01A Technical Detail That Says a Lot About Digital Maturity
In many Swiss SMEs, employees still have administrator rights on their laptop.
The reason is usually pragmatic: installing a printer, adding a business application, configuring a device or solving a problem without having to call on IT support straight away.
For a long time, this approach seemed reasonable. It limited operational constraints and allowed businesses, often with limited IT resources, to gain agility.
But the context has changed.
Digital environments are now more connected, applications more integrated and cyberattacks more professionalised. In this new landscape, the question is no longer simply whether a user needs elevated privileges, but what the consequences could be if those privileges fell into the wrong hands.
02The Problem Is Not the User. The Problem Is What Their Rights Allow
When an employee works with administrator rights, the software they run potentially has the same level of authorisation.
If they click on a malicious link, open an infected attachment or install a compromised program, the malware can then benefit from the same elevated privileges as the user. Implementing Least-Privilege Administrative Models points out that when an administrator unintentionally runs a malicious program, it can act with the same rights as the compromised account. [learn.microsoft.com]
This is not an exceptional scenario.
It is inherent to the way modern operating systems work.
The question, therefore, is not whether or not to trust employees.
The real question is: what actions could malware carry out with the rights currently granted to users?
03Why Cybercriminals Are So Interested in Privileges
Modern attacks no longer aim solely to infect a workstation.
Criminal groups generally seek to gradually extend their access across the entire IT environment.
The user’s workstation is often the entry point.
Privileges then act as an accelerator.
A computer used with extended rights can enable:
- the installation of persistent components;
- changes to system settings;
- access to certain sensitive resources;
- the disabling of local protections;
- the retrieval of additional information.
According to Administrator protection, Microsoft considers administrator privileges to be a significant attack vector, frequently exploited to change system configuration or bypass certain security measures. [learn.microsoft.com]
From this perspective, privilege has become a risk multiplier.
It does not create the attack, but it can amplify its consequences.
04Swiss SMEs Facing a Paradox
Many Swiss businesses have significantly strengthened their security posture in recent years.
- Multi-factor authentication.
- Off-site backups.
- EDR solutions.
- Microsoft 365 protection.
- Employee awareness training.
These investments respond to a real evolution in threats.
Yet some organisations continue to grant local administrator rights widely to all their employees.
This contrast illustrates a paradox frequently observed in SMEs: advanced security tools sometimes coexist with administration practices inherited from the past.
Yet reducing privileges is among the most consistent recommendations of the main international frameworks.
CIS Controls safeguard 5.4 explicitly recommends carrying out everyday activities such as web browsing, email or office work from a non-privileged account, with administrator rights reserved for dedicated accounts. [csf.tools]
05An Unspectacular but Highly Cost-Effective Measure
The value of the principle of least privilege lies in a characteristic that is rare in cybersecurity: its excellent cost-benefit ratio.
Unlike an infrastructure modernisation project or the deployment of a new security solution, implementation often relies more on an organisational decision than on significant investment.
The most common approach is to:
- use a standard account for everyday activities;
- reserve administrator privileges for a separate account;
- grant temporary privilege elevation when necessary.
The principle of least privilege has long been advocated by Microsoft, which presents it as an effective way of limiting the impact of a compromise. [learn.microsoft.com]
For an SME, the approach can often be rolled out quickly while significantly reducing the risk surface.
06What Privilege Management Really Reveals
Beyond the technical aspect, the question of administrator rights often reveals an organisation’s level of digital maturity.
Does a business know:
- which users hold elevated privileges?
- why those privileges were granted to them?
- whether they are still necessary today?
- when they were last reviewed?
These questions tie into broader issues of identity and access management governance.
They are all the more important as SMEs now depend on increasingly interconnected environments: Microsoft 365, cloud applications, collaboration platforms, business tools or artificial intelligence solutions.
In each of these environments, the fundamental question remains the same:
Who has access to what, and with what level of privilege?
07A Shift Already Under Way Among Vendors
The industry itself is moving in this direction.
With Administrator Protection, Microsoft is gradually strengthening the mechanisms that allow users to obtain elevated privileges only when they are genuinely needed and after explicit approval. The aim is to keep users in a non-privileged state most of the time and to limit the opportunities to exploit administrator rights. [learn.microsoft.com]
This approach reflects a broader trend seen in modern security architectures:
- Privileges are becoming temporary.
- Elevations are justified.
- Access is more tightly controlled.
The permanent administrator account is gradually becoming the exception rather than the norm.
08A Question Every Executive Should Ask
SMEs regularly discuss cyber insurance, backups or ransomware protection.
But a much simpler question often deserves to be raised at executive board level:
How many employees currently have administrator rights on their computer?
For many organisations, the answer is either unknown or higher than expected.
And yet it is probably one of the simplest indicators to check in order to assess the organisation’s level of exposure.
09Cybersecurity Also Comes Down to the Details
Cybersecurity is often associated with complex technologies or sophisticated threats.
Yet some of the most effective measures still rest on fundamental principles.
Least privilege is one of them.
- Invisible to users.
- Rarely in the headlines.
- Seldom highlighted in digital transformation projects.
But recommended for years by the leading vendors, cybersecurity agencies and international frameworks. [learn.microsoft.com], [learn.microsoft.com], [csf.tools]
At a time when SMEs are looking to improve their resilience without multiplying investments, privilege management probably remains one of the simplest levers for reducing risk while preserving the flexibility the business needs.
Box: 5 Questions to Ask Your IT Manager
- How many users currently have local administrator rights?
- Are these privileges genuinely necessary for their day-to-day tasks?
- Are administrator accounts separate from user accounts?
- Are the privileges granted reviewed regularly?
- Is a formal least-privilege policy in place?
10Sources
- Implementing Least-Privilege Administrative Models (Microsoft) [learn.microsoft.com]
- Administrator protection (Microsoft) [learn.microsoft.com]
- Identity and Access Management Recommended Best Practices for Administrators (CISA) [cisa.gov]
- Restrict Administrator Privileges to Dedicated Administrator Accounts (CIS Controls v8.1) [csf.tools]
- ANSSI recommendations on privileged access [sns-security.fr]
Do you know who holds administrator rights in your organisation?
AWSMTECH helps you inventory privileges, separate administrative accounts and implement access management based on least privilege.
Talk to an expert



