What it is

In Azure, the closest thing to the AWS root user is a Global Administrator in Microsoft Entra ID. It can create other admins, change billing, reset passwords, and reach almost every Microsoft cloud service tied to that tenant.

Unlike AWS root, you can have more than one. That sounds safer. In practice it means the master key got copied. A contractor from 2021. A break-glass account nobody has tested. A founder who “just needs to get in.”

Microsoft’s own advice is the same as AWS: almost nobody should hold this day to day. Privileged Identity Management exists so the power is borrowed for an hour, not parked in a mailbox forever.

Why it matters in the meeting

When Bart asks how many Global Admins you have, he is not being pedantic. He is asking how many passwords can empty the building.

If the number is more than two, and one of them is a standing user with no MFA, you have the Azure version of an unlocked root. The meeting should stop there until that is a known number, not a guess.

Real world

Tenant takeovers usually do not start with a clever exploit. They start with an admin account that was created for a project, never removed, and reused for “just this one report.”

Auditors look for Global Admin count early because the blast radius is the whole Microsoft estate: email, files, Azure subscriptions, and the ability to make more admins.

In plain terms

A Global Admin is not a convenience role. It is the last resort key for the Microsoft tenant. Treat it like the AWS root user, except you may have accidentally issued three of them.

What to ask

  • How many Global Administrators exist in Entra ID right now, named, not “a handful”?
  • Is MFA enforced on every one of them, including break-glass?
  • Do we use Privileged Identity Management, or is this a standing assignment?
  • Who still has Global Admin who should have been removed when they left the project?

You just knew a little more Jack than you did five minutes ago.

All concepts