Common problem

Who owns your admin account?

Administrative rights are usually handed out for a reason and then never reviewed. Years later nobody is certain who holds them, or whether the business could get in without asking somebody else.

Ownership and access are different things, and confusing them is what strands businesses. Plenty of people can be given administrative access. Only one entity should own the tenant, and that entity is the business.

The test is not who knows the password today. It is whether the business could still administer its own Microsoft 365 tomorrow if a particular person or supplier stopped answering the phone.

,

What good looks like

  • The tenant belongs to the business. Not to an employee, not to a contractor, and not to a provider's account.
  • Administrative accounts are separate from daily accounts. Admin work happens in an account that does not also read email all day.
  • Global administrator is rare. Two or three people, not everybody who once needed to do one job.
  • A break glass account exists. Kept for emergencies, excluded from the policies that could lock it out, credentials stored somewhere controlled.
  • MFA is on every administrative account. Without exception, including the ones people forget exist.
  • Recovery details are reachable by the business. Not a phone number belonging to somebody who left in 2023.
  • Somebody reviews it. Twice a year is enough to stop the list drifting back.
,

How it goes wrong

Nobody sets out to lose control of their own tenant. It happens the same few ways.

It was set up on a personal account

Fastest at the time, and it means the business is now a guest in its own environment. Getting out of this is tenant takeover.

The admin left

With the authenticator app on their phone and the recovery email pointing somewhere nobody reads. The access half of this is former employee access.

Everybody became an admin

Because it was quicker than working out which permission was actually needed. Each grant was reasonable. The total is not.

The provider holds everything

Which works perfectly until the relationship ends, at which point it is the only thing anyone can talk about.

,

How to check it this week

  1. List who holds administrative roles

    Not who you think. What the tenant actually reports.

  2. Ask which of them still work there

    This question alone usually finds something.

  3. Check where recovery goes

    The recovery email and phone number on the administrative accounts.

  4. Confirm MFA on every admin account

    Including any account that exists for a system rather than a person.

  5. Create or confirm a break glass account

    And write down where its credentials live, in a place that is not the tenant.

  6. Remove what is not needed

    Roles first, accounts second, and record what you removed.

,

Who this is for

  • You are not certain who has administrative rights.
  • The tenant was set up by somebody who has left.
  • A provider holds the only administrative account.
  • You are being asked to demonstrate access control to a customer or an insurer.

When this is not the right fit

  • You are locked out entirely right now. Start with tenant takeover instead, because the route is different.
  • You want access to a tenant your business does not own.
,
,

Common questions

Should our admin account be a person?

No. An account named after a person leaves with that person, and it also means everyday email and administrative rights live in the same place, which is exactly what an attacker wants.

The pattern that works is a separate administrative account owned by the business, used only for administration, with the recovery details held by the business rather than on somebody's phone.

How many global administrators should we have?

Fewer than most tenants have. Two or three people who genuinely need it, plus a break glass account kept for emergencies, covers almost every small business.

What we usually find instead is five or six, several of whom got the role once for a specific task in 2022 and never had it removed.

What is a break glass account?

An administrative account that exists only to get you back in when normal access fails: the person with the authenticator app has left, or a policy has locked everybody out.

It is excluded from the policies that could lock it out, its credentials are stored somewhere physical and controlled, and its use is something you would notice. It is deliberately boring and it is the thing people wish they had set up.

Our IT provider holds the admin account. Is that normal?

It is common, and it is fine for them to hold administrative access. It is not fine for them to hold the only administrative access.

The test is simple: if that relationship ended tomorrow, could your business still get into its own tenant? If the answer is no, that is worth fixing while everyone is still friendly.

,
Get a Quote

Find out who actually holds it

The review lists every account with administrative rights, when each last signed in, and which belong to people who have left.

Call now Request a quote