Forum Discussion

Danny Boulanger's avatar
Danny Boulanger
Copper Contributor
Jul 15, 2016
Solved

Global administrator in Office 365, how to get real governance

I am trying to have 100% governance to avoid having the following situation:

1- Global admin make the decision to kick-out the others global admin and take control

2- Give the corporate management people the ability to freeze Office 365, kick out the Global admin and replace the credential in case of fraud or miss-used information

 

I had one Global Admin, and having discover that he hacked my eMail on April 18th, we needed to replace him as a Global Admin.  Microsoft can not do anything on that.  Global Admin is like God.  Even if you add more global admin, the malicious global admin can remove the other one.

 

Being 100% the share older, how to I get full governance and avoid future issues?  Thanks  

  • Microsoft CAN help you in situations like this, but you will need to pass over multiple verifications and so on. So if you havent contacted support already, do it, and if the first line guys are giving you trouble ask to get the issue escalated.

     

    As to what you can do to avoid future issues - dont grant access to people you dont trust and protect your sensitive accounts with MFA (it's free and very simple to setup/use).

  • The Global Admin account level is extremely important to protect. MFA is a must.

     

    One related tip... If you're on E3, you can Activity log to query all changed admin settings or call the corresponding API.

     

    For E5, Advanced Security Management would be able to set up rules in case too many settings are set by a rogue Global Admin, then you could suspend that rogue Global Admin account automatically if they exceed your threshold.

     

    Either way, it is good from a checks and balances perspective to see what other admins are setting.

18 Replies

  • Brian Hamel's avatar
    Brian Hamel
    Copper Contributor

    Danny - I'm just getting around to reading this post.  If you're looking for a way to control admin rights on a per tenant basis and only allow certain admins to perform certain functions, wiht the ability to track all admin activity, reach out and we'll demo our multitenat O365 management platform to you. We have a number of features that go well beyond the O365 admin portal including advanced RBAC.

     

    Rgds,
    Brian

    • JayFMSTechComm's avatar
      JayFMSTechComm
      Iron Contributor

      To stop a rogue global admin from deleting other admins, is it possible to limit logins from global admins to specific physically secure local locations?  That way, when it's time to say goodbye to a global admin, you can change the physical access controls to the secure local locations and he/she would no longer have access and could do no harm.

  • Microsoft CAN help you in situations like this, but you will need to pass over multiple verifications and so on. So if you havent contacted support already, do it, and if the first line guys are giving you trouble ask to get the issue escalated.

     

    As to what you can do to avoid future issues - dont grant access to people you dont trust and protect your sensitive accounts with MFA (it's free and very simple to setup/use).

    • JayFMSTechComm's avatar
      JayFMSTechComm
      Iron Contributor

      Is it recommended that the Global Administrator of an organization be enabled for MFA, using the built in MFA that comes with the Office 365 E1 subscription? What happens if the Global Administrator loses access to his or her smart phone, and can't authenticate? What is the best practice recommendation for securing the Global Administrator's login credentials?

      • Dean_Gross's avatar
        Dean_Gross
        Silver Contributor
        A good place to start is to ensure that every admin role has at least 2 people assigned.
    • Danny Boulanger's avatar
      Danny Boulanger
      Copper Contributor

      Sorry Vasil, but Microsoft can not do anything if the Global Admin does not give is OK.  So if you deal with a bad boy, you are stock in the coner.  I have try if to 3 days, and Microsoft can not do anything.

    • JeremyChapmanMSFT's avatar
      JeremyChapmanMSFT
      Icon for Microsoft rankMicrosoft

      The Global Admin account level is extremely important to protect. MFA is a must.

       

      One related tip... If you're on E3, you can Activity log to query all changed admin settings or call the corresponding API.

       

      For E5, Advanced Security Management would be able to set up rules in case too many settings are set by a rogue Global Admin, then you could suspend that rogue Global Admin account automatically if they exceed your threshold.

       

      Either way, it is good from a checks and balances perspective to see what other admins are setting.

      • Danny Boulanger's avatar
        Danny Boulanger
        Copper Contributor

        Being more a busness manager I did not know MFA, but I quikly surf it, and it seem to be in the right direction.  So, If one department is taking care of managing MFA, and another one is doing Office 365, I understand that the MFA person could remove the Global Administor rights to login and take over.  I hope I have properly understood.  Thanks for the community, it is very helpfull.

  • Resources