I'm the only sysadmin at a small company of about 80 users. We primarily use Microsoft services, I normally work from the office, and I only take my work laptop home occasionally. I also haven't been issued a work phone.
Some employees work evenings and weekends, so I'm wondering how to handle situations such as account lockouts, password resets, suspected account compromise, or a lost device outside normal working hours.
At the moment I have a standard account, bug@company, and a separate Global Administrator account, bug.admin@company. I'm considering either allowing the admin account on my phone or assigning the necessary administrative roles to my normal account. Neither option feels ideal. What would be a sensible, secure approach, and how should the company define its after-hours support expectations?
4 Answers
Use self-service password reset for routine lockouts and password changes. With Microsoft Entra ID, configure SSPR and preferably passwordless authentication where practical. For lost devices or suspected compromises, define an escalation process so managers or leadership can declare a real emergency. Critical incidents could be handled by a contracted security provider or an agreed on-call rotation rather than relying on one person.
Put the process in writing and route requests through a ticketing system. An after-hours request should normally require the employee to notify their manager, and only business-stopping incidents should escalate immediately. The company should provide a managed laptop or other approved remote-access setup if it genuinely expects you to respond away from the office. Otherwise, the documented answer can simply be: use self-service tools where available and wait until support hours.
Avoid doing privileged administration from a personal phone, and don’t give your everyday account broad permanent privileges just to make emergencies easier. Keep the administrator account separate, use role-based access and just-in-time elevation if available, and maintain properly secured emergency access accounts. Any remote administration should use company-managed equipment and an approved VPN or management workstation.
First, establish whether after-hours support is actually part of your job. If the company wants 24/7 coverage, that needs to be an explicit policy with defined severity levels, staffing, equipment, and compensation. Otherwise, requests can wait until the next business day. Don’t quietly create an on-call service by making yourself available for free; once users learn you respond, they’ll expect it every night and weekend.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures