How to Protect Global Admin Accounts in Microsoft 365 and Entra ID
Retrospective: this article looks back at events from September 2017, written in 2026 with the benefit of hindsight.
Global Administrators can change every setting, read every mailbox and create new admins in Microsoft 365. Protecting those accounts is the highest-value identity task you have. Here is how.
Step 1: Count and reduce
List everyone with Global Administrator and other highly privileged roles (Privileged Role Administrator, Exchange Administrator, SharePoint Administrator, Security Administrator). Microsoft recommends fewer than five Global Administrators. Move people to less privileged roles that match their job.
Step 2: Separate admin accounts
Admins should use a dedicated cloud-only account for admin work — no mailbox, no web browsing, not synchronized from on-premises Active Directory. That way an on-prem compromise cannot reach cloud admin rights.
Step 3: Require phishing-resistant MFA
Create a Conditional Access policy targeting directory roles that requires the phishing-resistant MFA authentication strength (passkeys, FIDO2 security keys or Windows Hello for Business).
Step 4: Make admin rights just-in-time
With Entra ID P2, use Privileged Identity Management (PIM) so admins are eligible for roles and activate them for a limited time with justification and MFA, optionally with approval.
Step 5: Protect from risky devices
Require admin sign-ins to come from compliant or privileged access devices.
Step 6: Keep break-glass accounts
Maintain two emergency access accounts excluded from Conditional Access, with strong passwords stored securely and FIDO2 keys, and alert on any sign-in.
Step 7: Monitor
Alert on role assignments, PIM activations outside business hours and admin sign-ins from new locations.
Verify
Review admin role membership monthly. Any permanent Global Admin who is not a break-glass account should have a documented reason.
- Deloitte's Email Breach (Sept 2017): An Admin Account Without MFA Incident Teardowns
- Detecting Compromised Admin Account: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Privileged Accounts Are the Keys to the Kingdom CIO Briefings