It usually starts with something small. An employee needs a printer installed, a specialist program updated, or a setting changed. Giving them administrator access solves the problem in the moment.
The trouble is what happens after. That access rarely gets removed once the task is done. From that point on, the employee can install software, approve changes, and modify settings that would normally go through IT first. If they click the wrong installer, or someone takes over their account, those same permissions are what an attacker uses to take over the computer.
For day-to-day work, employees should be using standard accounts. Administrator access should be the exception, reserved for the specific tasks that actually require it.
What Administrator Access Actually Allows
An administrator account has far more control over a computer than a standard one. On Windows, anyone in the local Administrators group has full control over that machine. Microsoft’s own guidance on local accounts recommends keeping that group as small as possible — which tells you something about how much power it carries.
Depending on how the computer is set up, an administrator can typically:
- Install and remove software
- Add drivers for printers and other hardware
- Create, modify, or delete user accounts
- Change system settings
- Change permissions on files and folders
- Install background services
- Modify certain security settings
Mac computers work the same way. Apple’s own security guidance confirms that administrators can install and remove software, manage other users, and change system settings — and recommends limiting how many people carry that role, defaulting everyone else to a standard account.
One distinction matters here: local administrator access controls a single computer. It’s not the same as being an administrator in Microsoft 365, Google Workspace, or on your network or servers. Those roles can control email, cloud files, user accounts, or multiple systems at once. An employee can easily have local admin rights on their laptop without being anywhere near a Microsoft 365 admin. Both types of access need to be reviewed — separately.
Why Permanent Admin Access Is a Standing Risk
Here’s the part that catches people off guard: software runs with whatever permissions the person launching it has.
If a program asks for administrator approval and an employee with admin rights clicks “yes,” that program can now install system components, change settings, or touch data belonging to other users on that machine. That’s harmless when it’s a legitimate update. It’s a serious problem when it’s a fake installer, a malicious attachment, or software pulled from a site that isn’t actually the vendor.
Most people in that moment think they’re approving a routine update. They have no way of knowing they just handed a program the keys to the computer.
Windows tries to catch this with User Account Control, which prompts for approval before most administrative changes. But an employee signed in as an administrator can approve that prompt themselves, with nothing to slow them down. A standard user, by contrast, has to enter separate administrator credentials — which means someone else gets a chance to catch a bad request before it goes through. Microsoft is direct about this: it recommends the standard account as the more secure default for everyday Windows use.
Standard accounts also mean fewer people who can quietly change security settings without anyone reviewing it. When employees can’t approve every installation themselves, IT gets a chance to actually check what’s being installed, where it came from, and what it’s asking permission to do.
This isn’t a fringe opinion. CISA advises businesses to control local administrator access and restrict who can install software. The Australian Cyber Security Centre goes further, listing restricted administrative privileges as one of its Essential Eight security controls and recommending separate accounts specifically for administrative work.
What Standard Accounts Can Still Do
A standard account isn’t a limited account for limited work. It covers nearly everything most employees do all day, including:
- Reading and sending email
- Browsing the web
- Working in Microsoft 365 or Google Workspace
- Using approved business applications
- Joining online meetings
- Printing to an installed printer
- Opening and saving files
- Changing personal settings that don’t affect other users
Plenty of applications install fine for a single user without ever needing administrator approval. Others need it because they add drivers, background services, or files in protected areas of the system — and that’s a much narrower list than most people assume.
An employee shouldn’t end up with permanent administrator rights just because one program needed an update. IT can push the update remotely, approve the install directly, or use a dedicated administrator account for that one task instead.
Older line-of-business software is sometimes the exception, since some legacy applications were built assuming the user has admin rights. Test those specifically before changing anyone’s account type. Often, the fix is updating the application, adjusting its configuration, or granting access to the specific folders it needs — not leaving the whole account elevated indefinitely.
How to Handle Software Installs Without Permanent Admin Access
Removing standing admin rights doesn’t mean employees are stuck waiting on IT for every little thing. There are several practical ways to keep things moving.
Let IT Install Approved Software
Your internal team or IT provider can install the program remotely. This also gives them a natural checkpoint to confirm the installer actually came from the software vendor and that the version being installed is supported.
Use Managed Software Deployment
If your computers are centrally managed, approved applications and updates can be pushed out to employees automatically — no one has to run an installer themselves. The exact method depends on your operating system and device management platform.
Route Requests Through IT
When an installation needs administrator approval, the employee contacts IT. IT reviews the request and enters the credentials directly, without ever handing the password to the employee.
