When assigning permissions to users throughout any organization, best practice is to always assign only the permissions that are absolutely necessary. In accordance with this principle, we always recommend that users use an account on their PC that does not have administrator permissions unless there is a strong business justification.
When evaluating our call history, the vast majority of virus infections, computer slowness, and operating system issues are a direct result of a user having administrator access. If your business decides to allow users administrator access to their machines as a policy, it will cause your total technology costs to rise on average (e.g. fixing computer issues, employee downtime, data loss from virus infections). It is important to ensure that the increased potential cost is justified by a necessary and legitimate business need.
Administrator accounts on a computer allow the user to install software, make any change to the system settings, and override local folder permissions. Anytime a user has or has access to an administrator account any of the below is possible:
- Unauthorized software can be installed on the computer leading to non-work activities and computer slowdowns.
- Users can intentionally or unintentionally execute a malicious program leading to infections that could potentially span many PCs. These are often undetectable by anti-virus programs (frequently because the user specifically allows them to execute!).
- If multiple users use a single PC, the administrator account can be used to access data in other user profiles.
- Operating system settings can be changed intentionally or unintentionally causing potentially unfavorable consequences.
Below are three operating scenarios for a mythical user “John Doe”:
User JDoe is assigned limited (“user”) permissions.
Pros | Cons |
|
|
User JDoe is assigned a limited user account for day to day work, but also given access to a separate local administrator account that they can use when needed.
Pros | Cons |
|
|
User JDoe is assigned an ‘administrator’ account which is used on a daily basis.
Pros | Cons |
|
|