Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could an administrator access the account without the user?

Yes. Organisational administrators, delegates, providers, support processes and attackers with elevated privileges may manage an account independently of its named holder.

Preserve capability and activity separately

Record tenant, workspace, role names, delegated permissions, group membership and audit indicators. An administrator may reset credentials, access data, alter retention, sharing or account status.

Capability does not prove action. Provider and organisational audit records are needed to distinguish user, administrator and automated events and to identify which administrator acted.

Avoid premature attribution

Do not enter administrative settings without authority and an understood evidential effect. Preserve visible roles, warnings and session information, then contact the appropriate system owner while maintaining continuity.

An event labelled with the user account can still result from delegation or administration; infer intent only from wider evidence.

Key takeaway

Treat administrator and delegated access as distinct attribution routes and preserve roles, audit references and time windows before drawing conclusions.

Reference: FRP-106First Response & Preservation