Black Shard

Insights6 October 2026

Entra ID privileged access: PIM, admin roles and break-glass accounts

Privileged access in Microsoft Entra ID comes down to four decisions: how few people hold each high-impact role, whether they hold it all the time or activate it when needed through Privileged Identity Management, how administrators authenticate, and how the organisation gets back in when conditional access or an identity provider fails. Two monitored emergency access accounts with phishing-resistant credentials answer the last question. The same decisions carry the administrative privilege requirements of the Essential Eight.

Why does privileged access in Entra ID matter so much?

Entra ID is the identity control plane for Microsoft 365 and Azure. A Global Administrator can read every mailbox, change every conditional access policy, add credentials to any application, and elevate to User Access Administrator over every Azure subscription with one setting. Privileged Role Administrator, Privileged Authentication Administrator, Application Administrator and Cloud Application Administrator each reach a large share of that power by another route.

Attackers who compromise an administrator rarely need malware. They add a federated domain, grant consent to an application they control, or create a new credential on an existing service principal, and keep access after the password is reset. Limiting who holds these roles, and when, is the control that cuts those paths.

How many Global Administrators should a tenant have?

Microsoft recommends fewer than five Global Administrators, and at least two so one person's absence does not lock the organisation out. Most day-to-day work needs a narrower role: User Administrator for accounts, Exchange Administrator for mail, Intune Administrator for devices, Helpdesk Administrator for password resets. The review question for each Global Administrator assignment is which task needs it that a narrower role cannot do.

Administrative work should run from dedicated accounts that hold no mailbox, browse nothing, and exist only for administration. The Essential Eight states the same requirement at Maturity Level One: privileged users get a separate privileged account, and privileged accounts cannot access the internet, email and web services unless explicitly authorised.

What does Privileged Identity Management change?

Privileged Identity Management, PIM, makes role assignments eligible instead of active. An eligible administrator holds no privilege until they activate the role, for a set duration, after meeting the activation requirements. PIM requires Microsoft Entra ID P2 or Microsoft Entra ID Governance licences for the users who benefit from it.

The activation settings are where PIM earns its value. For Global Administrator and the other high-impact roles, require multi-factor authentication on activation, ideally through an authentication context bound to phishing-resistant methods, require a justification, require approval from a second administrator, cap the activation at a few hours, and send a notification on every activation. Lower-impact roles can activate without approval.

PIM also runs access reviews. A quarterly review of eligible assignments, with assignments removed when the reviewer does not confirm them, answers the Essential Eight Maturity Level Two requirement to revalidate privileged access at least every 12 months and to disable it after 45 days without use. Just-in-time administration is a Maturity Level Three requirement, and PIM is how a Microsoft tenant meets it.

SettingGlobal Administrator and equivalentLower-impact administrative roles
Assignment typeEligible, with no permanent active assignments except emergency access accountsEligible
Activation durationOne to four hoursUp to eight hours
Authentication on activationPhishing-resistant MFA through an authentication contextMFA
ApprovalRequired from a second administratorOptional
JustificationRequiredRequired
NotificationOn every activation, to a monitored addressOn activation
Access reviewQuarterlySix-monthly

PIM activation settings for high-impact Entra ID roles

How should administrators authenticate?

Administrators should use phishing-resistant methods: passkeys or FIDO2 security keys, Windows Hello for Business, or certificate-based authentication. Adversary-in-the-middle phishing kits capture a password and a one-time code or push approval together, and they capture the session token as well. Phishing-resistant methods are bound to the legitimate sign-in page and defeat that technique.

Conditional access enforces it. A policy targeting directory roles that requires the phishing-resistant authentication strength, combined with a requirement for a compliant or privileged access device, covers sign-ins by administrators. Microsoft now enforces multi-factor authentication for sign-in to the Azure portal and the Entra, Intune and Microsoft 365 admin centres, which sets a floor. The authentication strength policy decides which methods clear it.

How should break-glass accounts be set up?

Emergency access accounts, often called break-glass accounts, exist for the day conditional access is misconfigured, the federation provider is down, or every administrator is locked out. Microsoft recommends at least two. They are cloud-only accounts on the tenant's onmicrosoft.com domain, hold a permanent active Global Administrator assignment, and belong to no individual.

With multi-factor authentication now enforced on the admin portals, emergency access accounts need a credential that satisfies it without depending on the systems that might fail. FIDO2 security keys or certificate-based authentication fit, with the keys stored physically apart. Each account is excluded from the conditional access policies that could lock it out, and the exclusion is documented.

An unmonitored break-glass account is a standing Global Administrator nobody watches. Every sign-in by either account should raise an alert to several people through a Log Analytics alert rule or Microsoft Sentinel. The accounts should be tested on a schedule, often every 90 days, with the test recorded.

  • Two cloud-only accounts on the onmicrosoft.com domain, owned by the organisation and assigned to nobody.
  • Permanent active Global Administrator, outside PIM, so activation cannot fail when it is needed.
  • Phishing-resistant credentials such as FIDO2 keys, held in separate secure locations.
  • Documented exclusion from conditional access policies that could block them.
  • An alert on every sign-in, routed to more than one person.
  • A recorded sign-in test on a fixed schedule.

What does the Essential Eight ask of privileged access?

The Essential Eight's restrict administrative privileges strategy maps closely onto Entra ID controls. The requirements build by maturity level, and a Microsoft tenant can meet each of them with features it already licenses or can add.

RequirementMaturity levelEntra ID control
Requests for privileged access are validated when first requestedOnePIM assignment with approval, or a documented role request process
Privileged users use a separate privileged accountOneDedicated cloud-only admin accounts without mailboxes
Privileged accounts cannot access the internet, email and web services unless explicitly authorisedOneNo licence for mail on admin accounts, and conditional access limiting admin sign-in to privileged access devices
Privileged access is revalidated at least every 12 monthsTwoPIM access reviews on eligible assignments
Privileged access is disabled after 45 days of inactivityTwoAccess reviews using last sign-in, with automatic removal
Privileged access is limited to just in timeThreePIM eligible assignments with time-bound activation

Essential Eight administrative privilege requirements and the Entra ID control that meets them

Which other privileged paths get missed?

Role assignments are one path. Service principals with Microsoft Graph application permissions such as RoleManagement.ReadWrite.Directory or AppRoleAssignment.ReadWrite.All can grant themselves Global Administrator. Owners of those applications can add credentials to them. Partner relationships under granular delegated admin privileges, and older delegated admin relationships from a reseller, grant roles to people outside the tenant. Azure subscription Owners can be reached through automation accounts and pipelines.

A privileged access review lists all of these alongside the Entra roles, because an attacker uses whichever is least watched.

How do you check where your tenant stands?

Start with four exports: active and eligible role assignments with last sign-in dates, the conditional access policies that target directory roles, the emergency access account configuration and its alerting, and application permissions on Microsoft Graph with their owners. Those four exports show where privileged access stands in an afternoon.

Black Shard's Entra ID security review covers privileged roles, PIM settings, conditional access, emergency access, app consent and partner access in full, with read-only access, and the Microsoft 365 and Azure security review starts at $3,500 ex GST for a fixed scope. Where Azure subscriptions are in play, the Azure security review covers the RBAC side. Scope is set on a free 30-minute scoping call.

Tell us where your security program stands.

Brisbane head office.

Open a briefinfo@blackshard.com.au