Stedra
Sign inCheck my business
BlogPROVIDER GUIDE6 min read

Who controls your Microsoft 365 tenant? Global admins, explained.

Steps verified against the official documentation below · last checked 2026-07-18

In a Microsoft 365 tenant, the Global Administrator role is the root of everything: Exchange mailboxes, Teams, SharePoint, device management, and the Entra ID directory that signs everyone in. Whoever holds it controls the tenant; if nobody reachable holds it, the tenant controls you.

Microsoft publishes unusually concrete guidance on how this role should be held. Most small businesses have never read it, because the tenant was set up once by an IT provider and never audited. Here's the short version, and the fixes.

Check who holds Global Administrator

In the Microsoft 365 admin center (admin.microsoft.com), open Users → Active users and filter by admin role, or review Roles → Role assignments for Global Administrator. Look for the same two failure modes as any platform: exactly one holder, or holders who shouldn't be there — departed staff, an old MSP's engineer accounts, a personal Outlook address.

Microsoft's own rules of thumb

  • Fewer than five Global Administrators — more assignees means more accounts whose compromise is total. Entra even surfaces an alert when you hit five or more.
  • But never exactly one: assign lesser admin roles (Exchange admin, User admin, Billing admin) for day-to-day work, and keep at least two people able to reach Global Admin.
  • Separate admin accounts from daily-use accounts — the login that reads email all day shouldn't be the one that can delete the tenant.
  • Two cloud-only emergency-access ('break-glass') accounts with the role permanently assigned, excluded from conditional-access lockouts, credentials stored securely offline, and tested roughly every 90 days.
The break-glass idea matters even at ten employees: it's the answer to 'what if the person with the admin phone is on a plane while sign-in is broken.' Scale the ceremony down, keep the principle.

Grant or remove the role

  1. 1
    Users → Active users → select the user
    Use an account on your tenant domain that the business controls.
  2. 2
    Manage roles
    Assign Global Administrator to add a second holder — or strip it from someone who shouldn't have it. Enforce MFA on every admin account while you're here; it's also a standard cyber-insurance question.
  3. 3
    Departures get the full checklist
    An admin leaving the company is never just a role removal — recovery contacts, app registrations, and API credentials they created need the offboarding sweep.

If your only global admin already left

First, check whether you bought Microsoft 365 through a partner/reseller — they often retain delegated administration and can restore your access fastest. Otherwise, contact Microsoft support: expect to prove control of the tenant's domain and your authority over the business before admin rights are re-established. Like every platform, the recovery path exists but is slower and less certain than the five-minute prevention above.

Microsoft Learn — Best practices for Microsoft Entra rolesMicrosoft Learn — Manage emergency access admin accountsMicrosoft Learn — Admin account security in Microsoft 365 for business
This is one asset. How many others does your business not control?

The free scan maps your domain, email, cloud, social and tools from public records — and shows what you'd lose access to tomorrow. No login, nothing to install.

Check my business
Who controls your Google Workspace? Super admins, explained.
5 min read
The account-ownership questions on your cyber-insurance application, explained
6 min read