Picture a helpful IT technician who is logged in as a domain administrator all day. That same account opens email, clicks links, browses the web and joins video calls. One convincing phishing message later, an attacker is not just inside a mailbox; they hold the keys to every computer, server and cloud service in the organization.
Splitting everyday and administrative accounts is one of the least expensive and most effective security controls available. It requires some discipline, but not much money.
Attackers love administrator credentials because they unlock everything at once. When an admin account is used for routine tasks, it is exposed to the same risks as any user account: phishing, malicious downloads, infected websites and stolen browser sessions.
The standard approach is least privilege, a principle reflected in CISA guidance and in the access control expectations of the HIPAA Security Rule. People should have only the access they need for the task they are performing. For an IT administrator, that means one identity for reading email and doing normal work, and a separate one for administration.
Each person who performs administrative work gets:
A daily account with standard user rights, used for email, web browsing, chat, documents and meetings.
A privileged account used only to perform administrative tasks, with no mailbox and no routine internet use.
The privileged account should never be used to read email, click links or browse the web. It is used for the specific job, then closed.
In larger environments, split administration further. One account manages workstations and users, another manages servers, and a more restricted one administers the identity system itself. Smaller organizations can start with two and add tiers as they grow.
List your admins. Include employees, managed service provider staff and any vendors with administrator access.
Create the privileged accounts. Use a clear naming convention so they are easy to identify and audit, such as a prefix or suffix on the person's name.
Remove admin rights from the daily accounts. This is the step people skip. The goal is that a compromised daily account can do limited harm.
Do not license privileged accounts for email. Without a mailbox, there is nothing to phish.
Require multi-factor authentication on every privileged account, ideally with a phishing-resistant method such as a security key.
Store privileged passwords in a vault and make them long and unique.
Restrict where they can sign in. Use a dedicated administrative workstation or jump server where practical, and block privileged log-ins on ordinary desktops.
The same rule applies to email and cloud platforms. Global or tenant administrator roles should be assigned to dedicated accounts, not to someone's everyday mailbox. Keep a small number of emergency access accounts with very long passwords, held by named leaders and monitored for any sign-in, in case normal admin access fails.
"It's inconvenient." True, for a few seconds per task. Compare that to the cost of a compromised domain.
"We're too small." Small organizations are targeted often precisely because they have less defense. Two accounts per administrator is within reach of any team.
"Our vendor needs admin access." Give each vendor technician a named account, with multi-factor authentication, and disable it when work ends.
Turn on logging for privileged sign-ins and set alerts for unusual activity, such as an admin account logging in at an odd hour. Review the list of privileged accounts each quarter and remove anyone who no longer needs access. Shared "admin" accounts should be retired, since they cannot show who did what.
Rules like this work when leadership supports them. Tell staff why: the aim is not to distrust people but to protect them. When an administrator's daily account is phished, the damage should stay small.
UnityCare IT helps healthcare organizations design and implement split-account models, including the cloud and vendor access pieces, without disrupting day-to-day support.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172