Why this matters
Administrator accounts can install software, change security settings and access everything. If an attacker gets admin access, they control the environment. Restricting administrative privileges is an Essential Eight strategy because it limits how far an attack can spread.
What you'll need
- Admin access to Microsoft 365 and devices
- A list of who currently has admin rights
Step-by-step instructions
Step 1
Find every admin account
Review Microsoft 365 admin roles, local administrator rights on computers, and admin access in other systems.
Step 2
Remove unnecessary admin access
Staff should use standard accounts for daily work. Remove local admin rights from everyday users.
Step 3
Create separate admin accounts
People who need admin access should have a dedicated admin account without email or web browsing, used only for admin tasks.
Step 4
Use the least privileged role
Assign specific roles such as User Administrator or Exchange Administrator instead of Global Administrator where possible.
Step 5
Protect admin accounts strongly
Require phishing-resistant MFA for all admin accounts.
Step 6
Review regularly
Review admin access at least every 12 months, and immediately when roles change or staff leave.
Summary
Fewer, separated and well-protected admin accounts make it much harder for an attacker to take over your systems.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.