Jump to content

Recommended Posts

Posted

Hi All,

 

Been wondering how others are managing their 365 admin rights.

 

Do you just roll with a Global 365 admin account or do you assign each admin role specifically to a user account designated a "365 admin"? - Once the task is done, do you remove the role etc?

 

If you have an "admin user" with assigned roles, do you have a process for getting access to a global admin - who looks after it?

 

We're looking at tightening up our security, access and permissions so just wanted to get a feel of how others are doing it.

 

Cheers

Posted (edited)

The principal of least privilege jus the same as you would use on other systems.

 

https://en.wikipedia.org/wiki/Principle_of_least_privilege#:~:text=The%20principle%20means%20giving%20any,backup%20and%20backup%2Drelated%20applications.

 

Keep a Global Admin account credential in the safe in a sealed envelope only to be used when absolutely necessary. Once the seal is broken change the password.

 

Create specific accounts for services use rather than using the Global Admin account with the least privilege required.

Edited by Davit2005
  • Thanks 2
Posted

Could anybody give me some examples of how these processes work with the day-to-day of handling SharePoint permissions, 365 users & Groups, inTune, interacting with users OneDrive areas, Teams groups (even though it's all automated), managing MFA in Entra etc.

 

Is the preference an User with respective Admin role for each of these services?

 

PIM sounds interesting, will need to look into that.

Posted

E.g:

 

We have a member of staff that deals with Azure VMs, i've given him access via PIM to the Azure management role (forgot exact name off top of my head). He then has to go into PIM to activate his admin role and a reason why. It's then active for 8 hours (can be changed to w/e you want). Requires 2FA to activate

  • Thanks 2
Posted (edited)
It looks like you need P2 licences to use PIM, is this correct or can we also get it under one of the edu licenses?

 

We brought the minimum of 5 P2 licenses to qualify for it, unsure on Edu licenses im afraid as been couple of years since been in Edu and can't remember the setup, i think it was A3/A5

 

Edit: Looking at https://m365maps.com/files/Microsoft-365-Education-A5.htm looks like you need A5, or the entra ID plan 2 step-up (or p2 depending on licensing)

 

Was one of my first requests when i joined!

Edited by DalekSec
  • Thanks 1
Posted
Hi All,

 

Been wondering how others are managing their 365 admin rights.

 

Do you just roll with a Global 365 admin account or do you assign each admin role specifically to a user account designated a "365 admin"? - Once the task is done, do you remove the role etc?

 

If you have an "admin user" with assigned roles, do you have a process for getting access to a global admin - who looks after it?

 

We're looking at tightening up our security, access and permissions so just wanted to get a feel of how others are doing it.

 

Cheers

 

Global admin is more than simply a handy way to group lots of access together, it allows you to change the tenant itself, and is a huge risk. It should only be used when necessary and not assigned otherwise.

  • Thanks 1
Posted

I appreciate all the replies, but I feel too many of you are getting caught up on the global admin part and then skipping the rest of my question/post.

 

Also I understand many of you probably don't want to explain your exact processes because security, but it would be handy to have some idea of how many roles an IT Admin should hold on a daily 365 admin if going for the method of each IT Admin having a limited 365 admin user, say.

 

If this isn't the case, then is it more common industry practice to simply have all roles delegated to a role admin account i.e:

 

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

 

And each IT Admin then follows a process to gain access to the password for the service admin account, which is then changed after use etc?

Posted
We operate with standard users for our accounts, we have a separate admin accounts, which have permissions via PIM (we just add A5 for Security to these accounts to give them the P2 license), we then use PIM to limit what they can elevate to, for example Joe only works within SharePoint and Teams, so they only have permissions to elevate to those roles, they can request other roles through PIM but that would then need to be authorised by myself.
  • Thanks 2
Posted (edited)
I appreciate all the replies, but I feel too many of you are getting caught up on the global admin part and then skipping the rest of my question/post.

 

Also I understand many of you probably don't want to explain your exact processes because security, but it would be handy to have some idea of how many roles an IT Admin should hold on a daily 365 admin if going for the method of each IT Admin having a limited 365 admin user, say.

 

They should have the roles necessary to carry out their job, no lore or less. So you might determine that a help desk operator needs to be able to unlock accounts and reset passwords, then assign them roles that allow them to do just this and nothing else.

 

If you have the resources to manage this kind of thing, you might setup a ‘just-in-time’ system using tools like Microsoft’s PIM, which allows you to only assign roles to an admin temporarily to allow them to complete specific tasks - so my employer has previously agreed that I can be a global admin on our O365/EntraID tenant, but that role is only active when I request it to carry out a task that requires that level of privilege.

 

[quote=Space_Munkey;2060696

If this isn't the case, then is it more common industry practice to simply have all roles delegated to a role admin account i.e:

 

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

 

And each IT Admin then follows a process to gain access to the password for the service admin account, which is then changed after use etc?

 

No. Dear me, no. The problem with this approach is that it violates the integrity principle of the security ’CIA triad’- it breaks non-repudiation. If ‘anyone’ can log on with a generic role account like these then ‘anyone’ can make a change, steal or corrupt data, and you’ll never know for sure who did it or what exactly they did.

Edited by Roberto
  • Thanks 2
Posted
I appreciate all the replies, but I feel too many of you are getting caught up on the global admin part and then skipping the rest of my question/post.

 

Also I understand many of you probably don't want to explain your exact processes because security, but it would be handy to have some idea of how many roles an IT Admin should hold on a daily 365 admin if going for the method of each IT Admin having a limited 365 admin user, say.

 

If this isn't the case, then is it more common industry practice to simply have all roles delegated to a role admin account i.e:

 

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

 

And each IT Admin then follows a process to gain access to the password for the service admin account, which is then changed after use etc?

 

I don't think is another way to put it than to have least priviledge role to perform the tasks needed and this does not only go for the Global Admin role either. The PIM looks interesting though.

 

I would also suggest not using a regular user account either and maybe creating a user that is in Azure only and not a published or easily guesses email address.

  • Thanks 1
  • 4 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...