Mastodon Mastodon Mastodon Mastodon

Administrator

Updated: · CyberSecureFox Editorial Team

An administrator is a person or account with elevated privileges to configure, maintain and secure computers, networks or applications.

Administrator as a role and as an account

The word has two meanings. A system administrator (sysadmin) is the IT professional who installs, configures, updates and monitors servers, networks, workstations or services. An administrator account is the technical identity with elevated rights: the local Administrator on Windows, root on Linux and macOS, Domain Admin in Active Directory or Global Administrator in a cloud tenant.

Administrator rights allow installing software, changing security settings, reading other users’ data and turning off protection. That is why admin tasks should be done with a separate account, used only when needed.

Why administrators matter for security

Admin credentials are the main goal of most intrusions. Once attackers have them, they can disable antivirus, delete backups and deploy ransomware across the entire network. Common ways to get there are phishing of IT staff, password reuse, stolen session tokens and privilege escalation vulnerabilities. Insider misuse of admin rights is another risk that organisations often underestimate.

Best practices

  • Follow the principle of least privilege: everyday work runs under a standard account, admin rights only when necessary.
  • Protect all admin accounts with phishing-resistant MFA (FIDO2 keys or passkeys).
  • Use privileged access management (PAM), just-in-time elevation and dedicated admin workstations.
  • Log and review all administrative actions; remove admin rights when people change roles or leave.
Synonyms:
system administrator, sysadmin