grc-scan

User access control

Making sure accounts are only used by the right people, with MFA, unique logins and separate admin accounts.

🔍 What a scan can verify

Our scans have only limited visibility here — sometimes an exposed login/admin panel, or a default-credential exposure.

📝 What stays self-declared

MFA on every account, unique per-person accounts, separate admin accounts and prompt removal of leavers are mostly invisible to an external scan — you tell us these, and a CE Plus assessor would test them on your actual systems.

What Cyber Essentials asks for this control

How to get ready

  • Turn on MFA for every account that supports it — email and cloud services first.
  • Give each person their own login; remove shared accounts.
  • Use separate admin accounts and a leaver checklist that revokes access on day one.

Check your user access control — and the other four controls

Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.

Start the free readiness check

← Back to all five Cyber Essentials controls.

This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.