Plan administrator access before rollout. Grant administrative rights to as few accounts as possible, and give each account only the rights needed for its role.
Use Separate Admin and User Accounts
In most environments, the people who administer MyQ also use it as regular users – they print documents, scan files, and do everything other users do. Mixing administrative and everyday activity in a single account is a security risk. Instead, create two accounts for each administrator: one for daily use with standard user rights, and one strictly for administrative tasks.
For example, your IT administrator Tim would use the account tim.canterbury for printing and scanning, and tim.canterbury.admin for managing users, configuring queues, and adjusting settings. The everyday account carries no elevated rights. The admin account is used only when administrative work is required.
This reduces the attack surface of privileged accounts, makes stricter authentication controls easier to apply where available, and creates a clearer audit trail because administrative actions are not mixed with everyday print and scan activity.
The *admin Account
Every new MyQ installation includes a built-in *admin Server Administrator account for initial setup. It should not be used for ongoing administration after named administrator accounts are created. The recommended lifecycle is:
-
Set the
*adminpassword in Easy Config immediately after installation. -
Use it to complete initial setup – configure the system, synchronize or create users, assign rights.
-
Create at least one named administrator account with the minimum rights needed for ongoing administration.
-
Disable the
*adminaccount in Easy Config once setup is complete.
Note that from MyQ X 10.2, if the *admin password is still set to the default 1234 at upgrade time, the account is automatically disabled and requires a password reset in Easy Config before it can be used again.
Least Privilege
Beyond the admin/user account separation, apply the same principle to every rights assignment: grant only what is needed for the task, and nothing more. MyQ rights can be assigned by task. For example, a user who recharges credit can be granted the relevant credit rights without full Administrator rights; a user who manages users does not necessarily need access to system-wide settings.
See also: