Identity guidance · Global Administrator

How many Global Administrators should Microsoft 365 have?

Microsoft recommends assigning Global Administrator to fewer than five people and maintaining at least two separate cloud-only emergency access accounts. The useful target is not a magic total: it is the smallest defensible set of standing human administrators, backed by resilient emergency access and narrower roles for routine work.

The direct answer

Fewer than five people—with emergency access counted separately.

Microsoft’s current role guidance recommends assigning Global Administrator to fewer than five people. It also recommends two cloud-only emergency access accounts that are permanently assigned the role. Those are complementary controls, not permission to give every administrator Global Administrator for convenience.

Use two registers. Track named people who can perform routine administration separately from emergency accounts that exist only to recover access. A simple count that mixes the two hides whether standing human privilege is excessive or emergency access is fragile.

For normal operations, start with the task. Microsoft publishes a least-privileged role by task reference covering identity, applications, devices, logs, Conditional Access, authentication methods, and other administrative work. If a narrower role performs the job, Global Administrator is usually the wrong default.

A defensible operating model

Design for routine work, elevation, and recovery.

Each category solves a different administrative need. Review them separately, then test the complete model for coverage and lockout risk.

01

Routine administrators

Give named administrators task-specific roles at the smallest workable scope. Document what each person administers, why the access is needed, and who approves it.

02

Eligible privileged access

Where licensing and operating processes support it, use Microsoft Entra Privileged Identity Management for time-bound activation instead of permanent standing access. Activation controls should match the role and support path.

03

Emergency access

Maintain at least two independent cloud-only accounts for recovery. Microsoft’s emergency-access guidance covers authentication, storage, monitoring, validation, and Conditional Access exclusions.

Review the real exposure

Ask more than “How many?”

  • Who or what has the role? Identify users, role-assignable groups, service principals, guests, and emergency accounts—not only familiar administrator names.
  • How was it assigned? Record direct and group-based assignment, tenant or resource scope, and whether access is active, eligible, permanent, or time-bound.
  • What task requires it? Replace broad access when a Microsoft Entra, Exchange, SharePoint, Teams, Intune, Security, or other focused role covers the operating need.
  • How is it protected? Review authentication, Conditional Access treatment, privileged-workstation expectations, activation controls, alerting, and incident ownership.
  • Is it still used? Compare the approved purpose with sign-in, activation, and audit evidence. “We may need it someday” is not a sufficient justification for routine standing privilege.
  • Can the tenant recover? Validate emergency access without turning the emergency accounts into everyday administrator identities.

Use the companion guide to audit Microsoft 365 administrator roles, or review the deeper Entra ID Security Assessment.

Common mistakes

Avoid reducing a privilege decision to a dashboard number.

Treating “under five” as the goal

Four standing Global Administrators can still be excessive when narrower or eligible roles would cover the work. The Microsoft ceiling is a guardrail, not an entitlement.

Counting emergency accounts as operators

Emergency accounts should be reserved for recovery. If they are used for daily administration, the organization loses an independent recovery path and obscures normal accountability.

Removing access before validating recovery

Privilege reduction should be staged. Confirm emergency access, ownership, replacement roles, support coverage, and rollback before removing a critical assignment.

Reviewing users but missing assignment paths

A role can reach a principal directly, through a role-assignable group, at a narrower scope, or through eligible activation. The inventory must preserve those distinctions.

Common questions

Global Administrator count and control.

Are two Global Administrators enough?

Two emergency access accounts are not a routine administration team. The operating model still needs enough named, appropriately scoped administrators to provide coverage without giving everyone permanent Global Administrator access.

Should every senior IT employee be a Global Administrator?

No. Seniority does not define the permission required for a task. Use Microsoft’s task-to-role guidance and assign the narrowest role and scope that supports the person’s actual responsibilities.

Does Privileged Identity Management remove the need for emergency accounts?

No. Microsoft’s emergency-access guidance accounts for scenarios in which normal activation or approval dependencies are unavailable. Emergency accounts and eligible access solve different problems.

Should a service account have Global Administrator?

Broad application or service-principal privilege should be treated as an exception requiring a documented technical dependency, owner, credential protections, monitoring, and a plan to reduce permission. Do not assume a non-human identity is safer than a person.

Primary sources

Microsoft guidance used for this article.

These links open the current Microsoft Learn documentation in a new tab. TenantShield is not endorsed by Microsoft.

Turn the administrator count into a defensible access model.

Use the free checker for an initial identity signal, or request an assessment for assignment evidence, operating context, and a prioritized privilege plan.