Cyber Essentials Admin Account Requirements in the UK

17 August 2026

Learn the exact admin account rules for Cyber Essentials in 2026. We cover separation, passwords, MFA, and avoiding common assessment failures.

Why Admin Accounts Are a Key Cyber Essentials Control

In the Cyber Essentials scheme, the management of privileged administrative accounts is a core security control. This is because attackers often target admin accounts to gain full control of your systems, disable security software, and steal sensitive data. The UK's National Cyber Security Centre (NCSC) repeatedly highlights admin account compromise as a major route into business networks. Cyber Essentials was designed to address this by forcing organisations to implement basic but effective measures. By restricting who has admin rights and how those rights are used, you dramatically reduce the impact of a successful phishing attack or password breach. For UK businesses seeking certification, demonstrating proper admin account management is non-negotiable and is one of the most scrutinised areas during assessment.

The Core Rule: Separate Admin Accounts from Daily Use

The fundamental requirement is that administrative accounts must be separate from the accounts you use for everyday work. This means your day-to-day user account should not have admin rights, and your admin account should not be used for email, web browsing, or general productivity tasks. Why? Because if an admin account accesses a malicious link or attachment, the attacker inherits admin privileges. Under Cyber Essentials, you must maintain at least one separate privileged account per admin user, and that account must only be used for administrative tasks such as installing software, managing users, or changing system settings. This separation significantly reduces the chance of malware gaining elevated access. It also ensures that a compromise of your standard account doesn't immediately lead to full network control.

Password and Authentication Standards for Admin Accounts

Cyber Essentials requires admin accounts to be protected by strong authentication. For passwords, this typically means a 14-character passphrase that is unique and not reused elsewhere. Passwords must be changed if compromised or if the user leaves. Additionally, while multi-factor authentication (MFA) is mandatory for all internet-facing services, the NCSC recommends MFA for admin accounts as well. In practice, your certified assessor will expect to see MFA applied to admin accounts wherever feasible—especially if they can access cloud portals or remote access tools. For local admin accounts, at minimum, ensure they have a long, complex password and store them securely using a password manager or Windows LAPS. Avoid predictable passwords like 'admin123' or using the same password across multiple machines.

Implementing Admin Controls in Practice

To meet Cyber Essentials admin account requirements, start by auditing all existing accounts to identify who has admin rights. Then, create a distinct admin account for each person who genuinely needs those rights. Remove admin privileges from standard user accounts and disable the default built-in administrator account where possible. For Windows environments, implement Local Administrator Password Solution (LAPS) so each machine has a unique local admin password that rotates regularly. Enforce a policy that admin accounts are only used for management tasks—no browsing, no email, no social media. Train employees on why this matters and how to switch between accounts properly. Finally, document your policy clearly; your assessor will ask to see evidence of these controls, so maintain a list of admin users and their justifications.

Common Pitfalls That Cause Cyber Essentials Assessment Failures

Many UK businesses fail their Cyber Essentials assessment due to avoidable admin account mistakes. The most common pitfall is using the same account for both admin and daily work, violating the separation requirement. Another frequent issue is sharing admin passwords among staff, which undermines accountability and is not permitted. Also, forgetting to disable the built-in administrator account or leaving local admin passwords blank on workstations is a red flag. And, not applying MFA to admin accounts for cloud services such as Microsoft 365 is another breach. Finally, failing to document your admin account policies or not conducting regular user access reviews can lead to failure. Prepare by conducting a self-assessment, removing unnecessary admin rights, and ensuring your admin accounts are fully compliant before submission.

FAQ

Not every user. Only employees who regularly perform administrative tasks should have an admin account. For others, a standard user account is sufficient and is actually required. If a user needs temporary admin access, it should be granted through a separate elevated session, not by giving permanent admin rights to their standard account.

Latest guides