Who controls your Microsoft 365 tenant? Global admins, explained.
In a Microsoft 365 tenant, the Global Administrator role is the root of everything: Exchange mailboxes, Teams, SharePoint, device management, and the Entra ID directory that signs everyone in. Whoever holds it controls the tenant; if nobody reachable holds it, the tenant controls you.
Microsoft publishes unusually concrete guidance on how this role should be held. Most small businesses have never read it, because the tenant was set up once by an IT provider and never audited. Here's the short version, and the fixes.
Check who holds Global Administrator
In the Microsoft 365 admin center (admin.microsoft.com), open Users → Active users and filter by admin role, or review Roles → Role assignments for Global Administrator. Look for the same two failure modes as any platform: exactly one holder, or holders who shouldn't be there — departed staff, an old MSP's engineer accounts, a personal Outlook address.
Microsoft's own rules of thumb
- Fewer than five Global Administrators — more assignees means more accounts whose compromise is total. Entra even surfaces an alert when you hit five or more.
- But never exactly one: assign lesser admin roles (Exchange admin, User admin, Billing admin) for day-to-day work, and keep at least two people able to reach Global Admin.
- Separate admin accounts from daily-use accounts — the login that reads email all day shouldn't be the one that can delete the tenant.
- Two cloud-only emergency-access ('break-glass') accounts with the role permanently assigned, excluded from conditional-access lockouts, credentials stored securely offline, and tested roughly every 90 days.
Grant or remove the role
- 1Users → Active users → select the userUse an account on your tenant domain that the business controls.
- 2Manage rolesAssign Global Administrator to add a second holder — or strip it from someone who shouldn't have it. Enforce MFA on every admin account while you're here; it's also a standard cyber-insurance question.
- 3Departures get the full checklistAn admin leaving the company is never just a role removal — recovery contacts, app registrations, and API credentials they created need the offboarding sweep.
If your only global admin already left
First, check whether you bought Microsoft 365 through a partner/reseller — they often retain delegated administration and can restore your access fastest. Otherwise, contact Microsoft support: expect to prove control of the tenant's domain and your authority over the business before admin rights are re-established. Like every platform, the recovery path exists but is slower and less certain than the five-minute prevention above.
The free scan maps your domain, email, cloud, social and tools from public records — and shows what you'd lose access to tomorrow. No login, nothing to install.
Check my business