Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

Microsoft 365 Admin Roles Explained: Who Should Actually Be a Global Admin?

Most small tenants have three or four Global Admins because that was the fastest way to get something done. Here are the roles you actually need, and how to unwind the ones you don't.

Open the admin centre of almost any small business tenant and look at who holds Global Administrator. The usual answer is four or five accounts. One is the director who set it up. One belongs to a member of staff who needed to add a user once in 2022. One is the previous IT company. And one is the current owner, who assumed everybody else had been removed years ago.

Nobody decided this. It accumulated, one urgent request at a time, because granting Global Admin is always the quickest way to unblock somebody. It is also the largest single risk most small businesses own, and unlike a firewall or a backup, fixing it costs nothing but an afternoon.

What Global Admin actually means

A Global Administrator can reset any password in the business, including yours. They can grant themselves access to any mailbox and any SharePoint site. They can turn off multi-factor authentication, rewrite conditional access rules, disable audit logging, add a new administrator, and remove you. They can hand a stranger a permanent connection to your data through an app registration that never appears in a user list.

That is not a criticism of whoever holds it. It is a description of what an attacker gets if that one account is phished.

The roles a small business actually needs

Microsoft ships dozens of admin roles. Six of them cover almost everything a business under a hundred people will ever do.

Global Administrator. Everything, as above. Reserve it for tenant-wide changes: buying and assigning the first licences, adding a domain, changing security policy. Most weeks it should not be used at all.

User Administrator. Creates and deletes users, assigns licences, manages groups, resets passwords for ordinary staff. This is the onboarding and offboarding role, and it is what most people who “need admin” actually need. It deliberately cannot reset a Global Admin’s password or hand out privileged roles.

Exchange Administrator. Mailboxes, shared mailboxes, aliases, mail flow rules, quarantine, anti-spam settings. If your recurring pain is email — a message stuck in quarantine, a new sales@ address, a list nobody can edit — this is the role that fixes it, and it touches nothing else.

Helpdesk Administrator. Password resets for non-admin users, sign-in troubleshooting, service health, support tickets. Narrower than User Administrator: it cannot create or delete accounts or move licences around. It suits a first-line person or an outsourced service desk handling day-to-day calls and nothing structural.

Billing Administrator. Subscriptions, invoices, payment details, buying and cancelling licences. It sees no user data. Give it to whoever owns the finance relationship so they can query a bill without holding keys to the mailboxes.

Global Reader. The read-only twin of Global Admin. It sees every setting, report and configuration, and changes none of them. It is the most underused role in Microsoft 365 — what an auditor should get, and what a curious director should hold instead of the real thing.

Why the split is worth the bother

Least privilege gets explained as a trust exercise, which puts people’s backs up. It is not about trust. It is about blast radius.

If a Helpdesk Administrator falls for a convincing login page, the attacker can reset some staff passwords and cause a bad afternoon. If a Global Administrator falls for the same page, the attacker owns the business: a hidden rule on the finance mailbox, a fresh admin account for persistence, your backups within reach, and enough control to lock you out while they work. Same phishing email, entirely different Tuesday.

One habit goes with the split. Whoever holds a privileged role should hold it on a separate account from the one they read email on. It sounds fussy for a business of twenty people, and it is the difference between a bad link reaching one user and reaching your whole tenant. The same reasoning sits behind strong multi-factor authentication on every account that can change something.

The break-glass account, and why it is different

Tightening admin access creates a new failure mode: locking yourself out. A conditional access rule with an unlucky condition, an expired phone, a departed director — any of these can leave a tenant with no usable administrator. Microsoft support can help, but the identity checks take time.

A break-glass account exists for exactly that morning. It is a cloud-only account in the tenant’s own onmicrosoft.com domain, so it does not depend on your main domain, your on-premises server or anyone’s phone number. It holds Global Admin permanently. It is excluded from the conditional access policies that could lock it out, monitored so any sign-in raises an alert, and never used for routine work. Its credentials live somewhere physical and controlled, not in a password manager beside the Amazon login.

Two are better than one, and they need a real sign-in method rather than a bare password — admin accounts now face mandatory multi-factor prompts, so a hardware security key kept in the safe is the practical answer. Test them once a year. An emergency account nobody has ever signed into is a hope, not a control.

The provider who still has the keys

The awkward one. When you change IT companies, the outgoing provider very often keeps Global Admin, sometimes for years, occasionally with nobody there remembering they have it. Usually that is inertia rather than malice. It is still an unmonitored master key held by an organisation you no longer pay.

Work through it on the day the relationship ends. Check the partner relationships page in the admin centre and remove any delegated administration the old provider still holds — that is a separate mechanism from a named admin account, and removing one does not remove the other. Then audit every account with a privileged role and disable the ones that belong to them. Look for service accounts and app registrations they created, because those survive a user deletion. Check the finance mailbox for forwarding rules. Reset your break-glass credentials, since they may well have been shared. Finally, confirm you own the things underneath: the domain registration, the DNS, and the billing subscription itself.

Ask your incoming provider to do this in front of you rather than describe it afterwards, and get the resulting admin list in writing. Reluctance there tells you something useful early. It is one of the questions worth asking before you sign, along with the rest in our guide to choosing an IT support company.

Where to start

Pull the list of everyone holding a privileged role and ask, for each one, what they last used it for. Move most of them to User Administrator, Helpdesk Administrator or Global Reader depending on the honest answer. Create the break-glass accounts before you remove anything. Then leave the remaining Global Admins at two.

That review takes an afternoon and changes the worst case of the next phishing email more than any product you could buy. It is a standard part of how we secure a Microsoft 365 tenant, and if your tenant grew by accident rather than design, it is the first thing to look at in a Microsoft 365 setup review.

Frequently asked questions

How many Global Admins should a small business have?

Fewer than most have. Microsoft's own guidance is to keep the number under five, and for a business of ten to fifty people that usually means two named humans plus one or two break-glass accounts nobody uses day to day. Two is the floor rather than one, because a single Global Admin on annual leave with a broken phone is a genuine outage. The test is whether you can name every Global Admin in your tenant from memory. If you can't, you have too many.

Can an administrator read my email?

A Global Admin can, and so can an Exchange Administrator. Neither can open your mailbox by simply clicking on it, but both can grant themselves permission to it in a couple of minutes, and the change is not announced to you. That isn't a scandal — it is how support works when somebody leaves and their mail has to be handled. What matters is that the action is recorded in the audit log, that the number of people who can take it stays small, and that staff know the capability exists rather than assuming privacy they don't have.

What role should our office manager have if they set up new starters?

User Administrator covers almost all of it. They can create and delete accounts, assign licences, manage groups and reset passwords for ordinary staff, which is the whole of a normal onboarding. What they cannot do is reset a Global Admin's password, change security policy or add somebody to a privileged role, and that is exactly the boundary you want. If they also need to create shared mailboxes or release a message from quarantine, add Exchange Administrator alongside it rather than promoting them to Global Admin.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.