your IT team can install approved software remotely, verify the installer came from the legitimate source, and confirm the version is supported. With Intune and M365, managed software deployment can push approved applications and updates to devices automatically — no employee involvement required.
Approve individual requests
When an employee needs something installed, they contact IT, IT reviews the request, and enters credentials on the employee’s behalf. The employee never needs the password.
Use time-limited or separate admin accounts
For staff who genuinely need to perform technical tasks — developers, specialists — set up a separate administrator account enabled only for that task, then disable it again. Their standard account stays in use for email, browsing, and day-to-day work.
Who Should Actually Have Admin Access?
- Internal IT staff
- Your managed IT provider (via a protected, unique account per device)
- Approved technical employees with a documented business need
Business owners should also use standard accounts for everyday work. Owning the company doesn’t require permanent administrator access to every device.
One more thing worth flagging: using the same local administrator password across every device is a significant risk. If that password is stolen from one machine, it works on all of them. Each device should have a unique administrator password — or your IT provider should manage those credentials through a proper privileged access management tool.
Steps to Remove Admin Access Safely
- Audit who has it — Review the local Administrators group on every Windows machine and administrator users on every Mac. Include old, shared, and vendor accounts.
- Confirm there’s a business reason — Every admin account should have a clear, documented need. “Occasionally updates one application” isn’t enough.
- Make sure IT has a working account first — Confirm your IT team can access each device before removing employee permissions. Test it.
- Test business-critical software — Check that the applications employees rely on work correctly under a standard account before making the change permanent.
- Convert the account — Remove the employee from the local Administrators group and have them sign out and back in for the change to take effect.
- Tell staff how to request installations — Give employees a clear, single point of contact for software requests. Keep it simple and easy to use.
- Review access when roles change — Include administrator access in your regular access reviews, and revisit it whenever someone changes roles or leaves the business.
Frequently Asked Questions
Will removing admin access stop employees from working? Normal M365 and business applications will continue working. Test specialist or older software before rolling changes out across every device.
Does removing admin access stop malware? It limits what malware can do, but it’s not a complete defence on its own. You still need Microsoft Defender, email security, MFA, patching, and tested backups in place.
Is local admin access the same as M365 admin access? No. Local admin controls one computer. M365 admin roles can control users, email, cloud files, Entra ID, and security settings across your entire Microsoft environment. Both should be limited and reviewed regularly.
Not sure who currently has administrator access across your business devices, or whether your setup aligns with the Essential Eight? Get in touch with the team at IT TechNinjas — we’ll review your access controls and help you get it sorted properly.
