Cyber Essentials: User Access Control
The Cyber Essentials User Access Control covers how you manage who and what has access to your systems and data. It requires unique passwords for every account, two-factor authentication on important accounts, and ensuring that admin-level access is limited to those who genuinely need it. These guides cover every User Access requirement.
Last reviewed: July 2026
Cyber Nova AI helps you prepare for Cyber Essentials. It doesn't award or certify it. Follow the steps here to get ready, then apply for certification through an accredited Cyber Essentials body when you're set.
What this control covers
- ✓Set up two-factor authentication (2FA) on your email and important accounts
- ✓Use a password manager to create and store unique passwords for every account
- ✓Find and replace any weak or reused passwords across your accounts
- ✓Remove unused app access from your Google and Microsoft accounts
- ✓Use a standard (non-admin) user account for everyday tasks
User Access Control Guides (16)
- Set up two-factor authentication on your emailAdd two-factor authentication (2FA) to your email account so a password alone is not enough to get in.
- Set up Face ID and a strong passcodeTurn on Face ID (or Touch ID) and move from a 4-digit PIN to a six-digit or longer passcode. This is the lock on everything else on your iPhone.
- Change any weak or reused passwordsIdentify and replace passwords that are short, simple, or used on more than one account.
- Review connected apps in your Google or Microsoft accountCheck which third-party apps have been granted access to your Google or Microsoft account and remove any you no longer use.
- Create separate admin and day-to-day user accountsUse a standard (non-admin) account for everyday tasks. Only switch to the admin account when you need to install software or change system settings.
- Use a password managerInstall a password manager and move your passwords into it. A password manager generates and stores strong, unique passwords for every account, so you only need to remember one.
- Use an app for your login codes instead of texts. It's more secureReplace text message login codes with a free app such as Google Authenticator on your most important accounts. App-generated codes are more secure because they cannot be stolen, even if someone takes over your phone number.
- Check and update the passwords on your most important accountsCheck that your email, banking, and social media accounts all have strong, unique passwords. Replace any that are reused across multiple sites or that are short and easy to guess.
- Sign up for data breach alertsRegister your email address on Have I Been Pwned (haveibeenpwned.com) to receive free alerts if your details appear in a future data breach. You will hear about it before an attacker tries to use it.
- Check your credit report for signs of identity theftRun a free credit check via Experian, Equifax, or TransUnion to see if anyone has applied for credit in your name. Catching identity theft early limits the financial and personal damage significantly.
- Use a physical security key to lock down your most important accountsA hardware security key (such as a YubiKey) is the most secure form of two-step verification available. Adding one to your email account and other critical accounts eliminates the risk of phishing-based account takeover entirely.
- Turn on login alerts for your social accountsEnable notifications for new logins on your Facebook, Instagram, X, and other social media accounts. You will be alerted immediately if someone accesses your account from an unrecognised device.
- Save your backup sign-in codes somewhere safePrint or securely save the backup codes for your most important accounts, especially those protected by a login-code app. These codes are the only way back in if you lose your phone.
- Review and reduce app permissions on your phoneCheck which apps have access to your location, camera, microphone, and contacts, and remove any permissions that are not needed. Many apps request more access than they actually need to function.
- Use a standard account for everyday work on your MacDo your daily work in a standard account rather than an administrator account, so a bad click cannot make deep changes to your system.
- Do everyday work as a standard user, not rootUse a normal user account for daily tasks and switch to admin rights with sudo only when a job truly needs them.
Test yourself
A few quick questions to check what you have learned. Pick an answer to see whether it is right and why. Nothing is saved or scored.
Track your User Access Control progress. Free.
Create a free account to tick off tasks as you complete them and see your overall Cyber Essentials readiness score.
Start your free security checkCommon questions
What is user access control?
User access control means making sure that only the right people can access systems and data, and only to the level they actually need. Under Cyber Essentials, this includes using unique passwords for every account, two-factor authentication on key services, and limiting the use of administrator-level accounts.
What is the difference between an admin account and a standard account?
An administrator account has full control over a device: it can install software, change system settings, and access all files. A standard user account has limited permissions. Cyber Essentials requires that everyday work is done using a standard account, and that admin accounts are only used when specifically needed, to reduce the damage malware can do if a device is compromised.
Does Cyber Essentials require two-factor authentication?
Yes. Since April 2026 (version 3.3, the Danzell question set), two-factor authentication is required for all cloud services. If your team uses cloud email, file storage, or any cloud business tool, 2FA must be enabled for all users. For on-premises services, 2FA is required for remote access and for privileged accounts. From 26 April 2026, if multi-factor authentication is available on an in-scope cloud service and it isn't switched on, the assessment automatically fails, regardless of everything else. So turning it on everywhere it's offered is the single most important step for certification.
What counts as a strong password for Cyber Essentials?
A strong password is at least 12 characters long and unique to that account. The simplest way to achieve this is to use a password manager, which can generate and store random passwords for every account. Cyber Essentials does not require specific character types, but does prohibit using the same password across multiple accounts.