Improve Your IT Security Step 3: Disable Admin Rights

Disable Admin Rights

­
­
­

We continue our series about things you can do to improve your IT security.

In large companies, one of the first things IT departments do to improve security is to remove administrator rights for most users. This restricts the programs that can be installed and the changes that can be made. For this reason it is really good at reducing the risks if someone gets access to the computer. As a result they cannot install malicious software for example.

Up to now, at Technology Tamed, we have not done this as people find it intrusive and irritating and traditionally it moved control from the person who owns the computer to the IT department. Now, however, with the increase in risks from ransomware and other malicious software, we would now recommend you consider it.

Admin Permissions

What Is Admin Rights

A user with full administrative rights has the power to do the following:

  • Install software
  • Change ‘system’ settings
  • Create user accounts
  • Change passwords
  • Take ownership of files
  • Change network settings
Keep Your Computer Secure 300

How These Rights Can Be Used Against You

If a malicious user manages to get access to a computer with admin rights they can:

  • Download and install malicious software
  • Turn off your firewall, antivirus, Windows updates
  • Change the ownership of files so you no longer have access
  • Change passwords
  • Impersonate other logged on users
  • Run exploit tools to gain access to a network
  • Delete critical system files

How To Do This In A Small Organisation

As I have said, removing admin rights is something that is normally done in large companies because they have IT departments. Small companies do not and they don’t want the ‘overhead’ of having to contact an IT consultant every time they want to install software, etc. So how can a small company manage removing admin rights?

  • They can nominate an internal person to put in the administrator password whenever it is asked for. This means that just one person is responsible for your IT security. However, they will need to be interruptable and available when people need admin rights.
  • Or give key users the administrator password. This spreads the work load but increases your risk
  • Or give all users the administrator password. This means everyone could potentially download and run malicious software. It is, however, better than everyone having full administrative rights. As it will reduce the risk of someone outside the organisation from accessing your files and downloading software.

The Technology Tamed Service

We are happy help you with restricting your admin acces. We will:

  • Check user accounts with administrator access
  • Then change administrator access as required
  • Review/disable unnecessary user accounts, such as Guest
  • Change default passwords
  • Also, recommend a password policy – lock accounts after repeated failed logons, set a minimum length.

The Do It Yourself Service

If, however, you would like to give this a go yourself the following the following are really good step-by-step articles. Do be aware that you must have at least one user that has administrator rights.

Reducing admin rights on a Windows 10 computer

Removing admin rights on a Local Server
­

Rebecca Mansbridge
Director
May 2022