too many people have too many keys f30d8b8d

Too Many People Have Too Many Keys

Category : | | Posted : Jun 3, 2026

When we onboard a new client, one of the first things we look at is who has the keys. Not metaphorically. Literally. Who in this Microsoft 365 tenant can do anything they want, and what else are those accounts doing all day?

The answer, more often than it should be, is the owner. Or the office manager. Or the person who set the whole thing up six years ago and never thought about it again. Their everyday email (the one they use to send quotes, open PDFs from strangers, click links from vendors, sign into apps on their phone) is also the account that can do anything inside the environment. Reset anyone’s password. Read anyone’s mail. Turn off security controls. Wipe a laptop. Hand the same keys to someone else.

That’s the tell. When the daily-use account and the top-level admin account are the same account, nobody has been thinking about how bad a bad day could get.

Picture it this way. If this account gets compromised (phished, password reused on some breached site), how far does the damage reach? When it’s the top-level admin, the answer is “everywhere.” Email, files, identities, backups, settings, the whole environment. One bad click and an attacker doesn’t just get into one mailbox. They own the place.

There are two fixes, and most organizations skip both. They’re not exotic. They’re not expensive. Microsoft has recommended them for years. The honest reason they get skipped is that they take real hours to set up, and someone has to make the case for spending those hours when nothing is currently on fire. That’s a hard sell internally, and it’s a hard sell to a client when the invoice shows up. Often there are just too many other fires to put out, and this isn’t one of them yet. So it sits.

The first fix: a separate admin account you only sign into when you need it. Your everyday account, the one used for email and Teams and the apps on your phone, has no admin rights at all. When you need to do something administrative, you sign into a different account that exists only for that. Different username, different password, different MFA. The account exposed to the internet all day, clicking links and opening attachments, is not the account that can blow up your environment. If it gets compromised, the damage stops at one person.

The second fix is giving people only the access they actually need. Stop handing out top-level admin as the default. Someone who resets passwords for the help desk doesn’t need it. Someone who manages email groups doesn’t need it. Someone who handles new hires and departures doesn’t need it. Microsoft 365 has more specific roles for all of these. They give people what they need to do their job and nothing more.

This one gets skipped because it takes extra thought and care. Figuring out who needs to do what, and matching that to the right role, is a small project. It’s easier to just make everyone a top-level admin and move on. That’s how it quietly becomes the norm. Three people need to do “some admin stuff,” three people get full keys, and nobody ever revisits it. If one of those accounts gets compromised, or one of those people leaves on bad terms, the damage is the same as if the owner’s account got hit.

This is one of the quieter reasons IT support for a small business looks different than people expect. The flashy work is the new laptop, the migration, the helpdesk ticket closed in twenty minutes. The work that actually saves the company is the boring inventory of who has what, and the patience to keep it tidy over time. Whether that work happens inside the building or through outsourced IT, somebody has to own it. If nobody owns it, it doesn’t happen.

This isn’t about distrust. It’s about containment. The fewer rights any one account has, the smaller the damage when something goes wrong. And something will go wrong eventually. That’s the whole reason we’re talking about this.

A worthwhile thing to do this week: open your Microsoft 365 admin center, go to Roles, and look at who has Global Administrator assigned. If the list includes the everyday email accounts of people who use those mailboxes all day, you’ve found a real problem. In a small business, more than two or three names is usually a flag too. In a larger org, the right number scales up, but the principle holds: it should be a deliberate list, not an accidental one.

Then have the conversation with your team or your managed IT services provider. Not “are we secure.” That question is too big to answer usefully. Ask the specific one: “Who has what admin permissions in our environment, why do they have it, and what would happen if any one of those accounts got phished tomorrow?”

Written By

why are we paying nearly the same money for less protection

Why Are We Paying Nearly the Same Money for Less Protection?

Microsoft just raised prices across most of its business SKUs. Business Basic, Standard, E3, E5,…

Read More
mfa is on the floor for attacking it just dropped

MFA is on. The floor for attacking it just dropped.

MFA was on. It had been on for years. The training had been done, the…

Read More