Skip to content
CLD-019 Cloud Services

Cloud ServicesCLD-019

What is a cloud administrator?

A cloud administrator is a user or account with elevated authority to manage part of a cloud environment.

That authority may include creating users, changing permissions, resetting passwords, viewing logs, managing devices, configuring security or deleting data.

What this means in practice

Cloud environments often divide administrative powers into separate roles. One administrator may manage users. Another may manage security. Another may control billing or applications. Some roles may allow access to content, while others do not.

The scope of the role matters more than the job title.

An administrator’s activity can create important evidence. They may add a user, grant access, reset credentials, create a sharing link, change retention settings or disable logging. Those actions may explain events that would otherwise appear to be the ordinary user’s activity.

In an organisation, also identify who authorised the action and whether the administrator was acting under a support request, routine process or emergency response.

A cloud administrator may be an employee, contractor, managed-service provider or automated account. The named administrator account may itself be shared or compromised.

What this does not show on its own

The dangerous assumption is that an administrator can automatically see or do everything.

Administrators may also impersonate or access another user in some environments, but this varies by service and configuration. Do not assume the capability exists without checking.

What to do next

Identify the administrator account, assigned roles, effective dates and the systems it could control. Obtain administrator audit logs where available and compare them with user activity.

Do not treat administrator status as proof of responsibility for every change. The relevant question is whether that role had the capability, access and opportunity to cause the event under investigation.

Key takeaway

Identify the administrator’s exact role and permissions, then use audit and organisational records to establish what that account could do and what it actually did.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.