Microsoft 365 security guide
Microsoft 365 admin security: review Global Administrator access
Global Administrator access can change critical settings across your Microsoft 365 environment. A useful review asks who has that access, why they need it, how it is protected and how the business would recover if normal administrator access stopped working.
Published · Last reviewed · By CyberProva
Run your free Microsoft 365 security assessmentNo card required · Optional read-only Microsoft 365 connection
How many Global Admins should you have?
Microsoft recommends assigning the role to fewer than five people and using narrower roles where possible. Treat this as a review prompt, not a claim that any particular count makes an organisation secure.
- Identify direct assignments and privileged access through groups.
- Separate standing access from eligible or time-limited access.
- Review provider accounts, former staff and unexplained assignments.
How should administrator access be protected?
Ask whether people need the full role or a narrower permission. Separate administration from everyday email and browsing.
- Use named accounts and appropriate MFA protection.
- Review authentication and access-policy exceptions.
- Record the business reason, owner and review date for each assignment.
What about emergency access?
Recovery needs deliberate planning. Ask your administrator to document emergency access, protection, monitoring and testing before making changes to privileged roles.
- Know who can recover access if normal authentication fails.
- Review emergency-access accounts separately from routine administrators.
- Do not delete access solely to reach a target count without a recovery plan.
Make the answer provable
Evidence to request
- A dated privileged-role assignment report.
- Evidence of administrator MFA and separate accounts.
- A reviewed emergency-access procedure and access-removal record.
How CyberProva helps
CyberProva includes read-only Global Administrator review where the necessary access is available, alongside evidence-based privileged-access controls. Review the findings with your provider; a role count cannot establish whether every assignment is justified.
See what a Microsoft 365 security assessment should cover →
See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions
Common questions
Is one Global Admin always safer?
A low count can still leave excessive privilege or a single point of failure. Consider least privilege and recovery together.
Should our IT provider have Global Admin access?
They may need privileged access for agreed tasks. Ask which permissions are needed, whether access can be narrower or time-limited, and how it is reviewed.
Official guidance
Use these sources with your IT provider when reviewing the controls described above.
From assumptions to evidence
See what needs attention in your organisation
Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.
Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.