CIO Brief: Privileged Accounts Are the Keys to the Kingdom
Retrospective: this article looks back at events from September 2017, written in 2026 with the benefit of hindsight.
The short version: Deloitte's 2017 email breach reportedly started with one administrator account protected only by a password. Admin accounts are the keys to your entire cloud environment — and they deserve the strongest protection you have.
Why privileged accounts are different
An ordinary user account can expose that person's email and files. An administrator account can expose everyone's, create new accounts, turn off security features and erase evidence. Attackers know this and target administrators first.
The business impact
- Total compromise: one stolen admin account can mean every mailbox and file.
- Long recovery: attackers with admin rights create hidden ways back in.
- Client trust: for professional services and regulated firms, a breach of client data is existential.
Questions to ask your team
- How many people have full administrator rights in Microsoft 365 and Azure today?
- Do all of them use phishing-resistant multi-factor authentication?
- Do admins have permanent rights, or do they activate them only when needed?
- Would we be alerted if someone new became an administrator?
What good looks like
Fewer than five full administrators, separate admin accounts, the strongest form of MFA, time-limited admin rights, and alerts on every change to who holds them.
The decision
Ask for the current count of full administrators and a plan to reduce it this quarter. It is a small number that says a lot about your risk.
- Deloitte's Email Breach (Sept 2017): An Admin Account Without MFA Incident Teardowns
- How to Protect Global Admin Accounts in Microsoft 365 and Entra ID How-To & Hardening
- Detecting Compromised Admin Account: Defender XDR and Sentinel Hunting Queries Detection & Response