Working Global Admin Account

Anonymous
2023-02-28T22:44:34.9233333+00:00

I have 3 Global Admin accounts in my tenant a) Account 1 in my working tenant and b) Accounts 2 & 3 in my onmicrosoft.com tenant which are Emergency Breaking Glass accounts and as stated on the label NOT used unless there is an emergency

  • I am setting up a conditional access policy that requires MFA for ALL Users on the Include side of the assignment and on the excluded side of the assignment are the Emergency Breaking Glass Accounts Account 2 & 3 (so as to not lock myself out of the tenant).
  • Simple Question - Account 1, do I exclude it from the policy or not? What is best practice, as it is my main working Global Admin Account, do I apply the policy and get the extra protection or do I exclude it from the policy?

Many thanks.

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,400 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,657 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 43,721 Reputation points Microsoft Vendor
    2023-03-01T02:00:28.8333333+00:00

    @Richard Berry, Thanks for posting in Q&A.

    Based as i know, Global Admins have almost unlimited access to your organization's settings and most of its data. Multi-factor authentication is a process in which users are prompted during the sign-in process for an additional form of identification, such as a code on their cellphone or a fingerprint scan. Here is a link with more details:

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks

    On my point of view, if the global account Account 1 is used by one person, you can enable MFA to secure it. If it is shared by many people. maybe you can exclude it from the conditional access policy which require MFA.

    As this belongs to Azure AD, to help you get professional support, I have added "Azure Active Directory" tag for you.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.