Guest Guest Posted June 15, 2021 Posted June 15, 2021 We're looking to order Azure AD P1 licenses to allow for MFA and conditional access. I was quoted by Phoenix and went to sign up in their portal. However, they want delegated Global admin and help desk admin rights to our O365 tenant, is this normal? I'm very reluctant to allow this
Oaktech Posted June 15, 2021 Posted June 15, 2021 I've recently taken on 2 clients who have exactly this set up, one as you say, Phoenix, the other Rocket WP, so yeah, seems to be a thing. I'm pretty sure it's not a good thing.
Guest Guest Posted June 15, 2021 Posted June 15, 2021 (edited) They didn't mention it at all, the first I knew of it was when I was entering our tenant details and was redirected to the Admin centre and it was requesting the access Edited June 15, 2021 by Guest
gmonks Posted June 15, 2021 Posted June 15, 2021 I know of a school that recently were looking at Phoenix and they too were told they'd need global admin rights.
foofighterjim Posted June 15, 2021 Posted June 15, 2021 With current concerns regarding security considered, I think I would want a very detailed argument as to why they would need this. I don't see why they would need GA, if they need to manage subscriptions I believe there are built-in security groups for that in O365.
jmak Posted June 15, 2021 Posted June 15, 2021 I've used three suppliers over the years and they always had it, so I don't think it's dodgy per se, but that doesn't mean it's either essential or a good idea. I have an idea it's to allow them to add products, but that's just a vague memory. I'd ask the question. It's also possible that there's a better alternative for them to achieve what they need to. It might be that you can disable the account and then re-enable temporarily when they need it for something specific.
Steve21 Posted June 15, 2021 Posted June 15, 2021 That's normally if you're doing it via CSP, as they're effectively your provider/manager of the licenses then. If it's a standard OVS/EES no reason at all for this Steve
sonofsanta Posted June 16, 2021 Posted June 16, 2021 Given all the security concerns about right now, what they're asking you to do there is add their entire network as a new attack vector to your data. MSPs are absolutely targets for hacking groups (e.g. the SolarWinds attack was mostly activated against MSPs) and so anyone infiltrating their systems--which you have never seen and can't audit--would potentially have global admin access to your 365 data They probably have a legitimate reason for wanting this access, and it's probably a reason that can be handled through more targeted permissions, and Global Admin has always been the fastest and easiest way--same as logging on to your workstation as domain admin has always been the fastest and easiest way to work. So although I don't think the request itself is unusual or sign of anything dodgy, I'd still push back given the current spate of attacks. 1
localzuk Posted June 16, 2021 Posted June 16, 2021 Yeah, this is normal for CSP licensing (as that's how they process the licenses). Not normal for OVS-ES or EES.
chris_uk Posted June 16, 2021 Posted June 16, 2021 I am actually going through this at the moment with Pheonix, I asked the same question. The response I got back was (Copy and paste) "It’s not Phoenix (or any CSP partner) that decides that level of access is required, it’s actually Microsoft as detailed in the Microsoft Customer Agreement for CSP and all other CSP docs. Without that role in place your Microsoft licenses cannot be ordered/increased/decreased/cancelled, depending on the T&C’s the CSP partner imposes but Phoenix have one of the most flexible offering available. Also support for CSP licenses has to be provided by the CSP partner, not Microsoft, and without that role in place your CSP partner is unable to escalate any support queries to Microsoft as the ticket will get rejected. Here at Phoenix we have the various ISO accreditations, governance, and security measures in place to support our Public Sector and Education customers both large and small. "
Boredguy Posted June 16, 2021 Posted June 16, 2021 Would would think MS could create a set of permissions just for managing licences for the CSP scheme instead of global admin if that was the requirement
Guest Guest Posted June 16, 2021 Posted June 16, 2021 We went ahead with another supplier, I had to add them as a partner but didn't have to delegate them admin rights
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now