Separate Admin Accounts: Why IT Should Not Read Email as Admin

Picture a helpful IT technician who is logged in as a domain administrator all day. That same account opens email, clicks links, browses the web and joins video calls. One convincing phishing message later, an attacker is not just inside a mailbox; they hold the keys to every computer, server and cloud service in the organization.

Splitting everyday and administrative accounts is one of the least expensive and most effective security controls available. It requires some discipline, but not much money.

The problem with one account for everything

Attackers love administrator credentials because they unlock everything at once. When an admin account is used for routine tasks, it is exposed to the same risks as any user account: phishing, malicious downloads, infected websites and stolen browser sessions.

The standard approach is least privilege, a principle reflected in CISA guidance and in the access control expectations of the HIPAA Security Rule. People should have only the access they need for the task they are performing. For an IT administrator, that means one identity for reading email and doing normal work, and a separate one for administration.

The two-account model

Each person who performs administrative work gets:

A daily account with standard user rights, used for email, web browsing, chat, documents and meetings.

A privileged account used only to perform administrative tasks, with no mailbox and no routine internet use.

The privileged account should never be used to read email, click links or browse the web. It is used for the specific job, then closed.

Consider a third tier

In larger environments, split administration further. One account manages workstations and users, another manages servers, and a more restricted one administers the identity system itself. Smaller organizations can start with two and add tiers as they grow.

How to set it up

List your admins. Include employees, managed service provider staff and any vendors with administrator access.

Create the privileged accounts. Use a clear naming convention so they are easy to identify and audit, such as a prefix or suffix on the person's name.

Remove admin rights from the daily accounts. This is the step people skip. The goal is that a compromised daily account can do limited harm.

Do not license privileged accounts for email. Without a mailbox, there is nothing to phish.

Require multi-factor authentication on every privileged account, ideally with a phishing-resistant method such as a security key.

Store privileged passwords in a vault and make them long and unique.

Restrict where they can sign in. Use a dedicated administrative workstation or jump server where practical, and block privileged log-ins on ordinary desktops.

Handle the cloud, too

The same rule applies to email and cloud platforms. Global or tenant administrator roles should be assigned to dedicated accounts, not to someone's everyday mailbox. Keep a small number of emergency access accounts with very long passwords, held by named leaders and monitored for any sign-in, in case normal admin access fails.

Anticipate objections

"It's inconvenient." True, for a few seconds per task. Compare that to the cost of a compromised domain.

"We're too small." Small organizations are targeted often precisely because they have less defense. Two accounts per administrator is within reach of any team.

"Our vendor needs admin access." Give each vendor technician a named account, with multi-factor authentication, and disable it when work ends.

Monitor and review

Turn on logging for privileged sign-ins and set alerts for unusual activity, such as an admin account logging in at an odd hour. Review the list of privileged accounts each quarter and remove anyone who no longer needs access. Shared "admin" accounts should be retired, since they cannot show who did what.

Make it a habit

Rules like this work when leadership supports them. Tell staff why: the aim is not to distrust people but to protect them. When an administrator's daily account is phished, the damage should stay small.

UnityCare IT helps healthcare organizations design and implement split-account models, including the cloud and vendor access pieces, without disrupting day-to-day support.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172