
How to Give IT Support Access Without Your Password
A legitimate technician can usually diagnose and repair your computer without knowing your password. Learn how to use temporary access, separate accounts, approved remote tools, and proper MFA handling without handing your keys to a stranger.
If someone says they need your password, your email password, and the code texted to your phone before they can help, stop right there. A good IT provider can normally work through a temporary support session, a separate admin account, or a supervised login. Your password is not a troubleshooting tool. It is the master key to a lot more than one computer.
What you need
Before you grant anyone access, have a few basics ready:
- The name, phone number, and official website of the company helping you.
- A way to contact them using a number or address you found yourself, not one supplied in a surprise pop-up or random email.
- Your computer nearby, plus your phone if you use multi-factor authentication, or MFA.
- A temporary time window when you can watch the work if remote access is involved.
- A separate standard user account or temporary support account, if your setup allows it.
- A recent backup of important files, especially for business machines.
For a South Florida business, this is not just fussiness. One shared Microsoft 365 password can expose email, client documents, invoices, bank-reset messages, and enough personal information to create a long, unpleasant week. (Nobody needs that kind of excitement.) If your company has several users and systems, managed IT support should include a documented method for granting and removing access, not a sticky note with passwords on it.
1. Verify who is asking for access
Start with the least glamorous step. Verify the technician or company before you open anything.
Do not trust an incoming call merely because the caller knows your name, your computer brand, or the name of a popular software company. Scammers buy leaked contact lists, scrape public business listings, and read enough from social media to sound convincing. The old "Microsoft detected a virus" routine is still alive because somebody, somewhere, keeps giving it lunch money.
If you contacted the provider yourself, use the number from their website, your service agreement, or a known business contact. If they contacted you unexpectedly, hang up and call the company through a number you independently find. The same goes for email links. Go to the company site yourself instead of clicking the link in the message.
For employees, establish a simple rule: no remote session starts from an unsolicited call, text, pop-up, or email. Report it to the person responsible for IT. Businesses that need a clear process for this should include it in their business cybersecurity procedures.
A legitimate technician should not pressure you to act immediately. They should be able to explain who they are, what they need to do, which support tool they use, and how you can end the session. If they get hostile when you verify them, congratulations, you have verified them.
2. Use a support tool that lets you approve each session
For one-time remote help, use a reputable remote-support tool that generates a session code or requires you to approve the connection. You should be able to see when the technician connects and disconnects. Ideally, the tool shows a notice while the session is active.
A proper attended session works like this:
- You open the support application from the provider's official instructions or website.
- The tool gives you a temporary code, link, or request.
- You provide that code to the verified technician.
- You approve the connection on your screen.
- You watch the work, ask questions if needed, and end the session when finished.
That is generally enough for routine diagnostics, software fixes, printer issues, application troubleshooting, and guided updates. You do not need to give the technician your Windows sign-in password to start that session.
For help from Fix My PC Store, use the official remote support page to start the process. Do not install a program because a stranger read a program name at you over the phone. Scammers love remote-control software because it is useful, common, and easy to abuse when installed without verification.
Avoid leaving unattended remote access enabled on a personal computer unless you understand exactly why it is needed. Unattended access means someone can connect later without you sitting there to approve the session. That can be appropriate for a managed business environment with agreements, logging, access controls, and a removal process. It is not something to leave enabled forever because a random helper said it would be "more convenient." Convenience is how half the messes on a repair bench begin.
3. Create a separate account instead of sharing your daily login
If a technician needs to sign in locally, create a separate account. Do not hand over the password for the account you use every day, particularly if that password is saved in your browser or connected to personal email, financial accounts, and cloud storage.
On a Windows PC, a separate local account can be useful for a repair visit. Give it a unique, temporary password. Start it as a standard user when possible. If the technician needs administrator rights for a particular task, you can approve that action while present, or create a temporary administrator account only for the work period.
The exact steps vary by Windows version and whether the PC is managed by a business. In general, go to Settings, then Accounts, then the area for Other users or Family & other users, and add a user. If you are unsure, do not blindly click through account settings. A technician can guide you while you remain in control.
