What are the cyber essentials user and admin account requirements?
What are the Cyber Essentials user and admin account requirements?
Cyber Essentials focuses heavily on how you manage user and administrator accounts, because attackers nearly always try to abuse access rather than smash through firewalls. For a UK business, getting accounts, passwords and privileges under control is one of the most practical ways to reduce cyber risk and to pass the Cyber Essentials assessment without drama.
The UK Cyber Security Group offers Cyber Essentials certification at a low cost through their services, giving smaller organisations an accessible route into formal cyber assurance.
Why accounts matter so much under Cyber Essentials
Cyber Essentials is a UK government-backed scheme that sets out a practical baseline of technical controls for organisations of all sizes. It focuses on five control areas:
- Firewalls and internet gateways
- Secure configuration
- User access control
- Malware protection
- Patch management
User access control is where account requirements live. The scheme expects you to:
- Know who has access to what
- Limit administrator rights strictly
- Remove or change default accounts
- Use strong authentication and sensible password policies
- Review access regularly and disable accounts promptly when people leave
Government surveys consistently show that a large share of cyber incidents in UK organisations involve stolen credentials, phishing or misuse of legitimate access. Many of these incidents would be much harder to pull off if accounts and privileges were tightly managed in line with Cyber Essentials.
The fundamental difference between user and admin accounts
Cyber Essentials makes a clear distinction between:
- Standard user accounts – used for day-to-day tasks like email, office work and accessing business applications.
- Administrator accounts – used to perform system-level changes such as installing software, changing security settings, managing other accounts or accessing central management consoles.
A core expectation is that:
- Staff should operate day-to-day using standard accounts.
- Administrator rights should only be used when strictly necessary, and ideally via separate admin accounts that are not used for email or general browsing.
This separation massively reduces the risk that a successful phishing email or malicious website can exploit administrator-level access and take over a whole device or network.
Core Cyber Essentials requirements for user accounts
Individual, identifiable accounts
Under Cyber Essentials, each person should have their own unique user account. That means:
- No shared logins for general use
- No “team” accounts for everyday work unless there is a very strong justification and additional controls
- Audit trails can be tied back to named individuals
This requirement helps with accountability and incident investigation, and it makes it easier to apply the “least privilege” principle – giving each user only what they genuinely need.
Least privilege access
Standard users should only have access to:
- The systems they need to perform their roles
- The data they are authorised to see
- The functions that are appropriate for their responsibilities
In practice, this means:
- Role-based access where possible (for example, customer service, finance, HR)
- Careful control of who can access sensitive data such as finance, payroll or personal information
- Avoiding blanket access “just in case”
Least privilege is one of the main ideas behind Cyber Essentials: if an attacker compromises a user account, they should be limited in what they can do.
Passwords and authentication
Cyber Essentials expects you to use strong, sensible authentication practices. That includes:
- Using passwords or passphrases that are hard to guess
- Avoiding obvious default passwords and never leaving them unchanged
- Protecting administrator and remote access accounts with additional measures such as multi-factor authentication (MFA) where available
- Limiting, or completely disallowing, the reuse of passwords on different systems or services
The scheme does not prescribe one strict password recipe, but the assessor will expect to see that:
- Default credentials have been changed
- Passwords are not trivially weak
- There is some form of protection against brute-force attempts (for example, account lockout or throttling after several failed logins)
Joiners, movers and leavers
User account management must follow the staff lifecycle:
- Joiners – when someone starts, you create an account with the minimum access they need, based on their role.
- Movers – when roles change, you review and adjust access; you remove permissions that are no longer required.
- Leavers – when someone leaves, you disable or remove their accounts promptly and revoke any remote access, including email on mobile devices.
Cyber Essentials assessors often ask about how you handle leavers, because stale accounts are a common weakness.
Core Cyber Essentials requirements for administrator accounts
Separate admin accounts
One of the strongest expectations is that administrator rights are not used with everyday accounts. Instead, you should:
- Provide separate administrator accounts for IT staff or others who need elevated rights
- Use these admin accounts only when performing administrative tasks
- Avoid using admin accounts to browse the web or open email
This separation reduces the risk that malware runs with full system control if an admin is tricked into clicking something malicious.
