
No-Faffing Managed IT Support & Cyber Security Support. Made in Yorkshire, built for the UK.
Jonathan Edwards released a clear and timely YouTube video explaining why so many Managed Service Providers are mismanaging privileged access in Microsoft environments. In the video he argues that common practices, such as using a single shared Global Admin password and storing MFA codes in a shared vault, destroy accountability and increase risk. Consequently, Edwards presents a practical model to replace those habits with stronger controls that align with modern security expectations. This article summarizes his key points and explains the tradeoffs and challenges MSPs must consider when adopting the fixes he recommends.
Edwards begins by describing a familiar scenario: one shared admin account that everyone knows and uses. This setup makes it impossible to trace who did what, so accountability disappears and response to incidents gets slower and less precise. Moreover, when an MFA token sits in a shared vault, the supposed benefit of two-factor authentication collapses because the protection is effectively shared just like the password. As a result, MSP teams often feel secure while they remain exposed.
He frames the issue as more than bad habit: it is a systemic weakness that invites targeted attacks. Attackers prefer a small number of high-privilege accounts to compromise, and shared credentials create many high-value targets across tenants. Edwards stresses that this problem is common enough to require urgent action by MSP owners and engineers. Therefore, the video aims to offer concrete alternatives rather than just warnings.
Edwards recommends moving to named admin identities instead of shared credentials, which restores traceability and discipline. In addition, he advises using GDAP (Granular Delegated Admin Privileges) rather than client credentials, because GDAP gives limited, auditable access to specific roles and resources. He also emphasizes the use of Microsoft Entra ID features like PIM and JIT elevation so admins remain eligible rather than permanently active in high-privilege roles. Together these changes reduce the attack surface and improve forensic visibility.
Further, Edwards highlights the importance of enforcing phishing-resistant authentication methods such as FIDO2 passkeys and certificate-based options. He points out that not all MFA is equal, and storing shared MFA secrets undermines strong methods entirely. For tenant-level protection he recommends limiting the number of true Global Admin accounts to a minimal set and tagging those accounts for extra monitoring. Thus, the recommended model balances reduced exposure with continued operational capability.
A central detail in Edwards’s guidance is to stop letting Global Admin credentials touch client devices. To address that, he proposes using Windows LAPS and Privileged Access Workstations so local admin rights never leak into cloud control planes. By isolating administrative activities onto hardened endpoints, teams lower the chance of lateral movement from everyday tools like email or web browsing. This separation enforces a practical boundary between routine work and sensitive administration.
However, Edwards explains that adding PAWs and LAPS introduces operational overhead and training needs. For example, organizations must manage updates, provisioning, and recovery processes for those special workstations, which costs time and attention. Still, the long-term payoff often outweighs the overhead because the risk of a large tenant-wide breach drops significantly. Therefore, MSPs must weigh short-term friction against the long-term security benefits.
Edwards candidly addresses tradeoffs, noting that stricter controls can slow day-to-day tasks if teams apply them without planning. For instance, PIM approvals and temporary elevation workflows add steps that can delay incident response if not tuned correctly. Consequently, he suggests automating approval rules where safe, providing clear runbooks, and setting sensible elevation windows to strike a balance. This approach preserves security while keeping operations practical.
Another challenge he raises is legacy environments that still rely on hybrid accounts or legacy authentication protocols. Migrating those setups to modern, role-based models demands testing, staged rollouts, and stakeholder buy-in. Edwards recommends an incremental path: start with high-risk tenants, enforce better MFA, and progressively convert permanent roles into eligible ones. In doing so, MSPs can reduce disruption while steadily improving their security posture.
Finally, Edwards provides an audit checklist MSPs can use this week, including reviewing admin account assignments, checking for shared credentials, and verifying that MFA tokens are bound to individual users. He also encourages auditing PIM activations and access reviews to ensure justifications and approvals match recorded activities. These practices create a clearer trail and make it easier to spot anomalies before they escalate.
In conclusion, Edwards’s video offers practical, actionable guidance that mixes strong technical controls with realistic operational advice. While the fixes require effort and some tradeoffs, they address core weaknesses that leave MSPs and their clients exposed. For MSP owners and engineers who want to improve security without breaking operations, his model provides a clear roadmap to follow.
MSP admin access mistakes, privileged access management for MSPs, PAM best practices MSPs, least privilege model MSPs, secure RMM access for MSPs, admin credential management MSPs, MFA for MSP admin accounts, zero trust strategies for MSPs