Module 2 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: why admin accounts are the top target, least privilege roles, separating admin accounts from day-to-day work, break-glass emergency accounts, and the steps to lock it all down.

    Protecting Your Admin Accounts in Microsoft 365

    Module 2 · FoundationsUnit 1 of 6 · about 1 min

    Why admin accounts are the crown jewels

    In the last module you switched on MFA and made a stolen password close to useless. This module is about the accounts where a stolen password hurts the most: your admins. A compromised staff account is a bad day. A compromised Global Administrator account is every mailbox read, every file copied, every user locked out, and the attacker changing the locks behind them.

    Attackers know this, which is why admin accounts are their favourite target. The good news is that protecting them is not expensive or complicated. It comes down to a handful of habits: give people the smallest role that does the job, keep admin work away from email and browsing, keep a spare key for emergencies, and put MFA on everything. This module walks you through each one.

    The master-key way to think about it

    A Global Administrator account is the master key to your whole building: every office, the safe, the server room, and the biscuit tin. You would not cut a copy for everyone who occasionally needs the stationery cupboard, and you certainly would not carry it to the pub. Same rules apply here.

    StartCloud Assistant

    Online

    G'day! 👋 I'm the StartCloud Assistant. How can I help you today?