How to Secure Help Desk and Support Roles in Microsoft 365
Retrospective: this article looks back at events from April 2019, written in 2026 with the benefit of hindsight.
Help desk and support staff can reset passwords, change MFA methods and see user data. Here is how to scope those roles tightly in Microsoft 365 and Entra ID.
Step 1: Use the right built-in roles
Replace broad roles with task-specific ones:
- Helpdesk Administrator or Password Administrator for password resets of non-admin users.
- Authentication Administrator for managing MFA methods of non-admin users.
- User Administrator only where account creation and group management are needed.
- Exchange Recipient Administrator for mailbox tasks, not Exchange Administrator.
Avoid giving Global Administrator to help desk staff.
Step 2: Scope with administrative units
Use administrative units to limit a support team's roles to specific departments, regions or subsidiaries. A regional help desk then can't reset passwords for users elsewhere — or for executives, if you place them in a restricted management administrative unit.
Step 3: Make roles just-in-time
With Privileged Identity Management, make support roles eligible rather than permanent, with activation requiring MFA and justification.
Step 4: Protect support accounts
- Separate admin accounts for support work.
- Phishing-resistant MFA.
- Conditional Access requiring compliant devices.
Step 5: Govern external support
For managed service providers, use granular delegated admin privileges (GDAP) with time-limited, least-privilege roles instead of legacy delegated admin.
Step 6: Monitor
Alert on unusual volumes of password resets or MFA changes by a single support account, and on resets of privileged users.
Verify
Review support role assignments quarterly with access reviews.