For a Mac, create a separate standard user in System Settings, under Users & Groups. Avoid making it an administrator unless the work requires it. Macs have fewer places to hide bad decisions, but they can still hide them quite effectively.
Use a temporary account only when it makes sense. If the repair requires access to a problem inside your own profile, such as a corrupt user setting, a local email profile, or files stored only in your account, the technician may need you to log in while you are present. That still does not mean you must reveal the password. You type it. They look away. This is not difficult.
After the work is done, remove the temporary account or change its password. For business devices, access should be tied to named people, roles, and a documented offboarding process. That is one reason businesses benefit from Microsoft 365 support and managed identity controls rather than shared office logins.
4. Keep your password and MFA codes private
This is the part people get talked around. Do not disclose your password verbally, by text, through email, in a chat box, or on a handwritten note. Do not provide the one-time code sent by your authenticator app, text message, or email unless you personally initiated a specific login and fully understand what it is approving.
A one-time MFA code is not harmless. It may be the final approval for someone signing into your email, cloud storage, payroll portal, password manager, or business software. Once they are in, changing your password may not immediately kick them out, especially if they add their own recovery method or create an app session.
A legitimate technician may ask you to perform a login yourself. That is normal. They may tell you where to click, then ask you to enter your password and MFA code privately. Also normal.
What is not normal:
- "Read me the code so I can verify your account."
- "Your bank needs this code to secure your computer."
- "I need your email password to install an update."
- "Disable MFA permanently so I can work faster."
- "Add my phone number as a backup recovery method."
That last one is especially ugly. Account recovery methods are ownership controls. Adding a technician's phone number or personal email as a recovery contact is like giving them a spare house key and writing your alarm code on it. Keep recovery methods under your ownership.
If the issue involves your email account, have the technician explain the needed change, then sign in yourself. For business systems, use delegated administration, role-based access, or a properly managed support account instead of sharing a company owner’s credentials.
Worried your business is one click from a breach? Get a security review
5. Grant only the access required for the job
Access should match the task. Fixing a slow laptop does not require access to your bank website. Replacing a damaged screen does not require your Apple ID password. Configuring a business firewall may require administrative access to network equipment, but not unrestricted access to every employee’s email.
Ask one plain question before access is granted: What exactly do you need access to, and why? A competent technician will answer directly.
Here are sensible examples:
- A remote technician needs temporary screen control to diagnose an application crash.
- A repair technician needs you to unlock the computer so they can test hardware and confirm the repair.
- A business IT provider needs an approved administrative role to manage user accounts, patches, or security settings.
- A network technician needs administrator access to the router or firewall to correct a configuration issue.
Here are warning signs:
- They demand the password to your primary email account for unrelated PC work.
- They want full administrator access with no expiration or explanation.
- They ask to install multiple unknown remote-control tools.
- They want you to turn off antivirus, browser protection, or MFA without a clear, limited reason.
- They cannot tell you how access will be removed afterward.
For a business, use named accounts wherever possible. Shared admin passwords make audits, troubleshooting, and employee departures much harder. They also make it impossible to know who changed what when something breaks at 4:45 on a Friday. Funny how that always happens at 4:45.
If you run a small office, your provider can set up controlled admin access, device management, and documented permissions through business IT services. The goal is not to make everyday work complicated. The goal is to prevent one password from becoming the key to the whole building.
6. Protect your files and privacy before the session
Remote access is not automatically dangerous, but it does mean another person may see what is on your screen. Clean up first.
Close banking sites, medical portals, tax documents, personal email, password managers, and anything containing customer information. Lock or sign out of browser profiles that hold saved passwords. If you have confidential files on your desktop, move them to a secure folder before the session. Better yet, stop using the desktop as a filing cabinet. It is the digital version of keeping your tax return on the hood of the car.
Back up important files before significant repair work, operating system changes, malware cleanup, or disk troubleshooting. Good technicians warn you when a repair carries data risk, because storage devices can fail at inconvenient times and sometimes fail harder when stressed. A backup is your safety net, not a magic spell. Make sure it is current and that you can actually retrieve files from it.