Limiting who has admin rights
You should maintain a tight list of who has administrator access. Key points include:
- Only a small, justified group should have admin privileges
- Admin rights should be linked to job roles, not given “just in case”
- Admin access should be reviewed regularly, at least annually, and more often in dynamic environments
Cyber Essentials expects you to be able to show:
- A list of administrator accounts
- Who owns them
- Why those rights are needed
Protecting admin accounts with stronger authentication
Administrator accounts are high-value targets. Good practice under Cyber Essentials is to:
- Protect admin accounts with multi-factor authentication wherever supported (for example, for cloud admin portals, remote management tools and VPNs)
- Use longer, stronger passphrases for admin accounts
- Avoid storing admin credentials in browsers or unsecured password lists
While the basic Cyber Essentials profile does not enforce every detail of advanced identity management, it definitely expects more robust protection for admin accounts than for standard users.
Using admin tools and logging actions
Where possible, you should:
- Perform administration through known, secure tools rather than ad hoc local changes
- Make sure administrative activity is logged so that important changes can be traced and reviewed
This helps with both security monitoring and auditability. If something goes wrong, you can see which account made the change.
Handling shared, generic and service accounts
Not all accounts are neatly tied to a single person. You may have:
- Shared accounts (for example, a kiosk or a shared device)
- Generic accounts (for example, “reception” or “info@…”)
- Service accounts (used by applications and services, not humans)
Cyber Essentials does not ban these outright, but assessors will expect:
- A clear justification for each shared or generic account
- Controls to limit misuse (for example, limited privileges, locked-down desktops, restricted access to sensitive data)
- Careful management of service accounts, including strong and unique credentials
Where possible:
- Avoid using shared accounts for activities that should be attributable to individuals
- Keep service accounts separate from user accounts and limit their scope to specific tasks
If you rely heavily on non-individual accounts, be ready to explain and demonstrate how you manage the risks.
Remote access, cloud services and home working
User and admin accounts rarely live inside just one office any more. Cyber Essentials looks closely at how remote access and cloud services are secured.
Key expectations include:
- Secure remote access – use VPNs or secure gateways, and protect them with strong authentication (ideally MFA)
- Cloud management portals – admin accounts for cloud platforms (for example, email, collaboration suites, CRM) should use MFA and strong access controls
- Home working – where staff use company devices at home, ensure accounts are managed centrally and security policies still apply
If staff access systems from personal devices, this adds complexity. You need to be clear about:
- Whether those devices are in scope for Cyber Essentials
- How you enforce basic controls, such as secure authentication and appropriate use
For admin access from remote locations, the bar is particularly high, because a compromised home machine could give an attacker a direct route into your environment if you are not careful.
Tying this back to certification: key requirements and preparation
What are the key requirements for achieving Cyber Essentials certification?
To answer What are the key requirements for achieving Cyber Essentials certification? in the context of accounts:
- Implement unique user accounts for all staff and avoid shared logins wherever possible
- Separate standard user accounts from administrator accounts
- Apply least privilege across users and systems
- Change default passwords and disable unnecessary default accounts
- Protect important accounts (especially admin and remote access) with strong authentication
- Maintain clear joiner, mover and leaver processes for creating, adjusting and disabling accounts
- Keep records of who has admin rights and why
Alongside those account-specific points, you also need to meet the wider controls around firewalls, secure configuration, malware protection and patching, but user access control is a major pillar.
How can I prepare my small business for Cyber Essentials assessment?
For How can I prepare my small business for Cyber Essentials assessment?, a practical way to get ready is:
- Create a simple list of all systems and services that staff log into (email, file storage, business apps, remote access, cloud platforms)
- For each system, list the types of accounts (user, admin, service) and how they are authenticated
- Identify where staff have more access than they need and reduce it
- Check that default accounts have been changed or disabled
- Verify that ex-staff accounts are fully removed or disabled
- Ensure admin accounts are separate and protected more strongly, especially for cloud and remote management
- Document your processes and be ready to explain them in plain language during the questionnaire or any follow-up checks
If you start from your accounts and access, you will often uncover other issues (for example, outdated systems or unmanaged devices) that you can address at the same time.
