User access control
Making sure accounts are only used by the right people, with MFA, unique logins and separate admin accounts.
🔍 What a scan can verify
Our scans have only limited visibility here — sometimes an exposed login/admin panel, or a default-credential exposure.
📝 What stays self-declared
MFA on every account, unique per-person accounts, separate admin accounts and prompt removal of leavers are mostly invisible to an external scan — you tell us these, and a CE Plus assessor would test them on your actual systems.
What Cyber Essentials asks for this control
- Is multi-factor authentication (MFA) enabled on EVERY user account that supports it — including all cloud services and email, for every user, not just admins?
Under the current question set, MFA missing on ANY in-scope account fails the whole User Access Control section. Passkeys / FIDO2 count.
Mandatory item — a “No” here fails this whole control.
- Does each person have their own individual account, with no shared logins?
Shared accounts make it impossible to know who did what, and can't be properly secured.
- Are administrator accounts separate from everyday accounts, and are leavers' accounts removed promptly?
Day-to-day work should use a standard account; admin rights only when needed. Remove access as soon as someone leaves.
How to get ready
- Turn on MFA for every account that supports it — email and cloud services first.
- Give each person their own login; remove shared accounts.
- Use separate admin accounts and a leaver checklist that revokes access on day one.
Check your user access control — and the other four controls
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →← Back to all five Cyber Essentials controls.
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.