Cybersecurity & IT Support for Businesses Across NY & PA 

If Your IT Person Left Tomorrow, Would You Still Have IT Admin Access?

Micro Solutions blog graphic titled "IT Admin Access When Your IT Person Leaves

When we sit down with an owner whose organization has one IT person, one of the first questions we ask is this: if your IT person weren’t available tomorrow, could you log in and manage your Microsoft 365 environment, your domain, your firewall, your internet provider account, and your key vendors? The most common answer is “probably.” The next most common is “I think so,” and every so often someone admits they aren’t sure where those passwords would even be.

IT admin access is the set of top-level logins that let someone change settings, add or remove users, reset passwords, and recover a system when something breaks. Your staff can do their jobs every day without it. When it lives with one person, the business can’t change or recover its own systems without them, and most owners don’t find that out until the day they need it.

Key Takeaway

Admin access to every critical system should belong to the business, through accounts and records it controls, so one person leaving, or simply taking a day off, can’t lock you out.

What Happened When One Organization Couldn’t Get Back In

One senior living organization we started working with had just let its internal IT person go. Leadership assumed they’d keep control of their own technology. When they went to make an administrative change, they found that admin access to Microsoft 365, their domain environment, and their firewall was either unavailable or still in the former employee’s hands. Passwords, user permissions, and account recovery methods had all been set up under that one person instead of under the business or a proper admin account.

The onboarding team turned up two more problems. The machine everyone called the server was a workstation-class computer that had never been built or managed like business infrastructure, and there was no proper backup behind it. Before anything else could happen, we had to establish who owned what, recover admin access, verify identities, document what existed, and rebuild control so it sat with the company instead of an individual.

Why Nobody Notices Until Someone Leaves

Day to day, that organization looked fine. Employees could log in and do their work, and leadership could use the tools they needed. Everyday user access was never the problem. Nobody needed IT admin access until a change had to be made or someone got locked out, and by then there was no way to recover.

This usually happens without anyone intending it. A system gets set up under the IT person’s own login because that’s quickest, the recovery email goes to their address, and the verification codes go to their phone. Over a few years, access ends up tied to a person instead of a role. In a role-based setup, admin rights belong to a position the business controls, so they can be handed to someone else when people change.

If nobody at your organization owns IT at all, that’s a different situation, and we’ve written about the accidental IT person separately. This article is for organizations that do have someone in charge of IT and assume that means the business is covered.

What Goes Missing Even When the Departure Is Friendly

Even when there’s no conflict and everyone handles the handoff professionally, we find gaps afterward, mostly because things were never written down. These come up most often.

Passwords and recovery methods

Admin logins for core systems, plus the phone numbers and email addresses that verification codes and reset links go to.

Ownership records

Whose name is on the Microsoft 365 subscription, the domain registration, and the internet service.

Network settings

DNS records, firewall logins and configuration, and network diagrams or floor plans showing where equipment sits.

Vendors and licenses

Logins for vendor portals, software licensing records, and a contact at each provider.

Dates and inventory

Warranty end dates, subscription renewals, and a list of the devices the organization owns.

Backups

The login for the backup platform, what it covers, and the steps to get data back out of it.

Lost logins and ownership records can usually be recovered with enough calls to vendors and enough proof of ownership. The harder gap to close is everything the IT person knew and never documented, because there’s no vendor to call for that. Without a list, you find out what’s missing one emergency at a time.

Could You Get In Tomorrow?

Admin Access Self-Check

Micro Solutions

Go through each one as if your IT person couldn’t be reached today. Check the ones you could handle on your own.

  Microsoft 365. Someone besides your IT person can log in with admin rights.
  Domain registrar. You know which company account owns your domain, and you can log in to it.
  Firewall. A second person has the firewall login, or knows exactly where it’s stored.
  Internet provider. The account is in the organization’s name, with a company contact on file.
  Backups. You could get into the backup system and see when data was last restored.
  Vendors and software. You have logins for the vendor portals and the line-of-business software your team depends on.
  Sign-in codes and resets. Verification codes and password resets for these accounts go somewhere other than one person’s phone or personal email.
  Documentation. There’s a written list of your systems, vendors, and renewal dates, kept somewhere the organization controls.

Reading your results

Every box you couldn’t check, or weren’t sure about, is a place where one person holds the keys. Start with your domain and Microsoft 365. Your domain’s settings tell the internet where to deliver your email and where to find your website, and if your email runs on Microsoft 365, that’s where most of your other accounts send their password resets.

An informal check for your own use, not a security assessment. Nothing here is saved or sent.