Software tools that make compliance easier
What software solutions support compliance with Cyber Essentials standards?
Many organisations ask What software solutions support compliance with Cyber Essentials standards? because they want to automate some of the account and access work.
Helpful tools often include:
- Centralised directory and identity services – for example, cloud identity platforms or on-premises directory services controlling user accounts, groups and authentication
- Single sign-on (SSO) and multi-factor authentication – to secure user and admin logins to cloud services and internal apps
- Endpoint management tools – to enforce policies on devices, including account restrictions, local admin rights and configuration baselines
- Password management tools – to help staff store unique passwords securely and reduce the temptation to reuse them
- Logging and monitoring tools – to track login attempts, admin actions and unusual access patterns
These tools do not automatically give you Cyber Essentials, but they make it far easier to demonstrate that your account-related controls are being applied consistently.
Renewals, providers and consultancy support
Can I renew my Cyber Essentials certification through an online service?
Yes, Can I renew my Cyber Essentials certification through an online service? is a common question, and the short answer is that most businesses do exactly that.
Typical patterns are:
- Annual online self-assessment for the basic level, completed through a secure portal
- Uploading or presenting evidence as requested, particularly where there have been changes since the last assessment
- Using the same provider year on year, or switching if you prefer a different service model
An online route is particularly convenient for small firms and those with distributed teams, as it avoids complex on-site scheduling. The key is to maintain your controls throughout the year rather than treating renewal as a one-off rush.
Which companies provide Cyber Essentials certification services in the UK?
For Which companies provide Cyber Essentials certification services in the UK?, there are a number of certification bodies and service providers accredited to deliver the scheme.
They typically offer:
- Access to the official questionnaire through their assessment platform
- Support and guidance when you are unsure how to answer particular questions
- Optional add-ons such as vulnerability scanning or extended support
The UK Cyber Security Group is one such provider, offering Cyber Essentials certification at a low cost through their services, which is particularly attractive to smaller organisations looking to get certified without heavy overhead.
Which UK-based firms offer Cyber Essentials consultancy services?.
The question Which UK-based firms offer Cyber Essentials consultancy services?. covers a slightly different angle. Beyond certification bodies, many UK consultancies and IT service providers now offer:
- Readiness assessments and gap analysis
- Hands-on support to tidy up user and admin accounts, devices and basic security controls
- Policy drafting and staff awareness sessions tailored to Cyber Essentials
- Ongoing managed services that keep you aligned with the scheme year-round
These firms range from small specialist practices to larger managed security providers. They are especially helpful if you have limited in-house IT or security capability but still need to demonstrate sound account management and other controls.
Practical account checklist aligned with Cyber Essentials
To pull the main account-related requirements into one practical list, consider using the following checklist before you go through the assessment:
- Every employee and regular contractor has a unique user account
- No generic shared accounts are used for normal work, or they are tightly controlled and justified
- Standard user accounts do not have local administrator rights on their devices
- Administrator accounts are separate, used only for admin tasks, and protected with stronger authentication
- Default accounts on devices, routers, firewalls and applications have been disabled or had their credentials changed
- Accounts for staff who have left the organisation are disabled or removed promptly
- Remote access and cloud admin accounts have multi-factor authentication enabled where available
- Access rights are reviewed at regular intervals, and changes are documented
- Service accounts are clearly identified, have minimum required permissions and use strong, unique credentials
- There is a documented process for creating, modifying and disabling accounts, and staff understand their responsibilities
If you can honestly tick these off, you are already a long way towards meeting the Cyber Essentials expectations around user and admin accounts.
Using Cyber Essentials account controls as a stepping stone
Finally, it is worth noting that account and privilege controls introduced for Cyber Essentials often provide a foundation for more advanced security work later on, such as:
- Moving towards more formal identity and access management
- Implementing conditional access policies for cloud services
- Introducing security monitoring that focuses on anomalous account behaviour
- Preparing for higher-level standards and audits that expect robust access control practices
By treating Cyber Essentials user and admin account requirements as the baseline for good operational hygiene, rather than just “what you need to pass”, you get long-term value: fewer preventable incidents, easier audits and more confidence from customers and partners who need to trust your systems.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










