Forum Discussion
Shared Service Admin
Hi.
E.g we have one "master account" to manage our Azure subscriptions. We are several people that need to login on this to manage the subscriptions.
Also our Sharepoint guys need to share an account for working with Flow, where they need one account to create flows.
The case is the same here (more than 50'000 employees), so we are splitting the roles as following:
- The Tenant full admin role: 2 persons to share the holidays time
- The Exchange Admins role: 3 persons
- The SharePoint Admin role: 4 persons
- A dedicated support team who has also the tenant admin role and can execute the scripts or change depending of the request and with the Full admin validation
The situation was quite acceptable in the past because the isolation was ok, but with the new Office Group positioning, that is less and less sustainable.
From what I understood the dedicated admin will be removed and the admin permission will be transferred only to the support team.
Some other aspect are pushing us in that directly with the GPDR regulations, the US and SG regulations, …
So we will continue with that separation of account for Admin and support as explained before but the associated role will probably change a little bit.
About the developers case, we have that question for Flows & PowerApp but also for PowerBI dev and we defined to create shared service accounts (without MFA) delivered to the "Publisher", the developer will work into dedicated space (site collection or groups/teams)
Hope that will help you.
Fab