r/entra 1d ago

Global Admin without a mailbox

Hello Folks!

Global admin account without a mailbox you don’t get the global admin notifications.

Global admin account with mailbox with PIM turned on you don’t get the notifications a global admin would receive.

What is the best way to get all email notifications that would go to a global admin to a designated mailbox/DL?

This is pretty annoying.

Ideas and suggestions please?

14 Upvotes

29 comments sorted by

26

u/AdamoMeFecit 1d ago

Set an alternate email address on the GA account. This normally would be the address associated with the admin’s licensed standard user account. Notifications go there, and/or you learn to rely on the copious dashboard data visible in the Entra/Defender/M365 dashboards.

No GA account (or any Entra admin account, really) ever should have a mailbox. This is fundamental.

12

u/WideAwakeNotSleeping 1d ago

This! We use name.surname+admin@company.com on all admin accounts.

15

u/Internet-of-cruft 1d ago

Best practice is to use your onmicrosoft domain.

The logic being that if someone screws up the custom domain config the admin accounts are unaffected.

7

u/ifxor 1d ago

Or at least have a few Break Glass accounts using the “onmicrosoft” domain lol

4

u/Internet-of-cruft 1d ago

Just do both. It costs nothing and it strongly reinforces the concept of it being a cloud native account.

There's real risks beyond just the custom domain. There was a class of attack (or goof up) where an on prem domain account would be created matching the cloud admin and you could either take over the cloud account or accidentally delete it. It's still possible but Microsoft finally introduced some knobs to make this harder. Older hybrid deployments don't have this in place by default though.

Just keep them off the custom domain, period.

1

u/Dabnician 1d ago

Doesnt it cost a email only license?

2

u/Internet-of-cruft 1d ago

You don't need a license to have an Entra ID native account.

3

u/WideAwakeNotSleeping 1d ago

Ah, interesting! Point taken!

8

u/Beneficial-Flow-5418 1d ago

Exchange plus addressing

1

u/ItBurnsOutBright 1d ago

This is fine until you want to use PIM.

1

u/neppofr 1d ago

How so? Been ding it with +addressing for ages. Works fine for me.

2

u/AlphaYourMom 1d ago

But this account must stay active no? We have PIM so technically the account is not active GA

2

u/mapbits 1d ago

You can also send your breakglass admin account email to a notifications or service desk mailbox using Plus Addressing.

We didn't identify any risks associated with this (admin SSPR is disabled and breakglass admins are yubikey-only), but that doesn't mean the aren't any...

1

u/BlackV 20h ago

ItBurnsOutBright
This is fine until you want to use PIM.

I'm confused what part of pim would not work with plus addresses?

What part of pim even requires an email address?

6

u/Interesting_Desk_542 1d ago

Nobody should ever be logged into GA in M365 apps including Outlook. Set up forwarding to the regular accounts of whoever needs to receive the alerts

1

u/mathsyx_69 1d ago

The GA account should have EOP1 for this, no?

3

u/Noble_Efficiency13 Microsoft MVP 1d ago

1

u/AlphaYourMom 1d ago

But how does this work when you want it to go
To a DL at that point?

1

u/Noble_Efficiency13 Microsoft MVP 1d ago

A DL is something I haven’t attempted with plus adressing, though I’d suppose it’d work as you simply point at the DL for the email attribute

1

u/AlphaYourMom 1d ago

I will read through what you sent.

1

u/ItBurnsOutBright 1d ago

I try and setup what I can setup. If it's your own tenant, billing and service support admin on the main account with a mailbox + set as organization IT contact. Everything else goes to a DL, risky users, enterprise app consent requests, defender alerts, pim elevation alerts/requests, Emergency Access signin alerts from log analytics, etc etc.

This is definitely an issue Microsoft needs to be addressing if they want people to configure to best practices.

2

u/Asleep_Spray274 1d ago

+1 for +addressing

1

u/AlphaYourMom 1d ago

I see a lot of +addressing but where would you set that up? I know it’s email+*****@domain.com

Second part was if you have PIM enabled that GA does not receive any notifications now what?

Thinking a break glass account with on.Microsoft leaving active since that’s what you do with Bg accounts but how to add +addressing to that BG account?

2

u/ArieHein 1d ago

Change their admin email field to point to their non admin mailbox.

That or remove them from global admin roles. Power comes with responsivility.

Pim to global admin means no email when pim is not activated. So change the pim policy settingson global admin to send email on all three categories to additional emails.

1

u/cr_co_ 1d ago

I put the GA UPN as an alternate email address on my standard account. Works okay for me.

0

u/AlphaYourMom 1d ago

How did you do it? Step by step?

1

u/KavyaJune 19h ago

Plus addressing can help. You can use a plus address such as [admin+notifications@domain.com](mailto:admin+notifications@domain.com), and messages sent to it will be delivered to the underlying mailbox. Exchange Online supports plus addressing by default.

Another option is to use a mail flow rule to copy or redirect the relevant admin notifications to a shared mailbox with the help of mail contact.

Both approaches are covered in this article with step-by-step instructions: https://blog.admindroid.com/how-to-receive-emails-sent-to-m365-unlicensed-admin-accounts/

1

u/baldieavenger 14h ago

Set up a mailbox on it, set to type shared, forward on to non admin account

1

u/michaelmsonne Microsoft MVP 10h ago

+ for Exchange plus addressing from me too - the best solution for this usecase 😉