Administrative accounts are designated privileged accounts with differing levels of access to data, users, and configurations. Standard user accounts should never be used for administrative functions. In hybrid environments, it's crucial to segregate administrative accounts from on-premises accounts. These accounts should not be associated with applications to prevent access to potentially compromised services such as email, Teams, SharePoint, etc. They should only be granted access for necessary administrative tasks. It's imperative to license administrative accounts without attached applications and ensure they are solely cloud-based.
By ensuring that administrative accounts are solely cloud-based and not associated with any applications, you effectively minimize the attack surface for highly privileged identities within your environment. However, to utilize Microsoft 365 security services like Identity Protection, PIM, and Conditional Access, an administrative account must be licensed. It's essential to select a license that excludes applications with potentially vulnerable services. Consider using either Microsoft Enterprise ID P1 or Microsoft Enterprise ID P2 for the cloud-only account with administrative roles. In a hybrid environment, maintaining separate accounts helps mitigate the risk of a breach affecting both the cloud and on-premises environments. This segregation ensures that if a breach occurs in one environment, it does not compromise the security of the other.
This security setting is recommended for atleast E3 Level 1 which aims to be practical and sensible, Offer a distinct security advantage, and does not inhibit the functionality of the technology beyond acceptable means.
To create licensed, separate Administrative accounts for Administrative users, please follow these steps:
Administrative users will need to switch between accounts and utilize login/logout functionality when carrying out administrative duties. Additionally, they won't benefit from Single Sign-On (SSO) capabilities.
To ensure that Administrative accounts are separate and solely cloud-based, follow these steps:
Quick & Simple
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you