Skip to content
Notifications
Clear all

Best practice for segregating admin roles? We have 5 admins who need different access.

5 Posts
5 Users
0 Reactions
1 Views
(@crm_hopper_2024)
Reputable Member
Joined: 4 months ago
Posts: 121
Topic starter   [#17446]

We have five people with "admin" in their title, and currently, they all have the Global Admin role. It's a disaster waiting to happen. I've seen this movie before with Salesforce and HubSpot—one eager intern triggers a company-wide lockout.

Entra ID's built-in roles are actually decent if you use them. Don't just hand out the global keys.

* Break it down: Who *really* needs what?
* User Admin for helpdesk.
* License Admin for the procurement person.
* Exchange, Teams, and SharePoint admins for those specialists.
* Keep Global Admin to two people, max. Use Privileged Identity Management (PIM) if you have the license. No permanent global admins.

The goal: everyone has the least privilege needed to not break your day. It's boring, but so is not getting hacked at 3 AM.


CRM is a means, not an end.


   
Quote
(@devops_shift_lead)
Estimable Member
Joined: 4 months ago
Posts: 136
 

I'm the senior platform engineer at a 350-person FinTech, managing our Azure and AWS environments where we enforce strict RBAC for ~120 engineers across 30+ production services.

* **Least Privilege Baseline**: Start by mapping Entra's 60+ built-in roles to your five admins. A "Help Desk Admin" does not need Billing Admin. In our setup, only two people have Global Admin via PIM with 4-hour activation and MFA challenge, which cut our standing privileged accounts from eight to two. It took about two weeks of meetings to map duties.
* **Cost for the Good Stuff**: Entra ID P2 (required for PIM) runs $9/user/month. Without it, you're manually managing permanent roles. Budget for that license for any account with *any* admin role. The hidden cost is the 5-10 hours per quarter auditing sign-ins and role assignments, but that's cheaper than an incident.
* **Deployment and Breakage**: Deploying PIM and breaking inheritance on groups was a two-week project. The main breakage point is with service principals - if your CI/CD or Terraform runs under a service principal, ensure it has the correct Application Administrator or Cloud Application Administrator role, not Global Admin. We had a pipeline break for six hours because we overcorrected.
* **Where It Clearly Wins**: The audit log is undeniable. When we get an alert for a suspicious sign-in to a Privileged Role Administrator account, we have a full session recording and approval trail. This stopped three phishing attempts cold last year because the attacker couldn't satisfy the PIM approval workflow.

My pick is Entra ID with PIM, specifically for mid-market companies with an existing Microsoft stack. If you're hybrid with on-prem AD, or if your budget absolutely cannot stretch to P2 licenses, tell us that - the alternative is a much more manual process using permanent custom roles.


shift left or go home


   
ReplyQuote
(@crm_pragmatist)
Estimable Member
Joined: 2 months ago
Posts: 98
 

Good point on the service principals, that's a silent killer. Admins love giving service accounts Global Admin to "make it work," and then you find out your entire deployment pipeline is a 24/7 admin.

Your PIM activation window is aggressive. We found 4 hours caused people to just leave it on all day. Switched to 1-hour max with a justification field. Annoying, but it forces actual thought.

And yes, the quarterly audit is non-negotiable. The Entra logs are useless if you don't look at them. We spend those 10 hours and call it cheap insurance.



   
ReplyQuote
(@devops_barbarian_v3)
Reputable Member
Joined: 3 months ago
Posts: 132
 

Seen the same thing with Kubernetes cluster roles. Handing out cluster-admin like candy because "the docs said to" is how you wake up to a drained node pool.

Your point on built-in roles is key. The default ones exist for a reason. But they're often too broad. We end up creating custom roles anyway, stripping out actions like "delete" for certain resources. It's tedious, but you only cry once.

PIM is the way. No permanent global admins, period. We enforce MTO on activation and a 1-hour timeout. The complaining stops after the first near-miss audit.



   
ReplyQuote
(@crm_hopper_2028)
Reputable Member
Joined: 3 months ago
Posts: 135
 

Exactly. The "admin in the title" thing is a massive red flag. I've seen teams where the CRM "admin" is just the person who runs reports, and they get handed Global Admin in HubSpot because it's easier.

Your point about mapping to built-in roles is the only way to start. But I'd add one caveat - sometimes the built-in roles are *too* specific. The "Teams Admin" might need a sliver of SharePoint access to manage team site creation, which the built-in role doesn't cover. That's where people get lazy and just escalate.

So you map to built-ins, then document the one or two gaps that actually need a custom role or a second, limited role assignment. It's more work upfront, but it prevents the "just make them global" backslide later.


Still looking for the perfect one


   
ReplyQuote