How Do You Stop Employees From Doing DIY IT Fixes Without Being a Jerk?

Every IT pro who’s ever been on-call at 2 a.m. That said, there are exceptions. knows the sinking feeling when a user says, “I tried to fix it myself.” Spoiler alert: It rarely fixes itself. In today’s cloud-driven world—where Microsoft 365 reigns supreme and users can look up troubleshooting steps faster than you can say “helpdesk ticket”—DIY IT fixes are a double-edged sword. They can be a sign of empowerment, but unchecked, they can lead to security gaps, data loss, and hours of recovery work.

How do you stop these well-meaning but potentially dangerous DIY IT interventions without becoming the office villain? Let’s break down the problem and share proven strategies so you can protect your business without being ‘that IT guy.’

Why DIY Troubleshooting in Business IT Is a Risky Business

We get it.

When users spot a problem, they want it fixed *now.* Waiting for a formal ticket to get processed can feel like slow-motion torture. But here’s the thing: home hacks and quick fixes don’t always translate into business IT environments, especially when Microsoft 365 and Windows are involved.

    Misleading tutorials: YouTube has a wealth of tutorials—some good, some downright outdated and dangerous. A user following an old Microsoft 365 Powershell fix from 2015? That’s a disaster waiting to happen. Unverified AI answers: Sure, AI chat assistants can spit out answers fast. But they don’t know your tenant’s specific configurations or security policies. Blindly running those answers can cause misconfigurations or exposure. Risky scripts: AI-generated or copied scripts sometimes contain commands that can delete data or disable critical security settings — and users might not recognize these pitfalls. Security risks: Users messing with permissions, MFA settings, or mailbox rules without coordination can open up vulnerabilities or compliance issues.

Here's what kills me: stop right there: before someone clicks “run” on a solution they found online or a snippet from chatgpt, they need a clear path to escalate instead of winging it.

image

Crafting IT Policies for Users That Actually Work

Let’s be honest — policies are often written in a manner that overwhelms or alienates users. IT policies for users don’t need to be boring PDFs buried in a shared drive. Your goal is to create *friendly*, clear, and easy-to-follow guidelines that set boundaries without stifling initiative.. Pretty simple.

Checklist Before You Write Your Policy

Identify common DIY troubleshooting attempts your team faces (e.g., changing password policies, toggling MFA, installing unapproved apps). https://technivorz.com/what-are-the-most-common-diy-it-mistakes-businesses-are-seeing-in-2026/ Explain *why* certain actions need IT oversight — focus on business impact, not just rules. Outline what users *can* do themselves, and what they should escalate. Provide a clear, simple path to escalation (e.g., the helpdesk ticket portal link, phone number, chat channel). Include reminders about the risks of using unofficial online guides or scripts. Keep it short and use plain language.

Sample Policy Snippet

**Before You Try a Fix Yourself:** - Check if the issue is stopping you from working. - Do NOT change security settings like MFA or admin permissions. - Avoid running scripts or commands from online forums or AI without approval. - Contact IT helpdesk immediately for assistance: [[email protected]]

The Helpdesk Escalation Process: Make It a Breeze

If Website link users think calling IT means a bureaucratic headache or slow response, guess what? They’ll try to DIY next time. You want your helpdesk to feel like an MVP, known for quick and clear communication.

Key Tips to Improve Your Helpdesk Process

    Fast triage: Respond quickly to acknowledge issues. Even automated responses help users feel heard. Clear status updates: Users hate the “radio silence” wait. Set expectations for resolution times. Direct communication channels: Allow users to chat or call IT easily, rather than just email or ticket submission. Document common fixes: Maintain a knowledge base with approved steps that users can safely try. Ask “What changed right before this started?”: This golden question can often pinpoint root causes fast and discourage DIY changes.

Security Awareness Training: Your Best Ally

One-off policies and processes aren’t enough. Regular security awareness training builds a culture where users understand the “why” behind IT rules. It transforms potential DIY saboteurs into security partners.

Training Focus Areas Relevant to DIY IT Fixes

Topic Why It Matters Training Tips Phishing & Social Engineering Users may try “quick fixes” triggered by suspicious messages or scams. Simulated phishing exercises and teach users to escalate suspicious activity. Safe Use of Microsoft 365 Misconfiguration of SharePoint, OneDrive, Teams permissions can expose data. Demonstrate approved ways to troubleshoot minor issues and whom to contact for larger problems. Recognizing Risky Scripts & AI-generated Advice Users may search for fixes on YouTube or AI, unaware of hidden dangers in scripts. Explain how scripts can harm environments, and encourage verifying all commands with IT. Understanding MFA & Security Settings Temptation to disable MFA “just to test” is risky. Teach the importance of MFA, and have a clear process for any changes.

Working With Microsoft 365: Specific Considerations

Microsoft 365 is powerful but complex. DIY fixes designed for consumer apps might cause disaster in your tenant.

    Powershell scripts: Commonly suggested online fixes may target outdated cmdlets or assume elevated permissions users don’t have. Conditional Access & MFA: Improper adjustments can lock users out or open security holes. Data loss prevention policies: Changes made outside IT’s oversight can compromise compliance.

Before clicking “run” on scripts or changing configurations, users should always consult IT to verify the action against your tenant’s policies and architecture.

Final Thoughts: Being Clear and Collaborative—not Controlling

Letting users know they can’t handle their own fixes without consequence sometimes comes across as “jerky.” But you can set clear expectations with empathy, education, and support. Your goal isn’t to kill initiative — it's to harness it responsibly so the business stays secure and productive.

Remember these points before your next “No, don’t do that” conversation:

    Explain the business impact of DIY fixes you’re asking them to avoid. Provide simple escalation paths and fast helpdesk response. Share the WHY behind security and policy rules with regular, engaging training. Ask what changed before the issue started—it makes people less defensive and gets better data fast.

With a thoughtful approach, you *can* stop DIY IT fixes from snowballing into major incidents—without being the office jerk who shuts down all curiosity.

Now, go update your IT policy, your helpdesk scripts, and yes — maybe bookmark a few better YouTube videos to pass along!

image