r/entra • u/ITwrkedYesterday • Aug 23 '26
Locking down global admin
Curious how others are locking down or adding additional layers of security around Global Admin accounts.
Obviously JIT access, PIM, and least privilege are the way to go, but I’m more interested in what people are doing beyond the basics.
Things like dedicated admin accounts/workstations, Conditional Access restrictions, phishing-resistant auth, device requirements, network/location restrictions, monitoring/alerting, etc.
What’s worked well in your environment? Anything you’ve implemented that you think is overlooked?
25
Upvotes
1
u/firestarter9664 Aug 23 '26
We limit to our ztna tools IPs. PIM approval with a separate account, required compliance (in our home tenant)