Pro User
Zeitspanne
explore our new search
​
Microsoft Entra: Fix MSP Admin Access
Identity
3. Juli 2026 21:34

Microsoft Entra: Fix MSP Admin Access

von HubSite 365 über Jonathan Edwards

No-Faffing Managed IT Support & Cyber Security Support. Made in Yorkshire, built for the UK.

MSP: end shared Global Admins and MFA vault use, secure Microsoft three sixty five with GDAP, Windows LAPS and Intune

Key insights

  • Shared Global Admin and shared credentials destroy accountability and increase risk.
    When multiple people use the same admin account or store MFA codes in a shared vault, you cannot trace actions or revoke access per person.
  • Permanent Global AdminGive staff only role-appropriate rights and avoid always-on tenant-wide admin roles to limit damage if an account is compromised.
  • Use Named admin identities, GDAP for partner access, and Privileged Identity Management (PIM) for Just‑in‑Time elevation.
    Require a ticket or justification, set short durations, and log every elevation for auditability.
  • Protect admin sign-in and workstations with phishing-resistant methods like FIDO2, and isolate admin tasks on Privileged Access Workstations (PAWs).
    Apply Windows LAPS so Global Admin credentials never live on client devices.
  • Tightly control emergency access with locked-down break-glass accounts and limit the number of active Global Admins.
    Use approval workflows, MFA that isn’t reusable, and quarterly access reviews to keep roles current.
  • Audit these items this week: look for shared accounts, check active vs eligible admin assignments, remove legacy auth protocols, confirm GDAP use, and enforce phishing-resistant MFA.
    Fixing these areas removes easy attack paths and improves compliance and traceability.

Jonathan Edwards released a clear and timely YouTube video explaining why so many Managed Service Providers are mismanaging privileged access in Microsoft environments. In the video he argues that common practices, such as using a single shared Global Admin password and storing MFA codes in a shared vault, destroy accountability and increase risk. Consequently, Edwards presents a practical model to replace those habits with stronger controls that align with modern security expectations. This article summarizes his key points and explains the tradeoffs and challenges MSPs must consider when adopting the fixes he recommends.

Overview of the Problem

Edwards begins by describing a familiar scenario: one shared admin account that everyone knows and uses. This setup makes it impossible to trace who did what, so accountability disappears and response to incidents gets slower and less precise. Moreover, when an MFA token sits in a shared vault, the supposed benefit of two-factor authentication collapses because the protection is effectively shared just like the password. As a result, MSP teams often feel secure while they remain exposed.


He frames the issue as more than bad habit: it is a systemic weakness that invites targeted attacks. Attackers prefer a small number of high-privilege accounts to compromise, and shared credentials create many high-value targets across tenants. Edwards stresses that this problem is common enough to require urgent action by MSP owners and engineers. Therefore, the video aims to offer concrete alternatives rather than just warnings.


The Core Fixes: Named Admins, GDAP, and PIM

Edwards recommends moving to named admin identities instead of shared credentials, which restores traceability and discipline. In addition, he advises using GDAP (Granular Delegated Admin Privileges) rather than client credentials, because GDAP gives limited, auditable access to specific roles and resources. He also emphasizes the use of Microsoft Entra ID features like PIM and JIT elevation so admins remain eligible rather than permanently active in high-privilege roles. Together these changes reduce the attack surface and improve forensic visibility.


Further, Edwards highlights the importance of enforcing phishing-resistant authentication methods such as FIDO2 passkeys and certificate-based options. He points out that not all MFA is equal, and storing shared MFA secrets undermines strong methods entirely. For tenant-level protection he recommends limiting the number of true Global Admin accounts to a minimal set and tagging those accounts for extra monitoring. Thus, the recommended model balances reduced exposure with continued operational capability.


Protecting Devices and Credentials with LAPS and PAWs

A central detail in Edwards’s guidance is to stop letting Global Admin credentials touch client devices. To address that, he proposes using Windows LAPS and Privileged Access Workstations so local admin rights never leak into cloud control planes. By isolating administrative activities onto hardened endpoints, teams lower the chance of lateral movement from everyday tools like email or web browsing. This separation enforces a practical boundary between routine work and sensitive administration.


However, Edwards explains that adding PAWs and LAPS introduces operational overhead and training needs. For example, organizations must manage updates, provisioning, and recovery processes for those special workstations, which costs time and attention. Still, the long-term payoff often outweighs the overhead because the risk of a large tenant-wide breach drops significantly. Therefore, MSPs must weigh short-term friction against the long-term security benefits.


Tradeoffs and Operational Challenges

Edwards candidly addresses tradeoffs, noting that stricter controls can slow day-to-day tasks if teams apply them without planning. For instance, PIM approvals and temporary elevation workflows add steps that can delay incident response if not tuned correctly. Consequently, he suggests automating approval rules where safe, providing clear runbooks, and setting sensible elevation windows to strike a balance. This approach preserves security while keeping operations practical.


Another challenge he raises is legacy environments that still rely on hybrid accounts or legacy authentication protocols. Migrating those setups to modern, role-based models demands testing, staged rollouts, and stakeholder buy-in. Edwards recommends an incremental path: start with high-risk tenants, enforce better MFA, and progressively convert permanent roles into eligible ones. In doing so, MSPs can reduce disruption while steadily improving their security posture.


Practical Steps, Auditing, and Next Actions

Finally, Edwards provides an audit checklist MSPs can use this week, including reviewing admin account assignments, checking for shared credentials, and verifying that MFA tokens are bound to individual users. He also encourages auditing PIM activations and access reviews to ensure justifications and approvals match recorded activities. These practices create a clearer trail and make it easier to spot anomalies before they escalate.


In conclusion, Edwards’s video offers practical, actionable guidance that mixes strong technical controls with realistic operational advice. While the fixes require effort and some tradeoffs, they address core weaknesses that leave MSPs and their clients exposed. For MSP owners and engineers who want to improve security without breaking operations, his model provides a clear roadmap to follow.


Identity - Microsoft Entra: Fix MSP Admin Access

Keywords

MSP admin access mistakes, privileged access management for MSPs, PAM best practices MSPs, least privilege model MSPs, secure RMM access for MSPs, admin credential management MSPs, MFA for MSP admin accounts, zero trust strategies for MSPs