PA-01: Limit Global Administrators to 2-4

Frequently asked questions about implementing and managing the PA-01 security control in Microsoft 365 and Entra ID.

Q
What is PA-01 (Limit Global Administrators to 2-4)?
A

PA-01 is a security control that global administrators have unrestricted access to your entire tenant. too many increases your attack surface; too few risks lockout. service principals and groups with global admin are especially dangerous - service principals can be compromised via app credentials, and groups hide who actually has the role. microsoft recommends 2-4 permanent global admins for most organizations. It requires that between 2 and 4 principals have the global administrator role and no single point of failure (minimum 2), attack surface is minimized (maximum 4), no service principals have global administrator (use least-privilege), no groups have global administrator (hidden privilege escalation risk).

Related controls:PA-01
Q
Why is Limit Global Administrators to 2-4 important for Microsoft 365 security?
A

Global Administrators have unrestricted access to your entire tenant. Too many increases your attack surface; too few risks lockout. Service principals and groups with Global Admin are especially dangerous - service principals can be compromised via app credentials, and groups hide who actually has the role. Microsoft recommends 2-4 permanent Global Admins for most organizations.

Related controls:PA-01
Q
How do I implement PA-01 in my tenant?
A

PA-01 requires manual implementation. Review and adjust Global Administrator assignments manually. Remove service principals and groups.

Related controls:PA-01
Q
What license do I need for PA-01?
A

This control can be implemented with any Microsoft 365 subscription, including free Azure AD.

Related controls:PA-01
Q
Which security baseline includes PA-01?
A

PA-01 is included in the TrueConfig Recommended Secure baseline (Level 1). This is the foundation level suitable for most organizations.

Related controls:PA-01
Q
Why is PA-01 marked as critical severity?
A

PA-01 is rated critical because failure to implement this control significantly increases the risk of security incidents. Global Administrators have unrestricted access to your entire tenant. Too many increases your attack surface; too few risks lockout. Service principals and groups with Global Admin are especially dangerous - service principals can be compromised via app credentials, and groups hide who actually has the role. Microsoft recommends 2-4 permanent Global Admins for most organizations.

Related controls:PA-01

6

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial