Routine administrators
Give named administrators task-specific roles at the smallest workable scope. Document what each person administers, why the access is needed, and who approves it.
Microsoft recommends assigning Global Administrator to fewer than five people and maintaining at least two separate cloud-only emergency access accounts. The useful target is not a magic total: it is the smallest defensible set of standing human administrators, backed by resilient emergency access and narrower roles for routine work.
Microsoft’s current role guidance recommends assigning Global Administrator to fewer than five people. It also recommends two cloud-only emergency access accounts that are permanently assigned the role. Those are complementary controls, not permission to give every administrator Global Administrator for convenience.
For normal operations, start with the task. Microsoft publishes a least-privileged role by task reference covering identity, applications, devices, logs, Conditional Access, authentication methods, and other administrative work. If a narrower role performs the job, Global Administrator is usually the wrong default.
Each category solves a different administrative need. Review them separately, then test the complete model for coverage and lockout risk.
Give named administrators task-specific roles at the smallest workable scope. Document what each person administers, why the access is needed, and who approves it.
Where licensing and operating processes support it, use Microsoft Entra Privileged Identity Management for time-bound activation instead of permanent standing access. Activation controls should match the role and support path.
Maintain at least two independent cloud-only accounts for recovery. Microsoft’s emergency-access guidance covers authentication, storage, monitoring, validation, and Conditional Access exclusions.
Use the companion guide to audit Microsoft 365 administrator roles, or review the deeper Entra ID Security Assessment.
Four standing Global Administrators can still be excessive when narrower or eligible roles would cover the work. The Microsoft ceiling is a guardrail, not an entitlement.
Emergency accounts should be reserved for recovery. If they are used for daily administration, the organization loses an independent recovery path and obscures normal accountability.
Privilege reduction should be staged. Confirm emergency access, ownership, replacement roles, support coverage, and rollback before removing a critical assignment.
A role can reach a principal directly, through a role-assignable group, at a narrower scope, or through eligible activation. The inventory must preserve those distinctions.
Two emergency access accounts are not a routine administration team. The operating model still needs enough named, appropriately scoped administrators to provide coverage without giving everyone permanent Global Administrator access.
No. Seniority does not define the permission required for a task. Use Microsoft’s task-to-role guidance and assign the narrowest role and scope that supports the person’s actual responsibilities.
No. Microsoft’s emergency-access guidance accounts for scenarios in which normal activation or approval dependencies are unavailable. Emergency accounts and eligible access solve different problems.
Broad application or service-principal privilege should be treated as an exception requiring a documented technical dependency, owner, credential protections, monitoring, and a plan to reduce permission. Do not assume a non-human identity is safer than a person.
These links open the current Microsoft Learn documentation in a new tab. TenantShield is not endorsed by Microsoft.
Use the free checker for an initial identity signal, or request an assessment for assignment evidence, operating context, and a prioritized privilege plan.