Summary: Employees should use standard accounts for email, web browsing, and everyday work. Administrator access should be limited to approved IT tasks and protected with a separate account.
Administrator access often starts with one request. An employee needs to install a printer, update a specialist program, or change a setting on their computer.
Giving them administrator access gets the job done. The problem is that the access usually stays after the request has been completed.
From then on, the employee can approve other software installations and make changes that would normally require help from IT. If they install the wrong program or someone takes control of their account, those permissions can also be used to change the computer.
For everyday work, employees should use standard accounts. Administrator access should be kept for tasks that require it.
What administrator access allows someone to do
An administrator has more control over a computer than a standard user.
On Windows, members of the local Administrators group have full control over the resources on that computer. According to Microsoft’s guidance on local accounts, Microsoft recommends limiting the number of users in that group.
Depending on the computer and how it is managed, an administrator may be able to:
Install and remove software
Add drivers for printers and other equipment
Create, change, or remove user accounts
Change system settings
Change permissions on files and folders
Install services that continue running in the background
Make changes to some security settings
Mac computers also have standard and administrator accounts. Apple says administrators can install and remove software, manage other users, and change settings. Apple recommends limiting the number of administrative users and using a standard account when administrator rights aren’t required.
Local administrator access applies to the computer itself. It is different from Microsoft 365, Google Workspace, network, or server administrator access. Those accounts may control email, cloud files, user accounts, or several systems at once.
An employee may have local administrator access to a laptop without being a Microsoft 365 administrator. Both types of access should be reviewed separately.
Why permanent administrator access increases your risk
Software launched by an employee normally starts with the permissions available to that employee.
If the software asks for administrator approval and the employee approves it, the program may be able to install system components, change settings, or affect information belonging to other users.
That matters when someone downloads a fake installer, opens a harmful attachment, or installs software from an untrusted website. The employee may think they are approving a legitimate update while giving the program permission to change the computer.
Windows uses User Account Control to ask for approval before many administrative changes. An employee signed in with an administrator account can approve the request themselves. A standard user is normally asked for credentials belonging to an administrator.
Standard accounts also reduce the number of people who can change security settings without review. Employees cannot approve every installation themselves, so IT has a chance to check the program, where it came from, and what permissions it needs.
A standard account can still be used for normal business tasks, including:
Reading and sending email
Using a web browser
Working in Microsoft 365 or Google Workspace
Accessing approved business applications
Joining online meetings
Printing with an installed printer
Opening and saving files
Changing personal settings that do not affect other users
Some applications can be installed for one user without administrator access. Others need administrator approval because they add drivers, services, or files in protected parts of the computer.
An employee should not receive permanent administrator access because one program needs an update. IT can approve the installation, deploy the update remotely, or use a separate administrator account for that task.
Older business applications sometimes expect the user to have administrator rights. Test those applications before changing account permissions. In many cases, IT can update the application, adjust its configuration, or grant access to the specific folders it needs.
How to manage software installations without permanent administrator access
Staff can still get software installed and updated without keeping administrator rights.
Let IT install approved software
Your IT team or provider can install the program remotely. This also gives them a chance to confirm that the installer came from the software company and that the requested version is supported.
Use managed software deployment
Businesses with managed computers can send approved applications and updates to employees without asking each person to run an installer. The available method will depend on the operating system and device management service.
Approve individual requests
An employee can contact IT when an installation requires administrator approval. IT can review the request and enter the required credentials without giving the password to the employee.
Provide time-limited administrator access
Some roles need to install or test software as part of their work. Give those employees a separate administrator account that is enabled only for the approved task, then disable it afterward.
Create a separate administrator account
Employees who regularly perform approved technical work can have a separate administrator account. They should continue using their standard account for email, browsing, and normal work.
The administrator account should only be used when a task requires the extra permissions.
Who should have administrator access?
Administrator access should be limited to people whose work requires it.
That may include:
Your internal IT staff
Your IT provider
An approved technical employee
A software specialist responsible for a particular system
Business owners should use standard accounts for their normal work too. Ownership of the company does not require permanent administrator access to every computer.
Your IT provider should keep a managed administrator account so they can support each device. The password should be protected and should not be shared with employees.
