Microsoft 365How-To & HardeningRetrospectives

How to Protect Global Admin Accounts in Microsoft 365 and Entra ID

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2017, written in 2026 with the benefit of hindsight.

Global Administrators can change every setting, read every mailbox and create new admins in Microsoft 365. Protecting those accounts is the highest-value identity task you have. Here is how.

Step 1: Count and reduce

List everyone with Global Administrator and other highly privileged roles (Privileged Role Administrator, Exchange Administrator, SharePoint Administrator, Security Administrator). Microsoft recommends fewer than five Global Administrators. Move people to less privileged roles that match their job.

Step 2: Separate admin accounts

Admins should use a dedicated cloud-only account for admin work — no mailbox, no web browsing, not synchronized from on-premises Active Directory. That way an on-prem compromise cannot reach cloud admin rights.

Step 3: Require phishing-resistant MFA

Create a Conditional Access policy targeting directory roles that requires the phishing-resistant MFA authentication strength (passkeys, FIDO2 security keys or Windows Hello for Business).

Step 4: Make admin rights just-in-time

With Entra ID P2, use Privileged Identity Management (PIM) so admins are eligible for roles and activate them for a limited time with justification and MFA, optionally with approval.

Step 5: Protect from risky devices

Require admin sign-ins to come from compliant or privileged access devices.

Step 6: Keep break-glass accounts

Maintain two emergency access accounts excluded from Conditional Access, with strong passwords stored securely and FIDO2 keys, and alert on any sign-in.

Step 7: Monitor

Alert on role assignments, PIM activations outside business hours and admin sign-ins from new locations.

Verify

Review admin role membership monthly. Any permanent Global Admin who is not a break-glass account should have a documented reason.

protect global admin microsoft 365Deloitte email breach2017

More on this story