Too many Global Admins in Microsoft 365

Microsoft 365 Global Admin security for Ontario firms: review privileged roles, reduce permanent access, and protect emergency accounts without risking lockout.

Short on time? Let your favourite AI sum up Teclara.

Wadhah Hussain, Founder · Updated · First published

Global Admin can change the tenant’s controls

A founder’s original setup account, an outside consultant’s account, and an office manager’s account can all retain Global Administrator long after the work that required it ends. Reviewing the employee list alone will not show whether that privileged access is still justified.

Microsoft recommends assigning Global Administrator to fewer than five people. That is a ceiling to work below, not a target to fill. The role can change nearly every administrative setting and can elevate access to data. See Microsoft’s role-management best practices.

A compromised standard account can expose the files and messages available to its user. A compromised administrator may also change sign-in controls or grant further access. The Microsoft 365 account-takeover guide explains the surrounding sign-in and session controls.

Record who holds the role and why

In the Microsoft Entra admin centre, open Entra ID, then Roles & admins, and inspect Global Administrator assignments. Record each principal, its owner, the work that needs the role, and whether the assignment is permanent, time-limited, or eligible for activation. Check assignments through role-assignable groups as well as direct assignments.

Review outside-provider access separately, including delegated administration. An absent provider account in the direct assignment list does not prove that all partner access is gone. Check applications and service identities with powerful permissions as another workstream; removing a person’s role does not revoke an application’s consent.

Keep the initial export as the before-state. Give unexplained assignments an owner to investigate. Do not remove the only working administrator while deciding which account should take over.

Replace broad roles with the access the task needs

Match each recurring job to its least-privileged role and scope. User administration, mail configuration, billing, and authentication support do not all need the same permissions. Check Microsoft’s least-privileged roles by task before assigning a replacement.

Test the replacement with the person responsible for the work. Confirm both that the intended task succeeds and that unrelated administration is unavailable. Keep a controlled recovery path during the change, then remove the broader assignment and record the result.

Where licensing supports it, Privileged Identity Management can make access eligible for time-limited activation. Configure approval and authentication requirements to suit the role. PIM requires Microsoft Entra ID P2 or Microsoft Entra ID Governance; check the current governance licensing requirements before including it in a plan.

Separate daily work from administration

Use a dedicated identity for privileged work. Keep normal email, document collaboration, and general browsing in the everyday account. Protect the administrator identity with phishing-resistant authentication and use a trusted, managed device.

Account separation reduces the occasions when a routine message or document is opened in a privileged session. It does not replace device security, session protection, or review of administrator activity. Apply sign-in restrictions carefully and verify that the people doing the work can still administer the tenant.

These changes belong with the broader Microsoft 365 and Google Workspace security baseline, so administrator controls, recovery, and logging are reviewed together.

Protect emergency access before removing roles

Microsoft recommends two or more cloud-only emergency access accounts. They should not depend on federation or synchronization from an on-premises directory. Keep their Global Administrator assignment permanently active, and use phishing-resistant authentication with a different dependency from normal administration. Follow the emergency-access guidance for the full configuration.

These accounts are for recovery, not everyday administration. Store credentials securely, document who can authorize access, alert on use, and test the procedure regularly. Any Conditional Access exclusions should be deliberate and documented; do not interpret emergency access as permission to leave an unprotected password-only account.

Validate recovery before reducing other access. Record the test date, the person who performed it, and any dependency that could still prevent sign-in. Investigate unexpected emergency-account activity.

Keep a record of the access you changed

Finish with the before-and-after assignments, the reason for each remaining privileged account, evidence that routine tasks still work, and the emergency-access test. Review the list again after staff, provider, and project changes.

If you discover suspicious administrator activity, follow the compromised-credentials response guide and preserve evidence before treating it as routine cleanup.

Export the current Global Administrator assignments and assign an owner to every entry. Teclara’s Microsoft 365 Tenant Cleanup can scope the role changes alongside stale accounts, sharing, and sign-in settings.

Short on time? Let your favourite AI sum up Teclara.

Want this handled for your organization?

Book a call to see how Teclara helps businesses and nonprofits put these controls in place without disrupting day-to-day work.