Using the same local administrator password on every computer creates another problem. If that password is stolen from one device, it may work on the others. Each computer should have a unique administrator password or use a management service that controls those passwords.
How to remove administrator access safely
Do not remove every administrator account at once. Someone still needs a working way to manage and repair each computer.
1. Check which employees have administrator access
Review the local Administrators group on every Windows computer and the administrator users on every Mac. Include old accounts, shared accounts, vendor accounts, and accounts created during the original setup.
2. Confirm why each person has it
Ask what tasks require administrator access. A clear business need should exist for every account that keeps the permission.
Needing to update one application occasionally does not require permanent access.
3. Make sure IT has a working administrator account
Confirm that your IT team or provider can sign in with a protected administrator account before removing permissions from employees.
Test the account on each device. This prevents the business from being locked out of its own computers.
4. Test important software
Check the programs each employee needs for their job. Confirm that they open, update, and work correctly when the employee uses a standard account.
Any application that fails should be reviewed before administrator access is removed permanently.
5. Change the employee’s account to a standard account
Once the computer has been checked, remove the employee from the local administrator group or change the account type.
The employee should then sign out and sign back in so the new permissions apply correctly.
6. Tell staff how to request an installation
Give employees one place to contact when they need software installed or a setting changed. Explain what information to include, such as the program name, the reason it is needed, and the official download page.
7. Review access when roles change
Check administrator access when an employee changes jobs, receives new responsibilities, or leaves the business. Include it in your regular access reviews as well.
Frequently asked questions
Can a standard user install software?
It depends on the software. Programs that only install inside the employee’s user profile may not need administrator approval. Software that changes protected system files, installs drivers, or adds background services usually requires administrator credentials.
Will removing administrator access stop employees from working?
Normal business applications should continue working. Test specialist and older applications before making the change across every computer.
Does removing administrator access stop malware?
It reduces what many harmful programs can change, but it does not prevent every attack. You still need supported software, security updates, endpoint protection, email security, MFA, and tested backups.
Should the business owner keep administrator access?
Use a standard account for everyday work. If you need administrator access for an approved task, use a separate account and keep its password protected.
Is local administrator access the same as Microsoft 365 administrator access?
No. Local administrator access controls one computer. Microsoft 365 administrator roles can control cloud users, email, files, security settings, and other parts of the company’s Microsoft environment.
If you are not sure who has administrator access or whether your employees need it, ask your IT provider to review the accounts on your business computers.
And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it out.
Summary: Most IT problems don't appear out of nowhere. Backups quietly stop running, updates sit unfinished for weeks, and old staff accounts stay switched on for months. A short check once a month catches these while they're still cheap to fix. This post covers the six things to look at.
Most owners only look at their IT when something has already gone wrong. A file won't open, a laptop won't start, or an invoice gets paid into a scammer's account. Fixing it at that point costs more than preventing it would have.
Almost none of it happens without warning. The backup that fails when you finally need it had been failing for weeks. The account a scammer used belonged to someone who left last year. Thirty minutes a month is usually enough to catch that kind of thing.
Why a monthly look is worth the time
Verizon's 2026 Data Breach Investigations Report found that 31% of breaches started with attackers exploiting software that hadn't been patched. That makes unpatched software the most common way in, ahead of stolen passwords. The same report found the median time to fully fix a known problem has risen to 43 days.
Most attacks use a problem that was already known, with a fix already available. Nobody had installed it yet.
The check
1. Updates
Check whether Windows updates are installing on your computers, or sitting at "restart required" week after week. Do the same for phones and for the software you use most, like your browser and your accounting app. If people keep clicking "remind me later," that's something to fix.
2. Backups
Open your backup tool and look at the last few runs. You want recent successful backups, not a list of errors. Then check when anyone last restored a file from it. If it's never been tested, you don't know whether it works.
3. Who has access
Pull up the list of user accounts in Microsoft 365 or Google Workspace and read through it. Every name should be someone who still works for you. Look for people who left, contractors who finished months ago, and shared logins like "office" or "admin" that several people use. Switch off anything you don't need.
Look at what's connected to your systems. If there's a laptop or phone you don't recognize, find out whose it is. While you're there, check that laptops are encrypted and that any phone with company email on it has a passcode or fingerprint lock.
