> For the complete documentation index, see [llms.txt](https://zts-guard.gitbook.io/zts-guard-discord-bot/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://zts-guard.gitbook.io/zts-guard-discord-bot/discord-cold-admin-recommendations.md).

# Discord Cold Admin Recommendations

<figure><img src="/files/memjrFjdz1VWBWvbRQJa" alt=""><figcaption></figcaption></figure>

This page covers the purpose and setup of a Cold Admin Account for Discord Server owners. A Cold Admin account provides enhanced security because it serves exclusively as the server owner and is not used for everyday activities. If a regular admin account (that is the server owner) is compromised, attackers gain full access to the server or account, making it challenging to involve support and potentially requiring days or weeks to resolve the issue (which usually isn't even possible).

Using a Cold Admin means creating a separate account dedicated solely to ownership functions, keeping it isolated from routine operations.

{% stepper %}
{% step %}

### **Discord Cold Admin Setup**

Begin by developing a team plan to determine who will set up the Cold Admin and who will have ongoing access. Everyone involved in setup and maintenance must ONLY access this account from a cold device.

A Cold Device is a factory-reset device with no previous configuration. This should be a dedicated phone or laptop, you can use an old iPhone/Android, Windows device, or even a Chromebook to keep costs down contigent it is still a device that are getting regularly updates.

The individual setting up the account should create a brand new Gmail (or email) account specifically for this Discord account. Do not use a VPN during this process, and it's best to use an incognito browser. After creating the Gmail account, immediately set up two-factor authentication (2FA) and save the backup codes. To do this, go to <https://myaccount.google.com/> and then on the left-hand side, click "Security & sign-in" and then:

* **Setup 2FA:** With authenticator app or security key but I recommend Security Key (Yubikey)
* Ensure to make sure that “skip password when possible is off”
* Do not have a phone number on the account
* Note down the 10 backup codes offline
* Ensure you have the email, password, and backup codes written offline on a piece of paper (DO NOT STORE ONLINE)

Head to <https://discord.gg> and create a new account. Use the gmail account you just created and setup above; remember to write down the email, username, password, and date of birth offline. I would recommend using a username that is not related to the business.

Once the Discord account is created, you can send your personal Discord account’s friend requests. I would also recommend that on the Cold Admin account to go the the user settings in the bottom right gear and:

* Give the profile a profile picture in the ‘My Account’ > Edit ‘User Profile’ section
* Go to ‘Content & Social’ and ensure the below settings are set correctly

<figure><img src="/files/haBkjLUw7JUxATbSHEcb" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/vvm4wRCL7f6OOb2jjjFi" alt=""><figcaption></figcaption></figure>

* I would recommend making the account invisible status so no one can see if its online or not, to do this go to the profile in the bottom left, and change the status from online → invisible

<figure><img src="/files/KIV6GGS4gKb1IxyNl72t" alt=""><figcaption></figcaption></figure>

* Once the above is completed, join the actual Discord Server that it will be owning and have it complete the verification captcha as if it was a normal account. Once it is in the server, assign it the ‘Cold Admin’ role, and then have it say a few messages in the team chat (private chat).

I typically recommend waiting around 24 hours, and then saying a few more messages in the chat, and then to transfer ownership.

To properly transfer ownership, you will go to Server Settings > Members > Search for the account in top right

**ENSURE THREE TIMES THAT IT IS THE COLD ADMIN ACCOUNT THAT YOU ARE TRANSFFERING TO FROM THE CURRENT USER ACCOUNT. If you transfer to the wrong account, it will be very very very bad…**

Once you verify it is the official account, click the three dots to the right, select ‘Transfer Ownership’ > input 2FA > and that's it!
{% endstep %}

{% step %}

### **Use of Cold Admin Account**

You should not use the Cold Admin account for day-to-day operations. It's recommended to log into both the Gmail and Discord account at least once a month.&#x20;

The Cold Admin account serves primarily to invite/add bots to the Discord server or make major changes that only the server owner can perform.

If an incident or compromise occurs, you can log into the Cold Admin account to regain control, as the server owner always maintains full access rights.

{% hint style="info" %}
Set a calendar invite reminder or a reminder on your phone to login to the GMAIL email and Discord account of the Cold Admin every 30 days.  This ensures that the account stays active and does not get deactivated from Discord for it being a dormant account.
{% endhint %}
{% endstep %}

{% step %}

### Accessing the Cold Admin

Only one user should setup the cold admin, and it should only be shared with **trusted team members!** If you want to share access then the email and password should be shared securely via password manager not showcasing the plain text information and the additional user should setup their security key (yubikey) to the account (You can associate multiple yubikeys as 2FA on one account).

{% hint style="danger" %}
Do not share any information over plain text or via any platform. It is extremely important to share securely and only to team members that you trust and that need access.  Anyone who has access or gains access to the Cold Admin account can do whatever they want in the Discord Server; including deleting it.
{% endhint %}
{% endstep %}

{% step %}

### Disclaimer

Thank you for following our recommendations below. Before implementing any changes based on this manual, please read and understand the following disclaimer carefully.

**Use at Your Own Risk:**

While the recommendations in this manual aim to enhance your Discord server's functionality and security, any changes to your server settings are made at your own risk. We strongly advise creating regular backups of your settings and data before implementing any changes.

**Compliance with Discord's Terms of Service:**

Ensure that all changes or commands applied to your server comply with Discord's Terms of Service (TOS). We are not responsible for any TOS violations resulting from the implementation of commands or settings provided in this manual.

\*\*Potential for Incident:\*\*Implementing the recommendations below assumes you are responsible for carrying them out correctly. Any incidents that occur due to failure to follow these recommendations are at your own risk.

**Keeping Documentation Updated:**

Discord regularly updates its features and functionality. It's crucial to stay informed about these changes, as they may affect the information provided in this document at the time of delivery.

**By using the information in this manual, you acknowledge and accept the terms outlined in this disclaimer. We are not liable for any damages, losses, or disruptions that may result from implementing these commands.**

**If you have any questions or concerns, please don't hesitate to contact us for clarification.**

**PLEASE NOTE: This document doesn't cover all security measures in place. This guide focuses solely on Cold Admin setup and serves as a reference with links to proper documentation should you need to make any alterations!**
{% endstep %}
{% endstepper %}
