Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is administrator access?

Administrator access is permission to make significant changes within a defined system or service. It is not one universal level of complete control: a device administrator, database administrator and cloud identity administrator have different scopes.

Define the actual role

Identify the account, assigned role, resources controlled and permitted actions. Determine whether access was permanent, temporarily activated, delegated to an application or exercised by a service account.

Authentication, approval, role-assignment, activation and expiry records can show when the authority existed. This is particularly important for time-limited privileges: an account may be able to perform an action during one narrow period but not outside it.

Administrative audit logs should then show which changes were attempted or completed in that session. Compare them with the expected function and authorised purpose of the role.

Authority does not identify the actor

A legitimate administrator account can be compromised or shared, and automated systems can use administrative permissions without an interactive person. The named holder should not be assigned every action recorded against the account.

Separate the existence and scope of privilege, the authenticated session, the administrative action and the person controlling it. This also avoids overstating a limited role as control of the entire environment.

Key takeaway

Define the administrator role's exact scope and active period, then connect actions to the session without equating the privileged account with its holder.

Reference: CIM-108Cyber Incidents & Offender Methods