How do I secure admin accounts and remote access?

Cut your admin accounts down to one or two people and make sure each uses two-step sign-in. Then turn off Remote Desktop, screen sharing and remote-control tools nobody uses, and turn on two-step sign-in for any you keep, including a VPN. Keep dated screenshots of the admin list and the remote access settings.
An admin account, or privileged account, can change settings for everyone. Remote access is any way into your computers from somewhere else.
Check if you already have it
- Admins: in Google Workspace, filter your user list by Admin role. In Microsoft 365, open Roles, Role assignments, Global Administrator. You want one or two names, each with two-step sign-in.
- Remote access on Windows: Settings, System, Remote Desktop should be Off unless someone uses it.
- Remote access on a Mac: System Settings, General, Sharing. Screen Sharing, Remote Login and Remote Management should be off unless someone uses them.
- Remote-control tools: look in your installed apps for TeamViewer, AnyDesk, Splashtop or LogMeIn.
- VPN: if you use one to reach the office, ask whoever set it up whether it needs two-step sign-in.
How to set it up
Start with the cloud admin accounts:
Protect your Google Workspace admin accounts with 2-Step Verification
Google Workspace, needs your Google Workspace super admin sign-in
- Sign in at
admin.google.comwith your super admin account. - Go to Directory, then Users, and add the filter Admin role. Write down who has admin access.
- Remove admin access from anyone who doesn't need it: open their name, then Admin roles and privileges, and unassign the role.
- Make sure every remaining admin has turned on 2-Step Verification. Add the 2-step verification enrollment column to check.
- Go to Security, then Authentication, then 2-Step Verification, and confirm Enforcement is on for the unit your admins are in.
- Keep one or two admin accounts only, and use them only for admin work.
How to show it's true: Screenshot the user list filtered to admins with the enrollment and enforcement columns showing on.
- Only one person has admin access and they're leaving: add a second admin before they go, or you may lose control of the account.
Protect your Microsoft 365 admin accounts with two-step sign-in
Microsoft 365, needs a Microsoft 365 Global Administrator sign-in
- Sign in at
admin.microsoft.comwith a Global Administrator account. - Go to Roles, then Role assignments, and open Global Administrator. Write down who is on the list.
- Remove anyone who doesn't need it. Keep two at most.
- Turn on security defaults (see the two-step sign-in steps for Microsoft 365). With them on, every admin must use two-step sign-in each time they sign in.
- Make sure each admin has set up the Microsoft Authenticator app.
How to show it's true: Screenshot the Global Administrator assignment list and the security defaults panel showing Enabled.
- Your tenant uses Conditional Access instead of security defaults: a tech should add a policy that requires two-step sign-in for all admin roles.
Then on each Windows computer:
Close remote access you don't need on Windows, and protect what you keep
Windows, needs an administrator account on each computer
- Open Settings, then System, then Remote Desktop.
- If nobody connects to this computer from elsewhere, set Remote Desktop to Off.
- Open Settings, then Apps, then Installed apps, and look for remote-control tools such as TeamViewer, AnyDesk, Splashtop or LogMeIn.
- Uninstall any that nobody uses.
- For any you keep, sign in to that tool's account online and turn on its two-step sign-in.
- If you use a VPN to reach the office, ask whoever set it up to require two-step sign-in on it.
How to show it's true: Screenshot the Remote Desktop setting and keep a short list of each remote tool you kept, with the date you turned on its two-step sign-in.
- Someone needs Remote Desktop to work from home: don't leave it open to the internet. A tech can set it up behind a VPN or gateway with two-step sign-in.
And on each Mac:
Close remote access you don't need on a Mac, and protect what you keep
Mac, needs an administrator account on each Mac
- Open System Settings, then General, then Sharing.
- If nobody connects to this Mac from elsewhere, turn off Screen Sharing, Remote Login and Remote Management.
- Open the Applications folder and look for remote-control tools such as TeamViewer, AnyDesk, Splashtop or LogMeIn. Delete any that nobody uses.
- For any you keep, sign in to that tool's account online and turn on its two-step sign-in.
How to show it's true: Screenshot the Sharing settings and keep a short list of each remote tool you kept, with the date you turned on its two-step sign-in.
- A tool keeps coming back after you delete it: it may be managed by an IT company. Ask them, or a tech, to remove it.
How to show it's done
Keep dated screenshots of your admin list, the Remote Desktop or Sharing settings on each computer, and a short list of remote tools you kept with the date you turned on their two-step sign-in. File them in your proof folder.
Common questions
Our IT company connects in to fix things. Does that count?
Yes. Ask which tool they use and whether it needs two-step sign-in, and get the answer in writing. How to control outside companies' access covers the rest.
Someone needs Remote Desktop to work from home. What do I do?
Don't leave it open to the internet. A tech can put it behind a VPN or gateway that needs two-step sign-in.
Does turning on MFA for email cover admins too?
In Microsoft 365, security defaults covers admins as well. Remote Desktop and remote tools on your computers are always separate.
Sources
- Canadian Centre for Cyber Security: Managing and controlling administrative privileges (ITSAP.10.094)cyber.gc.ca
- Microsoft Support: How to use Remote Desktopsupport.microsoft.com
- Apple Support: Turn screen sharing on or off on Macsupport.apple.com