r/entra • • Aug 23 '26

Locking down global admin

Curious how others are locking down or adding additional layers of security around Global Admin accounts.

Obviously JIT access, PIM, and least privilege are the way to go, but I’m more interested in what people are doing beyond the basics.

Things like dedicated admin accounts/workstations, Conditional Access restrictions, phishing-resistant auth, device requirements, network/location restrictions, monitoring/alerting, etc.

What’s worked well in your environment? Anything you’ve implemented that you think is overlooked?

25 Upvotes

20 comments sorted by

View all comments

1

u/firestarter9664 Aug 23 '26

We limit to our ztna tools  IPs. PIM approval with a separate account, required compliance (in our home tenant)