6. Subscriptions and licenses
Open your billing page and read what you're paying for. Businesses regularly pay for licenses belonging to people who left, or for two tools that do the same job. It's also how you find software somebody signed up for without telling anyone.
Make it a routine
Put it in the calendar on a fixed day, like the first Monday of the month, and give it to the same person each time. That's you or whoever handles the admin side.
Keep a running note of what you checked and what you found. After a few months you'll see whether the same problem keeps coming back. If it does, it needs fixing properly instead of clearing each time.
Thirty minutes only works if you don't stop to fix things along the way. Write down what you find and deal with it afterward.
Who fixes what
Most of it is small, like a laptop that needs restarting, a license to cancel, or an account to switch off. Handle those yourself.
Send the rest to your IT provider: backups that keep failing, MFA that won't turn on for someone, a device nobody recognizes, or updates that fail on the same machine every month. Those usually mean there's a bigger problem behind them.
What this check doesn't do
It isn't monitoring. A good IT provider has tools watching your systems all day and flagging things you'd never spot from a monthly glance.
The check covers what those tools can't know. You know who left, which subscriptions you approved, and whose laptop is whose.
Frequently asked questions
How often should a small business check its IT?
Once a month is enough for this list. Backups are worth a quick look more often if losing a day's work would seriously hurt, since that's the item most likely to fail quietly.
Who should do it?
You or whoever runs the admin side of the business. Most of the list needs no technical skill, just someone who knows who works there and what the business pays for.
What if I don't know where to find any of this?
Ask your IT provider to walk you through it once and write down where each thing lives. Many will also send you a monthly summary covering most of it.
Isn't this my IT provider's job?
They handle the monitoring, the patching, and the fixing. The check is the part that depends on knowing your business, like who left last month or which subscription nobody approved.
If I only have ten minutes, what matters most?
Backups and updates. Without working backups you can lose everything you've stored, and unpatched software is now the most common way attackers get in.
Does this apply if everything we use is in the cloud?
Yes. Cloud tools still need updated devices, working backups, MFA switched on, and access lists that match who actually works for you.
Sources and further reading
Verizon 2026 Data Breach Investigations Report — the finding that 31% of breaches start with exploitation of unpatched software, and that the median time to fully fix a known problem is 43 days.
If you'd like a hand setting this up, your IT provider can show you where each of these lives in your systems and take the fixing off your plate. And if you don't have an IT provider, feel free to reach out to us and we'll help you sort it.
Summary: The tools that run your business, like Microsoft 365, your accounting app, or your booking system, are reliable most of the time, but they do go down. When one does, work can stop for hours, and you often can't do anything but wait for the provider to fix it. A simple plan keeps your team working and your customers informed while you wait.
Most of your business probably runs in the cloud now. Email, files, accounting, bookings, payments, it's all online. Then one day a service goes down, and nobody can send an email, open a file, or take a payment.
It doesn't take a hacker for this to happen. In July 2024, a faulty software update from the security company CrowdStrike crashed millions of Windows computers around the world in a few hours. Microsoft estimated it hit 8.5 million devices, grounding flights and stopping work at banks and hospitals.
Outages happen, even to the big names
Microsoft 365 itself has had days where email or Teams stopped working for hours. Internet providers have bad days too, and when yours does, everything online goes with it. Any tool you depend on can go down.
So much of a small business runs on a handful of online services now, and if one goes down, the work that depends on it stops until it's back. Being with a big, well-known provider doesn't protect you from this.
What an outage does to a small business
When a key service goes down, your team can't get to email or files, so work stops. If your payment or booking system is offline, you can't take money or appointments. Customers try to reach you and can't, and you can't reach them either. Staff end up sitting around waiting.
You usually can't fix it yourself. When a big provider has an outage, all you can do is wait for them to sort it out. The goal of a plan is to keep working, and keep customers informed, until they do.
What a simple plan covers
A good plan answers these questions:
Which tools are critical? List the handful of services that would stop the business if they're down, like email, your payment system, or your booking tool. Ignore the ones you could live without for a day, and focus on the few that would halt the work.
How will people keep in touch? Have a backup way to reach staff and customers that doesn't depend on the tool that's down. That might be phone numbers, a group chat on a different app, or text messages.
