Module 2 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: why admin accounts are the top target, least privilege roles, separating admin accounts from day-to-day work, break-glass emergency accounts, and the steps to lock it all down.
Protecting Your Admin Accounts in Microsoft 365
Why admin accounts are the crown jewels
In the last module you switched on MFA and made a stolen password close to useless. This module is about the accounts where a stolen password hurts the most: your admins. A compromised staff account is a bad day. A compromised Global Administrator account is every mailbox read, every file copied, every user locked out, and the attacker changing the locks behind them.
Attackers know this, which is why admin accounts are their favourite target. The good news is that protecting them is not expensive or complicated. It comes down to a handful of habits: give people the smallest role that does the job, keep admin work away from email and browsing, keep a spare key for emergencies, and put MFA on everything. This module walks you through each one.
A Global Administrator account is the master key to your whole building: every office, the safe, the server room, and the biscuit tin. You would not cut a copy for everyone who occasionally needs the stationery cupboard, and you certainly would not carry it to the pub. Same rules apply here.
Least privilege is a simple idea: give each person the smallest role that lets them do their job, and nothing more. Microsoft 365 has dozens of admin roles for exactly this reason. If someone only needs to reset passwords, they do not need the keys to the kingdom, they need the key to the password drawer.
The role to be stingy with is Global Administrator. Microsoft's own guidance is blunt: keep it to fewer than five people in your organisation, and in a small business two or three is usually plenty. Go past five and the Microsoft Entra admin centre starts showing you a warning card, which is Microsoft's polite way of raising an eyebrow.
The master key. Ration it.
Global Administrators can read and change almost everything in your tenant, including other admins. Powerful, necessary, and exactly what an attacker hopes to land on. Keep assignments rare and deliberate.
- Fewer than five people, per Microsoft's guidance
- Every one of them protected with MFA
- Reviewed regularly: does each person still need it?
- Never assigned just because it is easier than choosing
The right key for the right door
For everything else, Microsoft 365 has a narrower role that fits. The person gets what they need, and a compromised account gives an attacker one room instead of the whole building.
- Dozens of built-in roles to choose from
- Assigned per person, per job
- Easy to change in the admin centre later
- Limits the blast radius when things go wrong
Right role, right person: a cheat sheet
One more tip from Microsoft's guidelines: keep at least one person with the Privileged Authentication Administrator role (or a second Global Administrator) so that if a Global Administrator locks themselves out, someone can reset their password. Admins forget passwords too. We have seen it. We have been it.
Here is the habit that separates tidy tenants from risky ones: the account that reads email and browses the web should never be the account that holds an admin role. Email and browsing are how phishing arrives. If the account that clicks the dodgy link is also the account that can change your tenant, one bad click is all it takes.
The fix is a dedicated admin account for each person who does admin work. It has no mailbox, does no browsing, and only gets signed in when there is actual admin work to do. Helpfully, admin-only accounts do not need a Microsoft 365 licence, so the extra account costs you nothing.
- Email, Teams, files, browsing
- Licensed like any other user
- No admin roles, ever
- Signed in all day
- Admin work only, nothing else
- No mailbox, no licence needed
- Holds the admin role, protected by MFA
- Signed out the moment the job is done
Three small habits that make it work
Name it blandly. Microsoft suggests a naming convention that does not advertise the account's power. An account called admin.alice@ tells an attacker exactly which door to kick. Something ordinary like alicec@ does not.
Keep sessions clean. Before signing in as an admin, close unrelated browser sessions, or better, use a private browsing window. It stops your everyday logins and the admin session sharing cookies and tokens.
Sign out when you are done. Admin sessions are not for leaving open in a background tab all week. Do the job, sign out, back to the day job.
Now for the safety net. A break-glass account (Microsoft calls them emergency access accounts) is the spare master key in the fire safe. If MFA has an outage, your phones are lost in the one gym bag, or the only Global Administrator has just left the company, these accounts are how you get back into your own tenant instead of spending a very long day on the phone to Microsoft support.
We flagged these in the MFA module. Here is how to do them properly, straight from Microsoft's guidance.
At least two accounts on your onmicrosoft.com domain, not synced from any on-premises setup, each permanently assigned the Global Administrator role. Two, so that one being unavailable does not sink you.
They are not Alice's account or Bob's account. They belong to the organisation, exist only for emergencies, and no one uses them for anything day to day.
This is the whole point. If MFA or your phones are the thing that is broken, these accounts still get you in. Exclude them from your Conditional Access policies and MFA requirements.
Because they skip MFA, the password is doing all the work. Microsoft suggests at least 16 characters, and longer is better. Random, unique, written down, and locked away somewhere safe like a fireproof safe, not saved in the browser.
Any sign-in from a break-glass account should raise an alert, because it should almost never happen. Check every few months (Microsoft suggests at least every 90 days) that the accounts still work and the right people can reach the passwords.
Break glass in an emergency. Not because someone left their phone at home, not because signing in properly felt like a hassle on a Friday. Every use of these accounts should be rare enough that the alert it triggers makes somebody sit up straight.
Time to put it all into practice. Set aside half an hour, grab a cuppa, and work through these five steps in order. None of them cost anything beyond your time.
- 1Count your Global AdministratorsSign in to the Microsoft Entra admin centre at entra.microsoft.com, go to Identity, then Roles & admins, and open Global Administrator. If the list makes you wince, that is the point of this exercise.
- 2Move people to smaller rolesFor anyone who does not truly need Global Administrator, pick the least-privilege role that covers their actual job (the cheat sheet in unit 2 is a good start). In the Microsoft 365 admin centre at admin.microsoft.com, go to Users, then Active users, select the person, and choose Manage roles.
- 3Create dedicated admin accountsFor each person keeping an admin role, create a separate cloud-only account with a bland name and no licence, assign the role to that account, and remove it from their day-to-day account.
- 4Set up your two break-glass accountsTwo cloud-only accounts with Global Administrator, excluded from MFA and Conditional Access, with long random passwords stored securely offline. Set an alert on any sign-in.
- 5Put MFA on every admin, and make it strongEvery admin account gets MFA, no exceptions apart from break-glass. Where you can, step admins up to phishing-resistant methods such as passkeys (FIDO2 security keys) or Windows Hello, which even a convincing fake login page cannot trick.
On Business Premium (Microsoft Entra ID P1), you can go a step further and use Conditional Access to require phishing-resistant authentication for admin roles specifically, so strong sign-in stops being a habit and becomes a rule.
When you assign or remove roles you will need to be a Global Administrator (or Privileged Role Administrator) yourself, so do this from one of the admin accounts you are keeping, ideally the new dedicated one you created in step 3.
- Microsoft Learn: Admin account security in Microsoft 365 for business
- Microsoft Learn: Best practices for Microsoft Entra roles
- Microsoft Learn: Manage emergency access accounts in Microsoft Entra ID
- Microsoft Learn: About admin roles in the Microsoft 365 admin center
- Microsoft Learn: Least privileged roles by task in Microsoft Entra ID
Steps were current at the time of writing (July 2026). Microsoft occasionally moves things around the admin centre, so screens may vary slightly.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. How many Global Administrators does Microsoft recommend an organisation have?
2. Someone on your team only needs to reset user passwords. Which role should they get?
3. What should a dedicated admin account be used for?
4. Which of these is true of a properly set up break-glass account?
5. For MFA on admin accounts, what does Microsoft recommend where possible?