What You Can Do This Month Without Hiring Anyone

Your IT person can handle most of these, and none of them requires bringing in a new provider.

Put Ownership in the Company’s Name

Ask that the Microsoft 365 tenant, the domain registrar, and the internet provider account each be registered to a company account and a company email address, such as a shared admin mailbox the business controls. A personal Gmail address or an employee’s own mailbox on these accounts is the first thing to change. For domains, ICANN’s registrant responsibilities put sole responsibility for a domain on whoever is listed as its registrant, so that should be the organization.

Set Up Emergency Admin Accounts

Microsoft calls these emergency access or “break-glass” accounts: admin accounts kept for the moment nobody can sign in the normal way. Microsoft’s guidance on emergency access accounts lists the last administrator leaving the organization as one of the reasons to have them, and recommends creating two or more, not tying them to any one person, and checking them again after a change in IT staff. Keep the credentials somewhere secure that you and one other trusted leader can reach.

Move Recovery Methods Off Personal Devices

For every admin login, check where the verification codes and password-reset emails go. If the answer is one person’s cell phone or personal email, that person is the only way back in when something goes wrong. For admin accounts, CISA’s multifactor authentication guidance recommends phishing-resistant methods such as a security key, which also keeps sign-in from depending on anyone’s personal phone.

Write It Down Somewhere the Business Owns

A SharePoint site or a shared folder works fine. List each system, its vendor and a contact there, license and renewal dates, and basic notes on how the network is set up. Keep passwords themselves in a business-owned password manager, separate from the notes. CISA’s Cyber Essentials guide asks small organizations for the same kind of record: inventories of hardware, software, user accounts, and vendor connections.

Confirm the Backups Restore

Ask your IT person when a file or system was last restored from backup as a test, and add the answer to your documentation. Our post on what makes a backup reliable covers what else to look at.

How to Bring It Up With Your IT Person

Asking for this can feel like a vote of no confidence. Frame it around continuity instead: if your IT person is on vacation or out sick, someone else should be able to get in during an emergency. It also takes pressure off them, since they’re no longer the only person who can fix things.

What We Do in the First Two Weeks

When we take on an organization in this situation, the goal for the first one to two weeks is simple: get admin control back with the business, and make sure nothing has been lost or compromised. That usually includes:

  • Identifying every critical system, then verifying who owns it and who has admin rights
  • Recovering or resetting credentials where needed, and closing or limiting access a former employee still has
  • Setting up emergency admin accounts and turning on multifactor authentication (MFA) and other current security controls
  • Confirming access to Microsoft 365, the domain and DNS, the firewall, the internet provider account, and line-of-business applications
  • Reviewing backups against the 3-2-1 rule in CISA’s data backup guidance: three copies of your data, on two kinds of storage, with one kept off-site
  • Documenting systems, vendors, and contacts in shared documentation the organization owns, usually in SharePoint

We also build a responsibility matrix that spells out which jobs belong to us and which stay with your team. If you still have an IT person, this is where co-managed support fits: we work alongside them, so the organization isn’t depending on one person for everything. Our Remote IT and co-managed IT service includes helpdesk support, day-to-day management of the systems assigned to us, a cybersecurity foundation, and, depending on scope, Microsoft 365 administration and backup management, at a flat rate.

Once control is back where it belongs, we put together a longer-term plan for technology decisions and ownership. For some organizations that means ongoing planning and budgeting through our vCIO service.

Technical review by Conner Long, Senior Solutions Architect.

Next Step

Find Out Who Holds Your Admin Access

If the self-check left you with more question marks than you’d like, see how Remote IT and co-managed support can work around the IT setup you already have.

Common Questions

Frequently Asked Questions

What is a break-glass account?

It’s an administrator account set aside for emergencies and used only when the usual admin logins fail. It isn’t assigned to an employee, it’s protected with strong sign-in security, and it’s tested on a schedule so you know it works before you need it.

Should the business owner have all the admin passwords?

The business needs its own way in: emergency accounts, credentials stored so more than one leader can get to them, and ownership records in the company’s name. The owner rarely has to sign in as an administrator personally.

Does asking for this mean we don’t trust our IT person?

Documented, shared access protects your IT person as much as the organization. When access and changes are written down, nobody has to guess who changed a setting or why, and your IT person isn’t on the hook for every question.

Do we have to replace our IT person to fix this?

No. Your IT person can do most of the steps in this article. If they’re stretched thin, co-managed support adds helpdesk coverage, takes on the systems you hand over to us, and puts a cybersecurity foundation in place under a defined scope, while they keep the work they know best.

To top