What do you need reachable offline? Keep a copy of the essentials, like your customer contact list, key phone numbers, and important documents, somewhere you can open if the main system is down. A printout or a copy on a phone is enough.
Who's in charge? Decide who makes the decisions during an outage and who keeps customers updated. When it's clear in advance, people act instead of waiting to be told.
Where do you check, and who do you call? Know where to see whether it's a wider outage, which is usually the provider's status page, and who to call for help, which is usually your IT provider.
What to do the moment an outage hits
Check whether it's just you. Look at the provider's status page, or ask whether anyone else is having the same problem. If it's a wider outage, there's nothing to fix on your end, so stop trying.
Tell your team. Let people know what's down and what to use instead, so nobody wastes an hour rebooting a laptop that was never the problem.
Switch to your backup way to communicate. Move to the phone, text, or another app so the team can still coordinate.
Tell customers if it affects them. If you can't take bookings or payments, say so and tell them when to try again.
Note when it started and what's affected. A couple of lines is enough. It helps you follow up afterward and spot anything that needs fixing once things are back.
A few things that make outages hurt less
Keep key files available offline. With OneDrive or SharePoint, recent files can sync to the device so you can still open them when the service is down. Ask your IT provider to make sure this is set up.
Have a backup way to get online. A mobile hotspot from a phone can get a few key people working again if your main internet drops.
Know your status pages. Bookmark the status page for Microsoft 365 and your other main tools. It's the fastest way to tell whether the problem is them or you.
Keep contacts off the cloud. Have your important phone numbers and contacts somewhere that doesn't need the internet, like a printout or your phone's own contact list.
Ask your IT provider about alerts. Many can set up a warning that tells you about an outage before your customers do.
Keep your plan on one page
Keep this to a single page, somewhere you can reach without your main systems, whether that's printed or in a separate app. Write down your critical tools, your backup way to communicate, where the essentials live, who's in charge, and who to call. Review it once or twice a year so the names and numbers stay current.
Frequently asked questions
Isn't the cloud always available?
No. Cloud services are reliable, but they still have outages, and even the biggest providers go down sometimes. The CrowdStrike outage in 2024 took millions of computers offline in a few hours. It's safer to assume an outage will happen eventually and have a plan for it.
What should a continuity plan include?
The basics: which tools are critical, a backup way to reach staff and customers, where to find essential information if the main system is down, who's in charge during an outage, and who to call for help. One page is enough for most small businesses.
What if the internet itself goes down, not just one app?
Plan for that too. A mobile hotspot from a phone can get key people back online, and a phone call still works when your systems don't. Keep important numbers and contacts somewhere that doesn't need the internet.
How can my team keep working if Microsoft 365 is down?
It depends on the work, but options include using files already saved on a synced device, switching to phone or text to stay in touch, and handling anything urgent on paper until service returns.
How long do outages usually last?
There's no set answer. Some are fixed in minutes, others take most of a day. That's the reason to plan around them, since you can't count on a quick fix and you can't speed it up from your end.
Whose job is this?
Yours, with help from your IT provider. They can tell you which of your tools are most at risk, set up things like synced files and a status-page alert, and help you write a simple plan.
If you're not sure which of your tools would hurt most if they went down, or you'd like help putting a simple plan together, your IT provider can work through it with you. And if you don't have an IT provider, feel free to reach out to us and we'll help you sort it.
Summary: If your business uses Microsoft 365, you have both OneDrive and SharePoint, and files usually end up scattered across them with no clear rule. OneDrive is for your own work, and SharePoint is for files the team shares. Getting this right makes files easier to find, safer when someone leaves, and easier to recover if something goes wrong.
If your business runs on Microsoft 365, you've got two places to store files: OneDrive and SharePoint. Most people are never told the difference, so files end up wherever is easiest, spread across OneDrive, SharePoint, Teams, and the desktop.
That's how you end up with the everyday headaches: a file nobody can find, a document only one person can open, and a scramble to recover someone's work after they leave. The rule for where things should go is simple once you know what each one is for.
What each one is for
OneDrive is your own space. Think of it as the cloud version of the My Documents folder on your computer: your work files, private to you unless you choose to share them. It's the right place for drafts and anything only you need.
