QuickBooks Online is simultaneously an accounting ledger, a bank-connected application, a source of tax and payroll-related information, and a platform for third-party integrations. A user who can edit the chart of accounts, reconcile a bank, manage other users, alter settings, or control an integration does not present the same risk as a user entering bills. Security therefore begins with the actual duties, data, and money movement a person can reach—not the convenience of giving everyone broad access.
Current Intuit guidance lists several preset roles and describes custom roles for QuickBooks Online Advanced and Intuit Enterprise Suite. It also ties user counts and some roles to subscription or service combinations. Do not copy an old role matrix or claim that a granular permission is universally available. Open Manage users in the live company, record the plan, expand the displayed permissions, test with a non-production identity, and capture the approved result without exposing names or email addresses.
Pair this guide with ALLMSP's [QuickBooks Online support library](https://www.allmsp.com/category/software-support/software-support-quickbooks-online/), [CPA and Financial Firms resources](https://www.allmsp.com/category/cpa-and-financial-firms/), and [Software Support guidance](https://www.allmsp.com/category/software-support/). The objective is least-privilege access with durable ownership, understandable verification behavior, reviewable changes, controlled prior-period edits, and an offboarding path that does not strand the books.
Key decisions at a glance
- Inventory the actual QuickBooks Online subscription and live role descriptions before granting access; user limits, preset roles, custom roles, and capabilities vary by plan and connected services.
- Keep primary-admin and company-admin ownership with accountable current personnel, use individual Intuit accounts, and establish recovery and succession before a departure or lockout.
- Distinguish Intuit's risk-based MFA, which current guidance says cannot be turned off, from opt-in two-step verification, which challenges every sign-in when enabled.
- Review the audit log, accountant access, integrations, bank connections, lock date, and responsibility transfers before deleting a user, then preserve evidence that critical workflows still have an owner.
Map Plan-Dependent Roles to Real Accounting Duties
Build an access register from the live QuickBooks Online company. Record each person's business duty, required company, preset or custom role, account-management privileges, payroll or payment service access, accountant relationship, bank-feed need, reporting need, integration ownership, approval owner, start and review dates, and exception. Keep personal details out of project notes. Use protected identity references and let the primary or company admin perform invitation and role changes through Manage users.
Current Intuit guidance distinguishes primary admin and company admin from operational roles such as Standard all access, In house accountant, Bookkeeper, accounts-receivable manager, accounts-payable manager, limited access, reports, time, and other service-specific roles. Capabilities differ materially. Some roles cannot view financial reports or bank registers; others can reconcile, journalize, alter accounts, manage payroll, or pay bills. Custom roles are described for QuickBooks Online Advanced and Intuit Enterprise Suite, so verify subscription and displayed permissions instead of promising custom granularity on every plan.
Separate the firm's external accountant path from an ordinary employee role when appropriate. Treat accountant access as privileged: confirm the firm identity, approved engagement, responsible partner, invited address, acceptance, client access within the accounting firm, and removal process. Never share one Intuit login between internal staff, outside accountants, temporary specialists, or support personnel because the audit evidence and recovery ownership become unreliable.
- Grant the smallest role that supports tested duties and document any excess access the current plan cannot separate.
- Reserve primary-admin and company-admin roles for accountable owners who genuinely need user and company control.
- Test banking, reports, payroll, bills, journal entries, account lists, settings, and audit access separately.
- Give temporary or vendor access an owner, purpose, expiration, review date, and explicit removal evidence.
- Recheck permissions after plan changes, service additions, Intuit interface updates, and major duty changes.
Protect Intuit Accounts and Administrator Continuity
Assign each person an individual Intuit account with a current work email and recovery information controlled by that person under company policy. The primary admin is the central ownership role; the person who creates the company receives it by default, and transfer requires the incoming person to be an admin first. Establish at least one current company admin, a documented transfer procedure, billing and support ownership, and an escalation route before the primary admin leaves. An emergency ownership request can require business proof and should not be the normal succession plan.
Use precise language for authentication. Current Intuit guidance says risk-based multi-factor authentication challenges an unrecognized device and cannot be turned off. Opt-in two-step verification is different: when enabled, it verifies every sign-in with a one-time code. The same guidance describes phone or email verification data, passkeys, and an authenticator that generates one-time passcodes. Build support instructions around these distinctions, because telling a user to disable MFA or expect a prompt on every sign-in may be wrong for the control they are experiencing.
