Create a new local user, then give it only the permissions it needs and use that account for daily work.
From the knowledge base:
1. Go to Management > User Management > Local Users > Users.
2. Click Add.
3. Enter the user’s information; username and password are required.
4. Add the user to a group so it inherits that group’s management permissions.
5. Confirm the settings and click Add.
For least privilege:
- Use the Users group for normal access.
- Only trusted accounts should be in the APM default admin group, because that group has full access to Management Center and Recovery Portal.
- The super administrator is created during first-time installation and has full access to the whole system.
If your goal is to stop using the default admin for everyday access, the sources say:
- Renaming the default admin name is not possible.
- After creating a custom admin user, you can disable the default admin user.
- In older DSM guidance, users with administrative rights were managed through the administrators group, and you could create a new admin user, assign it to that group, and remove the old one from it.
Sources used: [2], [4], [5], [12]