Grant Time-Limited Admin Access
Some roles genuinely need to install or test software as part of the job. For those cases, use a separate administrator account that’s enabled only for the approved task, then disabled again immediately afterward.
Set Up a Separate Administrator Account
Employees who regularly do approved technical work can be given a dedicated administrator account, kept entirely separate from the one they use for email, browsing, and everything else. The admin account only comes into play when a task specifically calls for it.
Use a Privileged Access Management Tool
Manually approving every request doesn’t scale well past a handful of computers. Privileged access management (PAM) and endpoint elevation tools solve this by letting employees request temporary administrator rights for a single installation. The request gets logged, the access is scoped to just that task, and it’s automatically revoked once it’s done — no standing admin account, no shared password, and no manual back-and-forth with IT for routine requests. If you’re managing more than a few machines, ask your IT provider whether they use a tool like this. It’s usually the difference between “we know this is a good idea” and actually being able to enforce it consistently.
Who Should Actually Have Administrator Access?
Administrator access should go to the people whose work genuinely requires it. In most businesses, that’s a short list:
- Internal IT staff
- Your IT provider
- A specific technical employee approved for that role
- A software specialist responsible for one particular system
That list doesn’t include business owners by default. Owning the company doesn’t require permanent administrator access to every machine in the building — owners should be on standard accounts for everyday work like everyone else.
Your IT provider should maintain a managed administrator account so they can support every device, with that password protected and never shared with employees. And one detail that trips a lot of businesses up: don’t reuse the same local administrator password across every computer. If that password leaks from a single device, it works everywhere. Each machine should have a unique administrator password, or be managed through a service that rotates and controls those passwords for you.
How to Remove Administrator Access Without Breaking Anything
Don’t strip every administrator account at once. Someone still needs a reliable way to manage and repair each computer while you make this change.
1. Audit Who Currently Has Admin Access
Check the local Administrators group on every Windows machine and the administrator users on every Mac. Don’t skip old accounts, shared accounts, vendor accounts, or anything left over from the original setup.
2. Confirm the Reason for Each One
Ask what task actually requires that access. There should be a clear, current business reason behind every account that keeps its permissions. Needing to update one program every so often isn’t a reason to keep standing access.
3. Make Sure IT Has a Working Admin Account First
Before removing anyone’s permissions, confirm your IT team or provider can sign into a protected administrator account on every device. Test it. This is what keeps your business from accidentally locking itself out of its own computers.
4. Test Critical Software
Check the programs each employee actually needs for their job, and confirm they open, update, and run correctly under a standard account. Anything that fails should be reviewed and fixed before you remove access permanently.
5. Switch the Account Type
Once a computer has been checked, remove the employee from the local administrator group or change the account type outright. Have them sign out and back in so the new permissions actually take effect.
6. Give Employees One Clear Path to Request Installs
Set up a single, obvious way for staff to request software or setting changes. Tell them exactly what to include — the program name, why it’s needed, and a link to the official download page.
7. Revisit Access Whenever Roles Change
Review administrator access whenever someone changes roles, takes on new responsibilities, or leaves the company. Fold it into your regular access reviews going forward, not just as a one-time cleanup.
Frequently Asked Questions
Can a standard user install software at all?
It depends on the program. Applications that install entirely within the user’s own profile often don’t need administrator approval. Anything that touches protected system files, installs drivers, or adds background services usually does.
Will removing admin access stop employees from working normally?
Standard business applications should keep working exactly as before. The one place to be careful is specialist or older software — test those first, before rolling the change out across every computer.
Does removing admin access stop malware on its own?
It significantly limits what a lot of malicious software can do, but it’s not a complete defense by itself. You still need supported software, current security patches, endpoint protection, email security, MFA, and backups that are actually tested.
Should the business owner keep administrator access?
Use a standard account for day-to-day work, the same as everyone else. If there’s an approved task that genuinely needs elevated access, use a separate account for it and keep that password protected.
Is local administrator access the same as being a Microsoft 365 administrator?
No, and this trips people up often. Local administrator access controls one computer. Microsoft 365 administrator roles can control cloud users, email, files, security settings, and other parts of your company’s Microsoft environment. Both need to be limited and reviewed — but separately.
Sources and Further Reading
- Microsoft Learn: Local Accounts
- Microsoft Learn: How User Account Control Works
- Apple Support: Set Up Your Mac to Be Secure
- CISA: StopRansomware Guide
- Australian Cyber Security Centre: Essential Eight
Not sure who has administrator access on your business computers, or whether they actually need it? Ask your IT provider to run a review. And if you don’t have one yet, reach out to us — we’re happy to help you sort it out.