The Password That Can Shut Down Your Entire Business
- Steven Burstyn

- Jul 30
- 5 min read

An employee leaves the company. Two weeks later, someone needs to change a Microsoft 365 setting.
The password works, but the verification code goes to the former employee’s personal phone.
Then another problem surfaces. That employee was also the only person who could manage the company’s email accounts. The router password is saved on their old computer. The company’s QuickBooks file still lists an outside bookkeeper as the primary administrator. Nobody is certain who controls the domain name.
Nothing was hacked. The business is locked out of systems it pays for because access was tied to people instead of the company.
You Can Pay for an Account Without Controlling It
Most small businesses collect accounts gradually. Someone sets up Microsoft 365 when the first employees are hired. A web developer registers the domain. An installer configures the router. A bookkeeper creates the accounting account.
Everything works, so nobody questions the arrangement.
Years later, the business may discover that a former employee, vendor, or consultant still controls an important login or recovery method. The owner may not even know which email address is associated with the account.
The accounts most likely to cause serious disruption include:
Microsoft 365 or Google Workspace administration
QuickBooks, payroll, and banking platforms
The company’s domain name and website
Internet service and router settings
Cloud storage and backup systems
Social media and advertising accounts
Security cameras, alarms, and building access systems
Any one of these accounts can interrupt normal work if the password, multi-factor authentication method, or recovery information is unavailable.
Password security is not only about preventing unauthorized access. It is also about making sure the company can reach its own systems when the person who set them up is no longer around.
Shared Access Is Not the Same as a Shared Login
Small businesses often solve the access problem by giving several people the same username and password. That keeps the information from living in one person’s head, but it creates a different set of problems.
When everyone uses the same login, there may be no reliable way to know who changed a setting or accessed sensitive information. Removing one employee may require changing the password for everyone. Someone who leaves could retain access simply because nobody remembered which shared accounts they knew.
Whenever a platform supports individual users, each person should have a separate account with the access needed for their job. QuickBooks Online, for example, allows administrators to add users and assign roles rather than handing everyone the primary administrator’s credentials.
If a service requires a shared credential, a business password manager provides a more controlled way to store it. Authorized employees can receive access through their own password-manager accounts instead of finding the password in an email, spreadsheet, or browser saved on one computer.
Depending on the password manager and subscription, the business may also be able to see who has access, revoke that access, and track changes to stored credentials.
The company must control the password-manager account and vault. Otherwise, it has only moved the access problem to a different system.
The Password Manager Needs a Recovery Plan Too
A password manager can generate and store a different password for every business account. That reduces password reuse and gives the company one organized place to manage critical credentials.
It also becomes one of the most important systems the business owns.
The vault should be protected with a long, unique master password and multi-factor authentication. More than one authorized person should understand how company access is administered, but that does not mean casually sharing the master password.
The business also needs a documented recovery process. If the owner loses the authentication device or the password manager locks the account, someone must know what to do next. Recovery information for the vault itself should be stored separately in a secure location. A recovery code kept only inside the locked vault will not help.
Ownership and recovery should remain tied to company-controlled email addresses, devices, and records rather than an employee’s personal account.
MFA Can Protect the Account and Still Lock Out the Company
Multi-factor authentication, or MFA, adds another verification step after the password. If someone steals a password, that additional step can prevent entry to the account.
The problem is not MFA. The problem is relying on one person’s phone as the only way to complete it.
Critical accounts should have recovery options that remain available when an employee leaves, changes phone numbers, or is unexpectedly unavailable. Depending on the service, that may involve another authorized administrator, company-controlled authentication devices, security keys, or securely stored recovery codes.
Microsoft’s current guidance goes further for its cloud services. It recommends maintaining at least two dedicated emergency access accounts that are separate from normal administrator accounts. These accounts should be protected, monitored, and tested periodically so the company has another way into its Microsoft environment if the regular administrators are locked out.
The correct setup will vary by platform. The principle does not: no single employee or personal device should be the only path into a system the business needs to operate.
Employee and Vendor Departures Need an Access Checklist
Removing an employee’s email account is only one part of the offboarding process.
The business should identify every system the person could access. Individual accounts should be disabled or removed. Shared passwords should be changed when necessary. Active sessions and connected devices may need to be signed out.
Administrative access requires particular attention. A former employee should not remain an administrator for email, accounting software, cloud storage, the website, or network equipment because nobody knew the account existed.
The same review should happen when the relationship ends with a bookkeeper, web developer, marketing company, consultant, or IT provider. Outside vendors should have only the access they need, and the business should be able to remove that access without locking itself out.
For every critical account, the company should know:
Who owns and administers the account
Which company email address is associated with it
Where the current password is securely stored
How MFA and account recovery work
Who can regain access if the primary administrator is unavailable
Which outside vendors currently have access
This record should identify where the information is stored without becoming a document that creates its own security problem.
Find the Lockouts Before They Stop the Business
Pick one critical account and see whether a second authorized person can access it. Confirm that the password works, the MFA method is available, and the recovery email belongs to the company.
Start with email administration, accounting, payroll, the domain name, network equipment, backups, and cloud storage. If nobody can explain who controls an account or how to recover it, that is the problem to fix first.
Unfrustrating Computers helps Long Island small businesses evaluate their technology, identify access problems, and create a practical infrastructure plan before a missing password interrupts the business.
Call 516-679-5540 or email info@unfrustratingcomputers.com to find out where your business is one lost password away from a lockout.




Comments