SharePoint is the team's space. It's built for files with shared ownership, the documents your team, department, or the whole business works on together. Microsoft's own advice is straightforward: if you're working on something by yourself, save it to OneDrive; if you're working as a team, save it where the team works.
Where Teams fits in
Microsoft Teams confuses this for a lot of people, because it looks like a third place to keep files. In reality, when you upload a file to a Teams channel, it's stored in that team's SharePoint site. The Files tab in Teams is just a view into SharePoint.
So if your team works in Teams, your shared files are already in SharePoint, whether you realized it or not. That's a good thing. It means the files have shared ownership and don't belong to one person's account.
So where should your files live?
Here's the rule that keeps things simple:
If it's your own draft or something only you need, keep it in OneDrive.
If the team needs it, more than one person works on it, or it's a client or project file, put it in SharePoint (or the Teams channel for that work, which is the same thing).
Don't leave important shared files sitting only on someone's desktop or only in their personal OneDrive.
Sharing files the right way
Where a file lives also changes how you share it.
When you share a file from your OneDrive, you're sending people into your personal space, usually with a link tied to your account. That works, but the link depends on you. If you leave, or the file moves, those links can stop working, and whoever relied on them is stuck.
In SharePoint or a Teams channel, the right people already have access, because the files belong to the team rather than to you. You can point a colleague to the folder and they're in, with no one-off links to manage.
It's also worth sharing a link instead of emailing a copy. When everyone opens the same file in OneDrive or SharePoint, they're all looking at the current version, and you avoid ending up with five slightly different copies attached to five different emails.
Why this matters
Putting files in the right place saves you real trouble later.
Take what happens when someone leaves. Their personal OneDrive isn't shared by default, so any important work kept only there can be hard to reach. Microsoft holds a deleted user's OneDrive for 30 days by default and gives their manager access, but that turns into a rush against the clock. Files kept in SharePoint stay with the team no matter who comes or goes.
It also makes files easier to find. When the team's documents live in one shared SharePoint library, people know where to look, instead of hunting through inboxes and personal drives.
And it helps you recover from mistakes. Both OneDrive and SharePoint keep older versions of your files and a recycle bin, so if a document gets overwritten or ransomware scrambles your files, you can roll back to a clean copy instead of starting over.
How to get it right
Put shared work in SharePoint or Teams. Anything the team works on together belongs in a shared library. Keep it out of one person's OneDrive.
Keep OneDrive for your own files. Drafts and personal work are fine there. Just don't let it become the only home for something the team needs.
Get files off local desktops. A file saved only on a laptop isn't backed up, isn't shared, and is gone if the laptop is lost. Move important files into OneDrive or SharePoint. You can still work from your computer the way you always have: the OneDrive app keeps a copy on the device for offline use and saves your changes to the cloud automatically.
Agree where things go. A simple, shared rule, like "client files live in the client's SharePoint folder," saves endless confusion later.
Use version history when you need it. If a file gets changed or deleted by mistake, you or your IT provider can restore an earlier version rather than redoing the work.
Frequently asked questions
What's the difference between OneDrive and SharePoint in one line?
OneDrive is for your own work files. SharePoint is for files your team shares.
Where do files in a Teams channel get stored?
In SharePoint. Every team has a SharePoint site behind it, and the Files tab in a channel is a view into that site. Uploading a file to Teams is the same as putting it in SharePoint.
Should I keep work files on my computer's desktop?
Try not to, for anything important. A file only on your desktop isn't shared or backed up, and it's gone if the device is lost or breaks. Save it to OneDrive or SharePoint instead, where it's protected and reachable.
What happens to files in someone's OneDrive when they leave?
By default, Microsoft keeps a deleted user's OneDrive for 30 days and gives their manager access, and that window can be extended if it's set up in advance. It's recoverable, but it's far easier if shared work was in SharePoint to begin with.
Can I get back a file that was deleted or changed by mistake?
Usually, yes. OneDrive and SharePoint both keep a recycle bin and older versions of files, so you can restore a deleted file or roll back to an earlier version. Your IT provider can help if you can't find it.
If your files are scattered and you're not sure what should sit where, your IT provider can set up a simple structure in SharePoint and move things into the right place, so files are easy to find and safe when people come and go. And if you don't have an IT provider, feel free to reach out to us and we'll help you sort it.