Plan recovery without collecting secrets. Confirm that users can reach approved recovery channels, know where to manage Sign in and security, and can contact the firm's help path if a device or phone changes. Do not record passwords, one-time codes, passkey material, authenticator seeds, recovery values, or full phone numbers in tickets. Test sign-in from a recognized device, the expected challenge on an unrecognized device, and two-step verification for users who enable it, but use protected test accounts and redact evidence.
- Maintain a named primary admin, at least one appropriate company admin, and an approved succession record.
- Explain risk-based MFA and opt-in two-step verification as separate Intuit controls in user training.
- Never ask a user to forward a one-time code, approve an unexpected recovery, or share an authenticator screen.
- Review recovery email, phone, device, and passkey ownership when a worker changes role or employment status.
- Escalate unexpected sign-in or recovery activity through a verified channel before changing financial-system access.
Interpret the Audit Log, Integrations, and Locked Books Correctly
Review the QuickBooks Online audit log as evidence, not as a complete security-monitoring platform. Current Intuit guidance says it records financial transactions and account activities, including sign-ins, settings changes, master-data edits, and payroll submission; events remain available for two years; the log cannot be turned off; and sign-outs are recorded only when the user selects Sign out. Closing a browser or timing out may therefore leave no sign-out event. Filter by user, date, and event, then open History before drawing a conclusion.
Learn the system-created identities. Online Banking Administration represents automatic connected-bank activity. Support Representative reflects a QuickBooks support consultant. System Administration can represent automatic downstream changes, third-party app data, recurring transactions, or bank-feed updates. Import Administration can relate to conversion activity. An unfamiliar label is not automatically an intruder, but it deserves correlation with the connected bank, app, import, user action, support case, transaction history, and expected time. Review indirect edits where one change alters another record.
Connect access review to period protection. Current Intuit guidance says primary or company admins can lock the books with a date and choose a warning or a warning plus password before past changes. Reconcile and review completeness before setting that date. Use the Exceptions to Closing Date report to review later changes. Also inventory third-party integrations and their administrator; app-originated changes may appear as System Administration, and a departing app owner must transfer or disconnect the relationship without silently breaking operational or audit flows.
- Review user, settings, bank, app, import, recurring, deleted-transaction, payroll, and close-date activity on a risk-based cadence.
- Correlate audit events with source documents, integration logs, support cases, bank evidence, and approved changes.
- Treat a lock-date password as a prior-period safeguard, not a substitute for least privilege or reconciliation.
- Give every connected app a business owner, technical owner, data scope, service account, review date, and exit path.
- Investigate changes to users, banks, payment services, payroll, accounting settings, and closed periods promptly.
Offboard Without Stranding Ownership or Damaging the Books
Sequence offboarding around financial continuity. Before deleting a user, transfer primary-admin ownership if needed; assign company administration, payroll, payment, banking, billing, support, accountant, recurring transaction, report schedule, and connected-app responsibilities; review open work; and preserve required evidence. Current Intuit guidance says deleting a user is permanent, although their history remains visible in the audit log. That history does not restore ownership of an external bank, app, phone, email, or workflow.
Use a departure checklist with independent verification. Confirm the worker's Intuit account status, QuickBooks Online role, accountant or client access, connected-app ownership, bank-feed administration, exported credentials held elsewhere, browser sessions under company policy, recovery methods, scheduled reports, custom automations, outstanding transactions, unreconciled work, and prior-period changes. Delete or reduce access only after the successor proves the critical tasks and integrations still function. Review the audit log around the transition and preserve the approved evidence location.
Bring identity, endpoint, and financial controls together through ALLMSP's [Cybersecurity resources](https://www.allmsp.com/category/cybersecurity/). [Contact ALLMSP](https://www.allmsp.com/contact-us/) when primary-admin continuity, compromised access, app ownership, bank feeds, locked books, or audit interpretation needs a controlled response. Intuit support can help with product and account processes; the company and its accountant remain responsible for access approval, financial accuracy, employment decisions, retention, and materiality.
