User Access, Administrator Accounts and Least Privilege Explained

How to control who can access business systems, reduce administrator risk and remove unnecessary access when employees or suppliers leave.

Cyber Security Basics · Lesson 7 of 10

Quick answer: How to control who can access business systems, reduce administrator risk and remove unnecessary access when employees or suppliers leave.

User access control is the principle of giving people the access they need without giving every account unrestricted permissions. It limits the damage that can follow a stolen password, compromised device or insider mistake.

What is least privilege?

Least privilege means each user receives only the permissions needed for their role. A member of the sales team may need CRM access but not payroll administration. A finance user may need accounting access but not control of the company website.

Why administrator accounts need special treatment

Administrator accounts can install software, create users, change security settings and access large amounts of information. Use separate admin accounts for privileged tasks and standard accounts for normal work wherever practical.

Avoid shared accounts

Named accounts make it easier to apply MFA, remove individual access and understand who performed an action. Shared logins reduce accountability and often lead to shared passwords that remain unchanged for years.

Remove access when people leave

A leaver process should cover email, Microsoft 365, CRM, accounting, VPN, remote access, websites, social media, password managers and physical access. Access removal should be planned rather than relying on somebody remembering every system.

Review access after role changes

Permissions tend to accumulate. An employee who moves teams may keep access from an old role while receiving new privileges. Periodic reviews help remove this “permission creep”.

Include suppliers and contractors

Third-party access should also be named, limited and removed when no longer required. Remote support accounts, supplier portals and temporary access can otherwise remain as hidden routes into the business.

What to do after this lesson

Export or review your Microsoft 365 users and administrators. Identify dormant accounts, former staff, shared accounts and users with privileges they no longer need.

Frequently asked questions

What is least privilege in simple terms?

Give each person only the access they genuinely need to do their job, and no more.

Should business owners use administrator accounts every day?

It is safer to use a standard account for routine work and a separate administrator account only when elevated privileges are required.

How quickly should leaver access be removed?

Access should be removed promptly according to the agreed leaving process, with high-risk systems prioritised.

Useful UK guidance

Put the lesson into practice

39Security helps small businesses turn cyber security guidance into practical controls and owned actions.

Course overview ← Previous lesson Next lesson →