A SMB executive team is comparing bundles and considering a cybersecurity assessment to determine where they need to start

If the only person with your admin passwords leaves, you can lose control of email, your domain name, your website, firewalls, backups and banking portals. Recovering them can take weeks. The fix is simple: put every critical account in the company’s name, give at least two people access and store credentials in a shared business password manager.

This is one of those risks that sits quietly for years. The office manager who set up Microsoft 365 in 2016 also registered the domain, built the website, holds the firewall password and is the only name on the backup account. Everything works, so nobody thinks about it. Then that person retires, gets sick, takes a job across the metroplex or leaves on bad terms, and leadership discovers the business doesn’t actually control its own technology. It’s a pattern worth checking for in any small organization, because it’s always more painful to fix after the fact.

What happens if only one person has access to all your business accounts?

It depends on how they leave, but none of the outcomes are good.

  • They leave on good terms. You’re relying on their memory and goodwill to hand everything over. Something always gets missed, usually the account nobody touches until renewal time.
  • They leave suddenly. An illness, accident or family emergency can take the only key holder offline with no warning.
  • They leave on bad terms. A disgruntled former employee or vendor with admin access can lock you out, delete data or hold access hostage during a dispute.
  • A vendor goes out of business. If your domain, website or firewall was set up under an outside contractor’s account, it disappears with them.

In every case, the business keeps paying for services it can’t fully control.

Which business accounts are most often controlled by one person?

  • Domain registrar and DNS (GoDaddy, Network Solutions, Cloudflare and others)
  • Microsoft 365 or Google Workspace global admin
  • Website hosting and the WordPress admin login
  • Firewall, Wi-Fi and network equipment
  • Backup and disaster recovery consoles
  • Line-of-business software admin accounts
  • Online banking, payroll and merchant services
  • Social media business pages and Google Business Profile
  • Apple Business, Google Play or other device management accounts
  • Cloud services like Azure or AWS
  • Software licensing and vendor portals

The domain registrar is the one we worry about most. Whoever controls it controls your email delivery and your website. If it’s registered to someone’s personal Gmail address and they won’t respond, you may be looking at a lengthy dispute to prove the business owns it.

How do you regain access if you’re locked out of your business accounts?

It’s usually possible, but it’s slow. Microsoft, domain registrars and most cloud providers have recovery processes that require proof the business owns the account. That might mean adding a DNS record to prove control of the domain, providing business registration documents or waiting through a support escalation. If the domain itself is the account you lost, you can end up in a chicken-and-egg problem. Plan on days at best and weeks at worst, with email or the website possibly down in the meantime.

What is a break-glass account?

A break-glass account, which Microsoft calls an emergency access account, is a highly protected admin account kept for emergencies when normal admin access fails. Microsoft’s emergency access guidance, updated in June 2026, recommends at least two of them for Microsoft 365. It also recommends:

  • Cloud-only accounts that don’t depend on any on-premises system
  • Phishing-resistant sign-in, with FIDO2 security keys as the recommended option
  • Credentials stored securely in separate physical locations, such as two different safes
  • Alerts on every sign-in, so you know if one is ever used
  • Testing at least every 90 days to make sure they still work

For a small business, that can be as simple as two security keys, one in the owner’s safe and one with a trusted second leader or your IT provider, plus a sealed record of the account details.

How many admins should a small business have?

Microsoft’s role best practices recommend assigning the Global Administrator role to fewer than five people, while keeping at least two emergency access accounts. The idea is balance. One admin is a single point of failure. Ten admins is an attack surface. Day-to-day tasks like resetting passwords or managing users should use narrower roles, such as User Administrator or Helpdesk Administrator, rather than full global admin rights.

How do you fix single-person admin risk? A 7-step checklist

  1. Inventory your critical accounts. List every account from the section above, who owns it, what email address it’s tied to and when it renews.
  2. Move ownership to the business. Recovery emails and account owners should be shared business addresses, like it@yourcompany.com, not anyone’s personal email.
  3. Add a second administrator to every critical system, ideally a leader plus your IT provider.
  4. Use a business password manager with shared vaults and access controls, so credentials aren’t living in a notebook, a spreadsheet or one person’s browser.
  5. Turn on MFA everywhere and make sure recovery methods don’t depend on one person’s cell phone.
  6. Set up break-glass accounts for Microsoft 365 and other core systems.
  7. Review it quarterly. Check admin lists, remove people who’ve changed roles and confirm the break-glass accounts still work.

What should be on an IT offboarding checklist?

When anyone with admin access leaves, whether an employee or a vendor, the same day they leave should include disabling their accounts, revoking active sessions, transferring ownership of files and sites, rotating any shared passwords they knew, removing them from admin roles and updating recovery contacts. Do it on their last day, not the following week. If the departure is contentious, do it while the conversation is happening.

Frequently asked questions

What happens if the only person with admin access leaves the company?

The business can lose control of email, its domain, website, network equipment and backups. Recovery requires proving ownership to each provider and can take days or weeks, often with service disruptions.

What is a break-glass account?

A break-glass or emergency access account is a highly protected admin account reserved for emergencies, such as when regular admins are locked out. Microsoft recommends at least two, secured with phishing-resistant sign-in and tested every 90 days.

How many global admins should Microsoft 365 have?

Microsoft recommends fewer than five Global Administrators, plus at least two emergency access accounts. Use narrower admin roles for routine tasks.

Who should own the company domain name?

The business should own its domain, registered with a shared business email address and with at least two people able to access the registrar account. It should never sit in a former employee’s or vendor’s personal account.

Is it safe to share admin passwords between employees?

Sharing a single admin login is risky and leaves no audit trail. Give each admin their own account with MFA, and use a business password manager for any credentials that must be shared.

How The Fulcrum Group helps

We help Dallas-Fort Worth organizations get control of their own keys. Through SPOT Managed IT Services, that includes a critical account inventory, documented ownership, Microsoft 365 admin cleanup and break-glass setup, password manager rollout and offboarding procedures that cover the accounts people forget. Our managed security team adds alerting on admin activity so changes don’t go unnoticed.

If you’re not sure who holds the keys to your business, Schedule a Discovery Call.