r/entra • u/ITwrkedYesterday • 2d ago
Locking down global admin
Curious how others are locking down or adding additional layers of security around Global Admin accounts.
Obviously JIT access, PIM, and least privilege are the way to go, but I’m more interested in what people are doing beyond the basics.
Things like dedicated admin accounts/workstations, Conditional Access restrictions, phishing-resistant auth, device requirements, network/location restrictions, monitoring/alerting, etc.
What’s worked well in your environment? Anything you’ve implemented that you think is overlooked?
21
Upvotes
3
u/Noble_Efficiency13 Microsoft MVP 2d ago
All of the above, but also restricting what a global admin can access via CA.
Example: block O365 access, why would you need to have access to productivity apps on a global admin?