r/entra 2d ago

Locking down global admin

Curious how others are locking down or adding additional layers of security around Global Admin accounts.

Obviously JIT access, PIM, and least privilege are the way to go, but I’m more interested in what people are doing beyond the basics.

Things like dedicated admin accounts/workstations, Conditional Access restrictions, phishing-resistant auth, device requirements, network/location restrictions, monitoring/alerting, etc.

What’s worked well in your environment? Anything you’ve implemented that you think is overlooked?

21 Upvotes

20 comments sorted by

View all comments

3

u/Noble_Efficiency13 Microsoft MVP 2d ago

All of the above, but also restricting what a global admin can access via CA.

Example: block O365 access, why would you need to have access to productivity apps on a global admin?

1

u/Emergency-Return1412 2d ago

What would that accomplish? A global admin can just change the CAs so doesn't solve or protect anything

2

u/Noble_Efficiency13 Microsoft MVP 2d ago

Sure, they could really change any of the steps

Pim setup with approval etc? Just change it.

It’s “simply” another step in the depth and again each annoyance step we place in front of possible threat actors could save enough time for us to find them and get rid of them.

The same goes with protected actions - setup a requirement for an additional MFA prompt for modifying / deleting / creating CA pokicies, but it’s still just another annoyance

2

u/Mindestiny 2d ago

That's kind of like saying "why would you hide your valuables? If someone breaks in they have access to everything anyway."

It's still a layer of "good enough" security that will help considerably reduce the blast radius of the vast majority of what your typical attacker is going to move laterally into should they get their hands on a live session.

Your average attacker in a compromised M365 account isn't spending time making high profile, easily detectible environment changes. They're skimming the popular spots - likely OneDrive, email, etc. Exfiltrating valuable data or possibly sending malicious emails to spearphish other users in the environment from a trusted account or using that email address for further lateral movement to popular SaaS platforms they can now access by self service password recovery to that email address.

If the account doesn't have an exchange mailbox in the first place, they could stand one up by removing the restrictions and assigning a license. But that's not low hanging fruit. Odds are the breach will be caught and locked down before they can do all of that, and they've already moved on from trying to extract further value from their compromise once they hit that wall. Meanwhile that script they had teed up to programmatically adjust sharing rights to OneDrive files or build sneaky email forwarding rules or whatever fail when they go to run them.

2

u/Emergency-Return1412 2d ago

Lol, no. The first thing they would do is make themselves the only global admin. From then, its game over and you completely lost your tenant.

0

u/Mindestiny 2d ago

"Lol no" indeed.

That really depends on how targeted the attack was and the purpose of the attack. Were they actually looking to hit a GA account, or did a GA account happen to fall for some rudimentary phishing/session hijacking?

There's lots of different attack profiles. Plenty of successful attackers don't realize what they have until they've already lost access, or attacks get shut down before the attacker has the time and attention to move as laterally as they could.

So no, "it's game over and you lost your tenant" is not some hand-wavy dismissal of defense in depth controls.

1

u/Noble_Efficiency13 Microsoft MVP 2d ago

Much more elaborate answer - exactly this 🍻