CyberEssentials 101: Administrative Accounts May 7, 2025 – Posted in: Cyber Security, IT Support – Tags: Cyber Essentials, Cyber Essentials 101, Cyber Security, CyberEssentials, cybersecurity, it support, SmallBusiness
All users need to have unique accounts and should not be carrying out day-to-day tasks like browsing the internet, invoicing or dealing with e-mail whilst logged on as a user with administrator privileges. Admin accounts allow significant changes to the way your computer systems work, doing day to day work logged in as an admin opens the door for any mistaken clicks on malicious software or attachments to cause significantly more damage. It’s also important to only give users access to the resources and data necessary for their roles, and no more.
Questions in this section apply to: servers, desktop computers, laptops, thin clients, tablets, mobile phones, and cloud based software services.
Further guidance from IASME can be found here.
A7.1 – Are users only provided with user accounts after a process has been followed to approve their creation? Describe the process.
Why are they asking you this?
One of the central tenets of security I ensuring data is only accessible by the people who need it to do their job. If you are going to make sure only the right people see the right data then the onboarding process needs to be deliberate.
What’s the detail?
It is fairly simple to cover this – you just need a documented onboarding process where you don’t give a new starter their account details until you’ve gone through the you are who you say you are checks and only people who know who needs to see what are allowed to request account creation.
Example answer:
New user accounts are created by the IT team at the request of department heads who specify the necessary access, signed off by a single authoriser – Bob Smith, the FD. New staff are not given their credentials until after HR have completed the initial onboarding checks and they have read and signed off on acceptable use policies.
A7.2 – Are all user and administrative accounts accessed by entering a unique username and password?
Why are they asking you this?
Each user should have their own, unique account and password. If people can log into each other’s accounts with the same password then there is little point having separate logins, and separate logins are required to enable granular data access approval and tracking of who did what when.
Example answer:
In order to pass the answer to this question must be yes.
A7.3 – How do you ensure you have deleted, or disabled, any accounts for staff who are no longer with your organisation?
Why are they asking you this?
Whatever the reason someone is leaving the business, you must make sure you revoke their access to company data.
Example answer:
As part of staff offboarding HR let our IT team know that the user is leaving, IT then disable all related logins and sign the user out of all sessions immediately their contract ends.
A7.4 – Do you ensure that staff only have the privileges that they need to do their current job? How do you do this?
Why are they asking you this?
Any access granted to a document increases the risk of someone who shouldn’t see it accessing it. If someone needs access to the document to do their job, then the risk is worth taking. If they don’t, then it isn’t. The more often account is used, the more chance there is of it being compromised.
What’s the detail?
This isn’t about trusting your staff, it is about damage limitation in case of a breach. If someone’s account is compromised then any data they have access to is compromised too. Limiting their access to only what they need is simply how you limit the damage that can be done if their account is hacked. When a staff member changes job role, you may also need to change their permissions to only access the files, folders and applications that they need to do their day to day work.
Example answer:
Staff are only granted access to data they need access to in order to perform their required tasks. This is managed on a job title/role level through group policy and security groups.
A7.5 – Do you have a formal process for giving someone access to systems at an “administrator” level and can you describe this process?
Why are they asking you this?
This is following on from A7.4 – admin access to your domain and systems is incredibly powerful. Malicious actors or unknowing staff could do significant damage with such access.
What’s the detail?
User accounts with special access privileges (e.g. administrative accounts) typically have the greatest level of access to information, applications and computers. When these privileged accounts are accessed by attackers they can cause the most amount of damage because they can usually perform actions such as install malicious software and make changes. Special access includes privileges over and above those of normal users.
It is not acceptable to work on a day-to-day basis in a privileged administrator mode.
Example answer:
Yes – Users are only granted admin access to systems if they have been approved by the IT team and Bob Smith (FD) and they have read and signed the acceptable use policies.
A7.6 – How does your organisation make sure that separate accounts are used to carry out administrative tasks (such as installing software or making configuration changes)?
Why are they asking you this?
This is a follow up question to A7.5. Browsing the internet or checking email as an admin is highly risky – if you accidentally click something malicious then the software will have admin level access to your system or even domain.
What’s the detail?
You must use a separate administrator account from the standard user account, when carrying out administrative tasks such as installing software. Using administrator accounts all-day-long exposes the device to compromise by malware. Carry out Cloud service administration through separate accounts.
Example answer:
No accounts used for day-to-day tasks have administrator access. All users who have access to admin accounts must first have read and signed the acceptable use policies.
A7.7 – How does your organisation prevent administrator accounts from being used to carry out every day tasks like browsing the web or accessing email?
Why are they asking you this?
This is a very similar to A7.6 but from the other direction. Your answer will be similar but relates specifically to activities carried out when an administrator account is in use.
What’s the detail?
You must ensure that administrator accounts are not used to access websites or download email. Using such accounts in this way exposes the device to compromise by malware. Software and update downloads should be performed as a standard user and then installed as an administrator. You may not need a technical solution to achieve this, it could be based on good policy, procedure and regular training for staff.
Example answer:
No users perform day-to-day tasks using administrator accounts, administrator accounts are used strictly for administrator tasks. All users who have access to admin accounts must first have read and signed the acceptable use policies.
A7.8 – Do you formally track which users have administrator accounts in your organisation?
Why are they asking you this?
Keeping track of who has administrator access is vital to make sure only the necessary users have it.
Example answer:
In order to pass the answer to this question must be yes.
A7.9 – Do you review who should have administrative access on a regular basis?
Why are they asking you this?
You should review the list of people with administrator access regularly. Depending on your business, this might be monthly, quarterly or annually. Any users who no longer need administrative access to carry out their role should have it removed.
Example answer:
In order to pass the answer to this question must be yes.
Next Time…
Next week we will cover the Password-Based Authentication section of Cyber Essentials.
If you’d like help reviewing what you’d need to do to be compliant, filling in the paperwork, or working with your staff to smooth any required changes, we can help. Give us a call on 01245 265 100 or email .