- Transfer primary-admin, company-admin, app, bank, payroll, payment, billing, and support ownership before deletion.
- Review open transactions, scheduled processes, reconciliations, and closed-period work associated with the departing user.
- Remove unneeded accountant, integration, and temporary access in addition to the ordinary Manage users entry.
- Confirm the successor can sign in, receive expected verification, perform the duty, and retrieve support evidence.
- Retain the audit trail and offboarding decision according to firm policy without exporting unnecessary personal data.
Vendor documentation and ALLMSP resources
- Intuit: User roles and access rights
- Intuit: Add and manage users
- Intuit: Secure your Intuit Account with extra verification methods
- Intuit: Use the audit log in QuickBooks Online
- Intuit: Change the primary admin role
- Intuit: Lock your books in QuickBooks Online
- Intuit: Edit your closed books in QuickBooks
- Intuit: Transfer app ownership or disconnect apps
- ALLMSP: QuickBooks Online Software Support
- ALLMSP: CPA and Financial Firms
- ALLMSP: Software Support
- ALLMSP: Cybersecurity
- ALLMSP: Contact Us
Frequently Asked Questions
What is the difference between primary admin and company admin in QuickBooks Online?
Both are broad administrative roles, but the primary admin is the central owner and has responsibilities a company admin cannot reassign. Current Intuit guidance says the person who creates the account becomes primary admin by default. Keep that role with an accountable current person and maintain an approved transfer and recovery plan.
Are QuickBooks Online roles the same on every subscription?
No. User limits, preset roles, custom-role options, mobile support, and service-specific roles vary by subscription and connected products. Current Intuit guidance describes custom roles for QuickBooks Online Advanced and Intuit Enterprise Suite. Verify the live plan and expand the displayed permissions before approving or documenting access.
Is Intuit MFA the same as two-step verification?
No. Current Intuit guidance describes risk-based MFA as a challenge on an unrecognized device and says it cannot be turned off. Opt-in two-step verification is a separate setting that requests a one-time code at every sign-in. Support staff should identify which control is active before giving recovery instructions.
Can the firm require every QuickBooks Online user to share one authenticator device?
No. Users should have individual Intuit accounts and approved personal recovery methods under company policy. Sharing a phone, code, passkey, password, or authenticator destroys accountability and creates a single point of failure. Never capture one-time codes or authenticator seeds in a ticket, screenshot, or shared procedure.
Why does the audit log show System Administration?
Current Intuit guidance says System Administration can record automatic downstream changes, third-party app activity, recurring transactions, or bank-feed updates. Correlate the event with History, source records, integrations, connected banking, approved automation, and nearby user actions. Do not assume it is malicious, but do not dismiss an unexplained high-risk change.
Does the QuickBooks Online audit log record every sign-out?
No. Current Intuit guidance says a sign-out appears only when the user deliberately selects Sign out. Closing the browser, navigating away, or an inactivity timeout does not produce the same event. Treat the log as important accounting evidence, but do not infer a complete session history from sign-out entries.
Who should receive accountant access to QuickBooks Online?
Invite the approved accounting firm or accountant through the dedicated accountant path after verifying the engagement and address. Record the responsible partner, client scope, acceptance, review date, and removal process. Do not substitute a shared employee login, and review the accounting firm's own client-access assignments when personnel change.
What does locking the books protect in QuickBooks Online?
A lock date adds a warning or a warning plus password before changes on or before that date, depending on the selected setting. Reconcile and review completeness first. Monitor the Exceptions to Closing Date report afterward. The control helps deter prior-period edits but does not replace accurate roles, review, or evidence.
What must be transferred before deleting a QuickBooks Online user?
Transfer primary and company administration, accountant relationships, connected-app ownership, bank-feed administration, payroll, payment, billing, support, recurring transactions, reports, integrations, and open accounting work. Confirm the successor can perform each critical duty. Then remove access, review the audit trail, and preserve the approved offboarding evidence.
What should the firm do after suspected QuickBooks Online account compromise?
Use a verified channel to protect the affected Intuit account, notify the primary admin and security owner, preserve audit and integration evidence, review users, recovery methods, banks, apps, payroll, payments, settings, and closed-period changes, and involve the accountant for financial impact. Avoid bulk edits that destroy evidence before scope is understood.


