How should elevated accounts be managed?

Each administrator must have a personal account for daily tasks and a separate one for administration. Privileges should be limited to the necessary role, protected with phishing-resistant MFA, and reviewed periodically. It is also advisable to maintain controlled and monitored emergency access.

Risks to review

  • Use a global administrator account for email and daily browsing.
  • Share one privileged account among technicians or suppliers.
  • Keep permissions for people who changed roles or left the company.
  • Rely on a single administrator, phone or recovery method.

Safe recommendations

  1. Assign individual administrative accounts and prohibit their use for daily work.
  2. Give the least privileged role that allows each task to be performed.
  3. Protect critical accounts with security keys, passkeys, or other phishing-resistant MFA.
  4. Maintain two emergency accesses guarded, alerted and tested.
  5. Review roles, providers, sessions and administrative activity monthly.
  6. Remove permissions immediately during leave, role changes, or end of contracts.

When to seek specialized help

  • It is not known how many administrative accounts exist or who uses them.
  • Only one person can recover service or change security.
  • There is unexpected administrative activity or changes without identified responsible party.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.