How should elevated accounts be managed?
Each administrator must have a personal account for daily tasks and a separate one for administration. Privileges should be limited to the necessary role, protected with phishing-resistant MFA, and reviewed periodically. It is also advisable to maintain controlled and monitored emergency access.
Risks to review
- Use a global administrator account for email and daily browsing.
- Share one privileged account among technicians or suppliers.
- Keep permissions for people who changed roles or left the company.
- Rely on a single administrator, phone or recovery method.
Safe recommendations
- Assign individual administrative accounts and prohibit their use for daily work.
- Give the least privileged role that allows each task to be performed.
- Protect critical accounts with security keys, passkeys, or other phishing-resistant MFA.
- Maintain two emergency accesses guarded, alerted and tested.
- Review roles, providers, sessions and administrative activity monthly.
- Remove permissions immediately during leave, role changes, or end of contracts.
When to seek specialized help
- It is not known how many administrative accounts exist or who uses them.
- Only one person can recover service or change security.
- There is unexpected administrative activity or changes without identified responsible party.
Reference sources
These public sources provide general good-practice guidance. They do not replace an assessment of your environment.