For businesses, backups should be managed and tested rather than assumed. See backup and disaster recovery services if you need a system for protecting company data beyond copying a few folders to a USB drive once in a blue moon.
If a technician needs access to a specific sensitive file or system, stay present and provide access only for that task. You can take back control of the mouse while entering credentials, viewing financial details, or approving MFA prompts.
7. Watch the session, then remove access when work is complete
During a one-time remote session, stay at the computer when practical. Watch for prompts you do not understand. It is fine to ask the technician what they are doing. A good tech should be able to explain in ordinary language, even if the answer is "I am checking logs because Windows has decided to be Windows."
At the end, confirm these points:
- The remote session is disconnected.
- Any temporary support program is closed or uninstalled if it is no longer needed.
- Any temporary support account is disabled, deleted, or has its password changed.
- You know what was fixed and what changes were made.
- You have a way to get support later through an official channel.
For business systems, request a short record of access granted, changes made, and access removed. Your IT provider does not need to write a novel about it. A clear ticket note is usually enough. What matters is that there is a trail.
If you accidentally shared a password or MFA code, act promptly. Change the password from a known-clean device, sign out of active sessions where the account allows it, review recovery methods and forwarding rules, and contact the affected service provider. For business accounts, report it to your IT team immediately. Do not wait because you feel embarrassed. Scammers count on that silence.
Common mistakes
The most common mistake is assuming every support request is urgent. Most real computer problems can survive five minutes of verification. The fake emergency is a scammer’s favorite wrench.
Another mistake is treating an email password as a minor credential. Email often controls password resets for everything else. If someone gets your email, they may not need your banking password first. They can simply reset it.
People also confuse a remote-support session code with a password. They are not the same. A temporary session code, given to a verified provider for a session you approved, can be appropriate. Your Windows, Apple, email, Microsoft 365, or password-manager password should remain private.
Do not create a permanent administrator account for a technician and forget it exists. Temporary access must actually be temporary. Remove it, rotate the password, or disable the account as soon as the work is complete.
Finally, do not assume a familiar logo makes a request legitimate. Fake Microsoft, Apple, antivirus, shipping, and bank messages are all over the place. The logo is cheap. Your account is not.
Bottom line
You can get solid IT help without giving away your password, your MFA codes, or control of your accounts. Verify the provider, use approved temporary remote access, create separate accounts when needed, enter sensitive credentials yourself, and remove access once the job is done.
If you need help with a PC, Mac, office system, or secure remote session in West Palm Beach or elsewhere in South Florida, contact a known local provider through their official channel. That is not paranoia. That is basic maintenance, like changing the oil before the engine starts making expensive noises.
Worried your business is one click from a breach?
Get a straight-talk security review from a local team that has cleaned up the aftermath more times than we'd like.
Frequently asked questions
Should I ever give an IT technician my password?
In most cases, no. You can type the password yourself while the technician looks away, or use a separate temporary account for the work. A legitimate provider should have a process that does not require collecting your everyday password.
Is it safe to give a technician a remote support code?
It can be safe if you initiated contact with a verified provider, opened the approved support tool yourself, and can see and approve the session. Treat a session code as temporary access, not as a password. Do not give codes to callers from unexpected pop-ups, texts, or emails.
Why should I never share an MFA code with IT support?
An MFA code can approve a sign-in to an important account, including email or cloud services. A technician can usually guide you while you enter the code privately. If someone insists that you read the code aloud, stop and verify the request independently.
What kind of account should I create for a repair technician?
Create a separate local or temporary account with a unique password. Start with standard-user permissions when possible, and only grant administrator rights if the job truly requires them. Remove the account or change its password after the work is complete.
What should a business do after granting IT vendor access?
Document who received access, what role they received, what changes they made, and when access was removed or reviewed. Use named accounts and delegated roles rather than shared owner credentials. Review recovery methods and privileged accounts regularly.