ISSUE 29 · 6 MIN READ ·

You have six people with the keys to everything

Global Administrator got handed out to whoever needed to change one setting. Now several everyday accounts can rewrite your whole Microsoft 365 tenant. How to count them.

It rarely happens on purpose. Someone needed to change one setting that only an administrator could reach — add a domain, reset a licence, unblock a mailbox — and the quickest way to unblock them was to make them a Global Administrator for the afternoon. The afternoon passed. The role stayed. Repeat that a handful of times over a couple of years, across a few different people, and one day you look up to find half a dozen everyday accounts each holding the highest level of access your Microsoft 365 tenant can grant.

Global Administrator isn’t “can do quite a lot”. It’s the keys to everything: it can read or reset any account, change security settings, grant itself access to any mailbox or file, and hand the same power to someone else. Each of those accounts is a full takeover waiting to happen — because if any one of them is phished, the attacker doesn’t get a foothold, they get the whole building.

This is the quiet failure. Nothing is broken. Everyone can do their job — rather too much of it, in fact. The risk isn’t that the access is being misused; it’s that so many copies of the master key exist, and each one is only as safe as the person holding it on their worst, most distracted day.

Why it stays invisible

Privilege only ever creeps in one direction. Granting an admin role is a two-minute job someone does under mild pressure to unblock a colleague. Taking it away is a job with no deadline, no reminder, and no obvious owner — so it never happens. Nobody wakes up and decides the organisation should have six Global Administrators. It accumulates, one reasonable exception at a time.

It stays hidden because the symptom of over-provisioning is nothing at all. An account with too much power looks exactly like an account with the right amount, right up until it’s the one that gets caught by a convincing phishing email. And the people most likely to hold a spare admin role — busy, senior, trusted — are also the ones least likely to be running a hardened, locked-down account for their day-to-day mail.

The security baselines are blunt about the right number. The widely used Microsoft 365 benchmark from the Center for Internet Security (CIS) says to ensure between two and four Global Administrators are designated — more than one, so no single admin goes unwatched and you’re never locked out; no more than four, so every one of them can be protected properly and accounted for by name.

Find it yourself

You can get an exact count of who holds the keys in about ten minutes, from the admin centre, without any special tooling.

  1. Sign in at admin.microsoft.com with an account that can view roles.
  2. In the left menu, open Roles, then Role assignments (older wording: Roles → Admin roles).
  3. Find Global Administrator in the list (on the Microsoft Entra ID tab, if tabs are shown) and open it to see its Assigned members.
  4. Write the names down. For each one, ask a plain question: does this person genuinely need to change tenant-wide settings as part of their job — or did they need it once?

For a fuller view, do the same in the Microsoft Entra admin centre (entra.microsoft.com): open Roles & admins (written in full as Roles and administrators on the page itself), select Global Administrator, and read the assignments. This also shows any accounts that hold the role permanently versus those granted it just when needed.

Tip: while you’re there, note any Global Administrator account that is a person’s everyday mailbox. The recommended pattern is that highly privileged roles sit on separate, tightly protected accounts, not the address someone also uses to receive newsletters.

The fix

Good looks like a short, named list. Two to four Global Administrators, each one a person you can point to and justify, each protected with strong multi-factor authentication (the second step — a code or a tap on the phone — that stands between a stolen password and your tenant). Everyone else who occasionally needs elevated access gets a narrower role that covers just their task — there are dozens of built-in ones, from Helpdesk Administrator to Exchange Administrator — rather than the master key.

For the accounts you can’t justify, don’t agonise: demote them. Removing the Global Administrator role doesn’t remove the person or their mailbox; it just takes back a power they weren’t using. If it turns out they needed it, granting it again takes two minutes — and now it’s a decision someone made on purpose.

To stop the creep returning, make elevation temporary by default. Microsoft’s Privileged Identity Management lets someone request the admin role only for the window they actually need it, after which it lapses on its own — which quietly solves the “granted it once, never took it back” problem at the root. Even without that, a twice-a-year glance at this one list is enough to keep the number honest. It’s a small, calm habit, and it turns “who has the keys?” from a question nobody can answer into one you can answer in a sentence.

PS — keeping that admin list to the right handful across a changing team is exactly the kind of slow drift AuthScope is meant to flag. Only worth it if the twice-a-year manual check is more than you want to remember.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

One real, fixable exposure every week. Free.