Who this is for
- You are not certain who has administrative rights.
- The tenant was set up by somebody who has left.
- A provider holds the only administrative account.
- You are being asked to demonstrate access control to a customer or an insurer.
Administrative rights are usually handed out for a reason and then never reviewed. Years later nobody is certain who holds them, or whether the business could get in without asking somebody else.
Ownership and access are different things, and confusing them is what strands businesses. Plenty of people can be given administrative access. Only one entity should own the tenant, and that entity is the business.
The test is not who knows the password today. It is whether the business could still administer its own Microsoft 365 tomorrow if a particular person or supplier stopped answering the phone.
Nobody sets out to lose control of their own tenant. It happens the same few ways.
Fastest at the time, and it means the business is now a guest in its own environment. Getting out of this is tenant takeover.
With the authenticator app on their phone and the recovery email pointing somewhere nobody reads. The access half of this is former employee access.
Because it was quicker than working out which permission was actually needed. Each grant was reasonable. The total is not.
Which works perfectly until the relationship ends, at which point it is the only thing anyone can talk about.
Not who you think. What the tenant actually reports.
This question alone usually finds something.
The recovery email and phone number on the administrative accounts.
Including any account that exists for a system rather than a person.
And write down where its credentials live, in a place that is not the tenant.
Roles first, accounts second, and record what you removed.
No. An account named after a person leaves with that person, and it also means everyday email and administrative rights live in the same place, which is exactly what an attacker wants.
The pattern that works is a separate administrative account owned by the business, used only for administration, with the recovery details held by the business rather than on somebody's phone.
Fewer than most tenants have. Two or three people who genuinely need it, plus a break glass account kept for emergencies, covers almost every small business.
What we usually find instead is five or six, several of whom got the role once for a specific task in 2022 and never had it removed.
An administrative account that exists only to get you back in when normal access fails: the person with the authenticator app has left, or a policy has locked everybody out.
It is excluded from the policies that could lock it out, its credentials are stored somewhere physical and controlled, and its use is something you would notice. It is deliberately boring and it is the thing people wish they had set up.
It is common, and it is fine for them to hold administrative access. It is not fine for them to hold the only administrative access.
The test is simple: if that relationship ended tomorrow, could your business still get into its own tenant? If the answer is no, that is worth fixing while everyone is still friendly.
A fixed scope review of who has access, how sign-in is protected, where mail goes and what you are paying for.
Getting administrative control of a tenant somebody else set up, then documenting it.
What to check when somebody has left and you are not certain their access is closed.
The review lists every account with administrative rights, when each last signed in, and which belong to people who have left.