Compliance

Who Owns the Admin Credentials Before You Hire IT?

Who Owns the Admin Credentials Before You Hire IT?

Know what attackers see before they do. See a live Radar report →

A dental office owner posts on Reddit asking a simple question: does the MSP really need full admin login credentials to the office router, or is read-only access enough? The MSP's technician — who also happens to be the owner's son — pushes back hard, insisting full admin access is non-negotiable. The thread blows up because every small business owner reading it has faced some version of this moment: someone outside your organization wants the keys to your network, and you're not sure what you're allowed to say no to.

This isn't a personality conflict. It's a policy gap. If you don't have a written access control policy before you hire outside IT, you have no standard to point to when a vendor, contractor, or well-meaning relative asks for more access than the job requires.

Why This Matters Right Now

The stakes of handing out admin credentials casually just went up. According to The Hacker News, the FBI issued a warning that an active campaign tied to the FortiBleed vulnerability has harvested 86,644 sets of credentials from internet-facing Fortinet devices — the exact category of equipment that sits at the edge of a small business network, including routers and firewalls like the one in the dental office dispute. Reused or poorly managed admin passwords on devices like this are precisely what attackers are hunting for.

It's not just firewall vendors under pressure. SANS ISC reports that Remote Management and Monitoring (RMM) tools — the same software MSPs and IT contractors use to remotely access client networks — are increasingly being abused by threat actors once they gain a foothold. If an outside technician's own account or RMM platform is compromised, every client they have full admin access to is exposed at once.

And credentials don't need to be stolen directly from your network to put you at risk. The Hacker News also reported on more than 100 compromised websites using fake Cloudflare verification checks to deliver LunexStealer, an infostealer designed to harvest saved credentials from infected machines. If an IT contractor's laptop gets infected, any admin logins they've saved or reused become instantly available to attackers — including yours.

What a Written Access Control Policy Must Cover

Before you grant anyone outside your organization admin access, put the following in writing — ideally before the contract is signed, not after.

1. Define least privilege by task, not by convenience. An MSP configuring Wi-Fi settings does not need full router admin rights. Map out exactly what the vendor needs to do, then grant only the access level that task requires. "It's easier for me" is not a justification for full admin access.

2. Use named, individual accounts — never shared logins. If a vendor needs admin access, every technician should log in with their own credentials, not a shared "admin" account. This is the only way you'll ever know who changed what, and it's a baseline expectation in frameworks like CMMC, as we outline in our CMMC Level 1 compliance guide.

3. Require time-boxed or revocable access. Admin access should expire or be reviewable on a schedule, not granted permanently the day a contract starts. This matters just as much when a relationship ends — our post on IT provider offboarding and data held hostage covers what happens when a departing vendor retains access nobody remembered to revoke.

4. Log everything and own the logs. Your router, firewall, and RMM platform should log every admin login and configuration change, and those logs should be retrievable by you, not only by the vendor. If your internet-facing devices are Fortinet gear, cross-check your exposure against the current threat using our FortiGate credential leak firewall guide.

5. Put it in the contract, not just a conversation. Verbal agreements about access scope evaporate the moment there's a dispute. A one-page access control addendum, signed before onboarding, protects both you and the vendor.

The Bottom Line for the Dental Office — and You

The dental office owner in that Reddit thread isn't wrong to push back. Owning your admin credentials isn't about distrust — it's about having a documented, defensible standard for who can touch your network and under what conditions. Family connections and good intentions don't change the math: every admin account is an attack surface, and the FBI's own data shows attackers are actively harvesting exactly this kind of access at scale.

Take Action

A written access control policy only works if you actually know what's exposed on your network today. Proactive scanning catches misconfigured admin access, exposed device credentials, and risky remote access tools before attackers do. Oscar Six Security's Radar scan is an affordable way to check your exposure for $99 — no long-term contract, no jargon, just a clear picture of your risk. Check out our solutions and get started today. Focus Forward. We've Got Your Six.

Frequently Asked Questions

Should I give my IT vendor full admin access to my router?

Not by default. Grant access based on the specific task the vendor needs to perform, using the principle of least privilege, and require named individual logins rather than a shared admin account.

What is an access control policy for small business IT?

It's a written document defining who can access which systems, at what privilege level, and under what conditions, including how access is granted, logged, and revoked. It should be in place before you hire any outside IT contractor or MSP.

How do I know if my router or firewall credentials have been leaked?

Check vendor security advisories and threat intelligence reports, such as the FBI's recent warning about FortiBleed-related credential harvesting, and consider a third-party scan. Oscar Six Radar scans for exposed admin interfaces and credential-related risks for $99 per scan.

What should be in an MSP contract about access control?

The contract should specify least-privilege access scope, require individual named accounts, define logging and audit rights for the client, and include a clear process for revoking access when the relationship ends.

What happens if I don't revoke IT vendor access after ending a contract?

Former vendors or contractors can retain the ability to log into your network indefinitely, creating an ongoing security and compliance risk. This is a common gap covered in our guide to IT provider offboarding and data hostage situations.

Step-by-Step Guide

  1. Map required tasks

    List exactly what the outside IT vendor or technician needs to do on your network before deciding what access level they need.

  2. Assign least-privilege roles

    Grant only the minimum access level required for those tasks, avoiding full admin rights unless absolutely necessary.

  3. Require individual logins

    Insist on named, individual accounts for every technician instead of a single shared admin login.

  4. Set access expiration

    Make admin access time-boxed or subject to scheduled review rather than permanent from day one.

  5. Enable and retain logs

    Confirm your devices log all admin activity and that you, not just the vendor, can access those logs.

  6. Document it in the contract

    Put the access scope, logging requirements, and revocation process in writing before signing any vendor agreement.

Find out what's exposed. Radar scans your external attack surface and shows you exactly what needs fixing. See a sample report →