Cyber Essentials v3.3: admin account requirements and stronger authentication
Individual administrator credentials, separate day and admin accounts, effective MFA and optional phishing-resistant authentication and emergency-access hardening.

Section 01
Cyber Essentials v3.3: admin account requirements and stronger authentication
Admin and privileged accounts are the highest-risk accounts in any organisation. This article explains the current requirements for administrative access, without attributing longstanding account separation to a new version change.
Section 02
The core rules under v3.3
The NCSC requirements, pages 19-22, require controlled account creation and approval, unique credentials, least necessary access, removal of unneeded accounts and privileges, and separate accounts used only for administrative activities.
Implement MFA wherever available; cloud authentication must always use MFA. SMS is recognised, with suitable alternatives recommended. The scheme does not mandate FIDO2-only administration, emergency-account envelopes or a ninety-day log-retention minimum.
Section 03
Account separation
Under v3.3, a user with admin rights must have two accounts:
- Day account: standard user permissions, used for email, browsing, line-of-business tools.
- Admin account: elevated permissions, used only for admin tasks (user management, system configuration).
Rationale: if the user's day-to-day credential is compromised (phishing, laptop theft, malware), the attacker does not get admin access.
Small organisations sometimes push back on this ("we only have 3 admins"). The CE requirement applies regardless - even a 5-person organisation with one admin needs the separation.
Section 04
FIDO2 for admins (preferred)
We recommend phishing-resistant passkeys or security keys for privileged access. This is stronger hardening, not an attributed compulsory or preferred-administrator factor in the scheme text.
Use a supported authenticator and require user verification. Prepare a backup/recovery method independent of the normal device, enrol credentials, test representative sign-in and then enforce the chosen authentication-strength policy.
Key costs depend on model, supplier and features. Obtain a current quote rather than treating a fixed £50-£80 range as a scheme requirement or universal budget.
Section 05
Windows Hello for Business as an alternative
Windows Hello for Business uses a device-bound credential with PIN or biometric user verification. It is not universally a FIDO2 credential. Check the deployed trust model and the service authentication, rather than treating a screenshot or Windows product label as proof.
Microsoft explains the distinction between Windows Hello and Windows Hello for Business. Management-policy evidence can support the review, but the actual sign-in flow determines what authentication is used.
Section 06
Break-glass accounts
Emergency access protects against lockout and loss of a normal MFA method. It is resilience practice rather than a universal Cyber Essentials requirement for two sealed accounts.
Follow the identity provider's supported emergency-access design, with independent strong authentication, controlled use, monitoring and safe recovery testing. An exclusion from a policy must not simply create password-only cloud access. See Microsoft emergency access for a current implementation example.
Section 07
Monitoring admin actions
Audit logs and alerts help detect misuse and investigate incidents. Select retention and review intervals according to risk, provider licensing and your other obligations. Cyber Essentials does not impose a universal ninety-day retention or monthly admin-log review rule.
Useful hardening includes alerts on privilege changes and unexpected emergency-account use. Check what the actual product plan retains rather than assuming every tenant includes the same functionality.
Section 08
What the assessor checks
- Screenshot of admin role membership (Entra ID, Google Admin).
- Evidence that admins have individual accounts, not shared.
- Evidence of effective MFA where required and the actual methods used.
- Relevant enforcement policies and representative sign-in results; FIDO2-only policies are optional hardening.
- Documentation of break-glass protocol.
Section 09
Common failures
- Shared admin account (often in small MSPs): split into individual named admin accounts.
- Admin uses same account for email and admin work: create a separate admin account.
- Missing effective MFA: implement it wherever available, always for cloud authentication. SMS is weaker, but is not automatically prohibited.
- Recovery not planned: design and test recovery as resilience practice, without presenting it as a universal scheme condition.
- MSP shares client admin credentials internally: individual named accounts per MSP engineer.
Section 10
Bottom line
v3.3 treats admin accounts as a discrete category. Individual credentials, separate ordinary/admin use, least privilege and effective MFA. Monitoring, phishing-resistant factors and emergency-access design provide additional hardening. Get this right and admin controls are the strongest part of your submission.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
User Access Control for Cyber Essentials v3.3: the complete pillar guide
User Access Control is the pillar of Cyber Essentials that catches the most UK organisations out at assessment. This guide walks through every v3.3 requirement - individual accounts, MFA, admin separation, joiner-mover-leaver, third-party access - and the exact evidence assessors now expect.
Read articleTechnical Guides
MFA conditional access under Cyber Essentials v3.3: what works, what fails
Review Conditional Access for Cyber Essentials v3.3: effective MFA, location exclusions, authenticated sessions, device trust and safe administrator recovery.
Read articleTechnical Guides
Plain English Guide to the April 2026 Cyber Essentials Changes
The Danzell question set and v3.3 requirements took effect on 27 April 2026. This guide answers the exact questions IT managers and MSPs are asking about MFA auto-fails, cloud service scope, free accounts, and what assessors actually check.
Read article

