An administrator account can change settings, grant access, and remove safeguards. It should therefore not be the ordinary account used for email, chat, or web browsing. This minimum standard is for a small business that wants to reduce risk without building a complex administration function.
1. Separate daily and administrator accounts
Every person who administers a system uses two accounts:
- a daily account for email, documents, meetings, and the web;
- a separate, named administrator account used only for tasks that require elevated privileges.
The administrator account should not receive email or be used to sign in to unrelated websites. If a task can be completed with the ordinary account, use the ordinary account.
2. Require phishing-resistant MFA
An administrator account must use multi-factor authentication. Passkeys or physical FIDO2 security keys are preferred. They resist phishing better than SMS codes and codes copied from an authenticator app.
Prepare at least one independent fallback and test it before disabling the old method. Store the second key and recovery codes separately from the primary laptop and phone. The passkey and MFA migration checklist provides a practical sequence.
3. Do not use shared accounts
Every administrator receives an individual account. Names such as admin, a shared password in a spreadsheet, or one login for both a supplier and employees make it impossible to determine who made a change.
If a legacy system requires a shared account, treat access as an exception: keep the password in the company password manager, release it only to authorised people, change it whenever one of them leaves, and record each use separately.
4. Grant only the privileges needed
An administrator does not need full access to everything. Grant privileges for a specific task and system, for the shortest practical time. A person managing the website does not automatically need access to accounting, backups, or every mailbox.
Document role boundaries when setting up system administration, and identify excessive privileges through a security assessment.
5. Prepare emergency access
The business should have one or two emergency accounts used only when its normal administrators cannot sign in. Store credentials and recovery methods securely, outside the daily workflow, with access available to at least two designated people. Every use requires a record of the reason, time, and actions taken, followed by a credential change.
Test the procedure at least once a year without making risky production changes.
6. Log sign-ins and changes
Enable available records of administrator sign-ins, failed attempts, privilege changes, MFA settings, and recovery methods. Alerts should cover at least a sign-in from a new location or device, addition of a new MFA method, and assignment of high privileges.
For a small business, it is enough to designate someone who checks alerts regularly and knows what to do. Appropriate monitoring can be defined as part of cybersecurity support. If account takeover is suspected, follow the account takeover emergency card.
7. Manage the full lifecycle
Create an account only after approving its access scope and identifying the person responsible. A role change triggers a fresh privilege review. When an employee leaves or a supplier’s engagement ends, promptly disable the account, terminate active sessions, recover security keys, and remove recovery methods. Do not delete audit records with the account.
8. Review the standard periodically
At least quarterly, check the administrator list, assigned roles, MFA methods, unused accounts, and emergency access. The review record can be brief: who checked, when, which exceptions were found, and when they will be resolved. An exception without a deadline and a responsible person quickly becomes a permanent gap.