A dental office owner posts on Reddit asking a simple question: does the MSP really need full admin login credentials to the office router, or is read-only access enough? The MSP's technician — who also happens to be the owner's son — pushes back hard, insisting full admin access is non-negotiable. The thread blows up because every small business owner reading it has faced some version of this moment: someone outside your organization wants the keys to your network, and you're not sure what you're allowed to say no to.
This isn't a personality conflict. It's a policy gap. If you don't have a written access control policy before you hire outside IT, you have no standard to point to when a vendor, contractor, or well-meaning relative asks for more access than the job requires.
Why This Matters Right Now
The stakes of handing out admin credentials casually just went up. According to The Hacker News, the FBI issued a warning that an active campaign tied to the FortiBleed vulnerability has harvested 86,644 sets of credentials from internet-facing Fortinet devices — the exact category of equipment that sits at the edge of a small business network, including routers and firewalls like the one in the dental office dispute. Reused or poorly managed admin passwords on devices like this are precisely what attackers are hunting for.
It's not just firewall vendors under pressure. SANS ISC reports that Remote Management and Monitoring (RMM) tools — the same software MSPs and IT contractors use to remotely access client networks — are increasingly being abused by threat actors once they gain a foothold. If an outside technician's own account or RMM platform is compromised, every client they have full admin access to is exposed at once.
And credentials don't need to be stolen directly from your network to put you at risk. The Hacker News also reported on more than 100 compromised websites using fake Cloudflare verification checks to deliver LunexStealer, an infostealer designed to harvest saved credentials from infected machines. If an IT contractor's laptop gets infected, any admin logins they've saved or reused become instantly available to attackers — including yours.
What a Written Access Control Policy Must Cover
Before you grant anyone outside your organization admin access, put the following in writing — ideally before the contract is signed, not after.
1. Define least privilege by task, not by convenience. An MSP configuring Wi-Fi settings does not need full router admin rights. Map out exactly what the vendor needs to do, then grant only the access level that task requires. "It's easier for me" is not a justification for full admin access.
2. Use named, individual accounts — never shared logins. If a vendor needs admin access, every technician should log in with their own credentials, not a shared "admin" account. This is the only way you'll ever know who changed what, and it's a baseline expectation in frameworks like CMMC, as we outline in our CMMC Level 1 compliance guide.
3. Require time-boxed or revocable access. Admin access should expire or be reviewable on a schedule, not granted permanently the day a contract starts. This matters just as much when a relationship ends — our post on IT provider offboarding and data held hostage covers what happens when a departing vendor retains access nobody remembered to revoke.
4. Log everything and own the logs. Your router, firewall, and RMM platform should log every admin login and configuration change, and those logs should be retrievable by you, not only by the vendor. If your internet-facing devices are Fortinet gear, cross-check your exposure against the current threat using our FortiGate credential leak firewall guide.
5. Put it in the contract, not just a conversation. Verbal agreements about access scope evaporate the moment there's a dispute. A one-page access control addendum, signed before onboarding, protects both you and the vendor.
The Bottom Line for the Dental Office — and You
The dental office owner in that Reddit thread isn't wrong to push back. Owning your admin credentials isn't about distrust — it's about having a documented, defensible standard for who can touch your network and under what conditions. Family connections and good intentions don't change the math: every admin account is an attack surface, and the FBI's own data shows attackers are actively harvesting exactly this kind of access at scale.
Take Action
A written access control policy only works if you actually know what's exposed on your network today. Proactive scanning catches misconfigured admin access, exposed device credentials, and risky remote access tools before attackers do. Oscar Six Security's Radar scan is an affordable way to check your exposure for $99 — no long-term contract, no jargon, just a clear picture of your risk. Check out our solutions and get started today. Focus Forward. We've Got Your Six.