Global Administrator and Privileged Role Administrator accounts can dismantle tenant security if compromised. Standing privileges and missing emergency access both create risk.
Preface
Privileged Entra roles are the highest-value targets. Securing them means removing permanent admin rights and building a resilient recovery path for lockouts and outages.
Problem
Permanent admin roles on personal accounts create standing privileges and a large blast radius after phishing or credential stuffing. Over-hardening without break-glass accounts can lock administrators out during Conditional Access mistakes or IdP outages.
Solution
Align with CIS Microsoft 365 Foundations Benchmark Section 1 and NIST SP 800-53 AC-2/AC-3:
- Deploy PIM: Eligible roles only, short activation windows, MFA on elevation, justification, and optional approvals.
- Create break-glass accounts: At least two cloud-only Global Administrators excluded from standard Conditional Access.
- Secure break-glass credentials: Split long passwords or dedicated FIDO2 keys in separate physical safes.
- Alert in Sentinel: High severity on any break-glass sign-in or elevation.
PowerShell: Audit Active Privileged Assignments
Connect-MgGraph -Scopes "RoleManagement.Read.Directory"
Get-MgBetaRoleManagementDirectoryRoleAssignmentSchedule -Filter "assignmentType eq 'Active'" |
Select-Object PrincipalId, RoleDefinitionId, StartDateTime, EndDateTime | Format-Table