How to Take Back Admin Rights Before Ransomware Uses Them

TL;DR: Most small businesses never chose to make employees administrators on their computers. A Microsoft 365 default did it for them. Administrator access lets one bad click install software, change security settings, and switch off protection. Give staff standard accounts for daily work, keep admin rights in a separate managed account, and change the default so new PCs stop adding admins. It costs little and closes a door attackers count on.

Administrator access on employee computers is one of those risks most Louisville business leaders never signed off on. Nobody held a meeting and voted to give the front desk full control of a company laptop. It happened anyway.

Sometimes it starts with a favor. Someone needs a printer installed or an accounting program updated, so they get admin rights for the afternoon. The afternoon ends and the rights stay.

More often, nobody did anything at all. If your PCs are joined to Microsoft 365 the usual way, Microsoft’s own documentation says the person who first signed in to set up each computer became an administrator on it. That’s the default. Few business leaders know it’s a setting, so few ever change it.

After 40 years in technology, I can’t name many fixes cheaper than this one. It needs no new hardware. It does take a decision, and a plan so work doesn’t grind to a halt.

What Does Administrator Access Let Someone Do?

Administrator access gives a user full control of that computer. An admin can install or remove any program, change security settings, turn off protection software, and reach files that belong to other users on the machine. A standard account can run approved programs and do everyday work, and nothing more.

The part most leaders miss is that software inherits the rights of whoever runs it. If someone in accounting is an admin and opens a fake invoice, that malware can run with the same control. Windows may ask “Do you want to allow this?” and an admin can click Yes on their own. A standard user gets asked for an administrator’s password instead, and that pause is the whole point.

The Default Nobody Changed

When a Windows PC joins Microsoft Entra ID (the sign-in system behind Microsoft 365), Microsoft adds the person doing the join to that computer’s administrator group by default. So if employees unbox and set up their own laptops, each one becomes an admin on day one.

You can turn this off. In the Entra admin center, under device settings, there’s an option that controls whether the registering user becomes a local administrator. Set it to None, or limit it to a small IT group.

There’s a catch. Changing the setting only affects computers joined after the change. It doesn’t remove anyone who’s already an admin, so every existing PC still needs to be checked and cleaned up one at a time.

I see the result every time we onboard a new client. At nearly every small business I’ve onboarded, employees already had local admin access on their computers.

Many times the business leader knows. They don’t know how to deal with it, or they don’t want to, because of the extra work it puts on whoever manages the computers. That’s often someone doing IT part-time on top of another job.

Why Is Permanent Administrator Access a Security Risk?

Permanent admin rights turn one mistake into full control of the computer. Malware that lands on an admin’s machine can install itself deeply, change settings, and shut off security software. On a standard account, the same malware hits a wall and has to find another way to climb.

Attackers plan around that climb. ESET researchers studied nearly 90 “EDR killers” in March 2026. These are tools ransomware crews use to switch off security software before they lock your files. The pattern was the same across groups: get high privileges first, kill the protection, then run the ransomware. An employee who’s already an admin hands over step one for free.

The numbers agree. BeyondTrust’s 2026 Microsoft Vulnerabilities Report found that elevation of privilege flaws made up 40% of all Microsoft vulnerabilities disclosed in 2025, or 509 out of 1,273. Those are bugs that help an attacker move from limited access to higher access.

Taking away admin rights won’t stop every attack. A standard user can still get phished, and data they can reach can still be stolen. That’s why this sits alongside security awareness training and tested backups, and doesn’t replace them.

How Do Employees Install Software Without Admin Rights?

They ask, and IT installs it. A request goes to your IT team or provider, who checks what the program is and where it came from, then installs it remotely with a managed admin account. Software your team uses every day can be approved ahead of time, so nobody waits on the basics.

The usual objection is that people will be stuck waiting. They will be if nobody’s set up to answer. That’s a support problem, and it’s worth fixing on its own. Handing everyone the keys to avoid a short wait is a bad trade.

If one employee does technical work regularly, give them a second account with admin rights. They use the standard account for email and browsing, and sign in to the admin account only when a task calls for it.

Who Should Have Administrator Access?

Only the people whose job is managing computers: your internal IT staff, if you have them, and your IT provider. Business leaders should use standard accounts for daily work too. Running the company doesn’t mean your email and web browsing should run with full control of the machine.

Each computer still needs one admin account for support, and it shouldn’t share a password with every other PC in the office. If it does, one stolen password opens them all.

Windows has a built-in answer. Windows LAPS automatically manages and backs up the local administrator password on each device, so every PC gets its own password that changes on a schedule. It works with any Microsoft Entra ID license, including the free tier.

What’s New: Windows Administrator Protection

Microsoft is changing how admin accounts work in Windows 11. A feature called Administrator protection began rolling out with the September 2026 update. With it on, an admin has to approve each admin task through Windows Hello (a face scan, fingerprint, or PIN), and the elevated access ends when the task does.

That’s good news for the few people who do need admin rights. It’s off by default for now, so your IT team has to turn it on. And it only makes admin accounts safer to hold. Who should hold them stays the same.

How to Remove Admin Rights Without Locking Yourself Out

Do this in order. Skipping the first step is how businesses get locked out of their own computers.

  1. Confirm a working admin account first. Make sure IT can sign in to every computer with a protected admin account before you remove anyone.
  2. List who’s an admin today. Check the local Administrators group on each Windows PC and the admin users on each Mac.
  3. Change the Microsoft 365 default. Stop new computers from adding the setup user as an admin.
  4. Move employees to standard accounts. Start with a small group, see what breaks, then roll it out to the rest.
  5. Review it when roles change. Check admin access when someone is hired, promoted, or leaves.

This cleanup is a normal part of managed IT services. If you have an IT person on staff, co-managed IT can give them the tools and backup to get it done.

The Bottom Line for Louisville Businesses

Admin rights spread quietly. A default grants them, a favor extends them, and nobody goes back to take them away. The fix is a short list: standard accounts for daily work, one managed admin account per computer, and a changed default so the problem stops growing.

Start with one question this week: who’s an administrator on our computers right now? If nobody can answer with a list, you’ve found your first project.

If you’d like help finding out, schedule an intro call with Z-JAK. We’ll talk through how your computers are set up and where admin rights fit into your wider cybersecurity plan.

Frequently Asked Questions

Does removing administrator access stop malware?

No, but it limits the damage. Malware on a standard account can’t easily install itself across the system or turn off security software. It can still reach whatever files that user can open, so you still need security software, training, and backups.

Should business leaders have administrator access?

Not on the account used for daily work. A leader’s account usually reaches the most sensitive data in the company, so it’s the last one that should run with full control. If you need admin rights now and then, use a separate admin account and sign in to it only for those tasks.

How do I check who has admin rights on a Windows computer?

Open Computer Management, go to Local Users and Groups, and look at the Administrators group. Anyone listed there has full control of that PC. Your IT provider can run this check across every computer at once and give you a single list.

Will removing admin rights slow my employees down?

A little at first, while missing software gets installed. After that, the main change is that requests for new software go to IT. How long those take depends on how responsive your IT support is, so ask about that before you start.

Do Macs have the same problem?

Yes. Macs have standard and administrator accounts too, and the same rule applies. Use a standard account for daily work and keep admin rights in a separate, managed account.

Find Out Who Has the Keys

You can’t fix admin rights you don’t know about. If you want a second set of eyes on how your computers and Microsoft 365 are set up, reach out to our Louisville team and we’ll start with a conversation.