If an attacker compromises one regular staff mailbox, that's bad. If they compromise a Global Administrator account, they control your entire Microsoft 365 tenant - every mailbox, every file, every user. Admin accounts deserve meaningfully tighter controls than everyday user accounts, and most small businesses haven't got around to setting that up.
Minimise Who Holds Admin Access
Start by reviewing who currently holds Global Administrator or other elevated roles, and reduce this to as few people as genuinely need it - Microsoft's own guidance suggests fewer than five for most organisations. Everyone else should hold only the specific role they actually need (a helpdesk admin role, for instance) rather than a blanket Global Administrator assignment.
Use Separate Admin Accounts
The single most effective, most overlooked control: give people who need admin access a dedicated admin account, separate from the one they use for email and daily work. If their everyday account is phished, the attacker doesn't automatically inherit admin rights along with it. This does add a small amount of friction, which is exactly the point - admin actions shouldn't be as casual as checking email.
Enforce Strong MFA, Not Just Any MFA
Admin accounts should use phishing-resistant methods where possible - a FIDO2 security key or passkey rather than SMS. See our guide on passkeys and phishing-resistant MFA for the difference between MFA methods and which suit admin-level accounts specifically.
Apply Conditional Access Specifically to Admin Roles
Beyond baseline MFA, Conditional Access policies can require admin sign-ins to come from specific trusted locations or managed devices, and can block or flag sign-in attempts that look unusual. See our guide on Conditional Access explained for how this works in practice.
Set Up a Properly Secured Break-Glass Account
Keep at least one emergency access account, deliberately excluded from Conditional Access policies, with a very strong password stored securely (not in an easily accessible location) and used only when normal admin access genuinely can't be reached. Monitor sign-ins to this account closely - any use of it should be a known, deliberate event, not a surprise.
Use Privileged Identity Management for Just-in-Time Access
For businesses on Microsoft 365 E5 or Entra ID P2, Privileged Identity Management allows admin roles to be activated only when needed, for a limited time, rather than standing permanently active. This significantly reduces the window an attacker has to exploit a compromised admin account, though it's a more advanced control not every small business will need immediately.
Review Admin Access Regularly
Admin roles accumulate the same way general permissions do - someone gets elevated access for a project and it's never revoked. Build this into a periodic review. See our guide on auditing Microsoft 365 user permissions for the broader process this should sit inside.
Frequently Asked Questions
How many people should have Global Administrator access?
As few as genuinely necessary - Microsoft itself recommends fewer than five for most organisations, and many small businesses only need one or two. Every additional Global Admin is another account an attacker could target to gain full control of the tenant.
What's a break-glass account, and do I need one?
A break-glass (emergency access) account is a highly secured admin account kept for the rare case where normal admin access is unavailable - for example, if MFA methods are all lost simultaneously. It's excluded from Conditional Access policies deliberately, monitored closely, and used only in genuine emergencies. Most small businesses benefit from having at least one, properly secured and documented.
Should admin accounts be separate from a person's everyday login?
Yes, this is one of the most effective and under-used controls available - using a dedicated admin account only for admin tasks, separate from the account used for email and daily work, significantly limits what an attacker gains if the everyday account is phished.
Does Microsoft 365 Business Premium include enough security features to do this properly?
Business Premium includes Conditional Access and Entra ID P1, which cover most of what's needed for a small business. Larger organisations, or those with more complex compliance requirements, sometimes need E5's more advanced identity protection features - see our guide on Microsoft 365 E3 vs E5 for when that upgrade actually matters.
We configure and lock down Microsoft 365 admin access for Perth businesses - dedicated admin accounts, phishing-resistant MFA, and a secured break-glass account.
Microsoft 365 Services →Not sure how many people hold admin access in your tenant?
Call 0433 087 091 - we'll review your current admin setup, no obligation.
Get a Free Admin Access ReviewFor related reading, see our guides to Microsoft Entra ID explained and auditing Microsoft 365 user permissions.