{"id":10801,"date":"2019-04-25T06:00:37","date_gmt":"2019-04-25T13:00:37","guid":{"rendered":"https:\/\/www.zubairalexander.com\/stage\/?p=10801"},"modified":"2019-11-16T14:14:23","modified_gmt":"2019-11-16T21:14:23","slug":"best-practices-for-configuring-the-global-admin-account-in-office-365","status":"publish","type":"post","link":"https:\/\/www.zubairalexander.com\/blog\/best-practices-for-configuring-the-global-admin-account-in-office-365\/","title":{"rendered":"Best Practices for Configuring the Global Admin Account in Office 365"},"content":{"rendered":"<p><span style=\"color: #000000;\">Use the following best practices to secure your Global Admin account in Microsoft Office 365.<\/span><\/p>\n<ol>\n<li><span style=\"color: #000000;\">For maximum security, use the maximum allowed password length for your Global Admin accounts.<\/span><br \/>\n<span style=\"color: #000000;\"><span style=\"color: #ff0000;\"><span style=\"text-decoration: underline;\">NOTE<\/span>: The maximum password length used to be 16 characters with no spaces. As of May 14, 2019, Azure Active Directory supports passwords up to 256 characters and they can contain spaces.<\/span><br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-11332\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2019\/04\/AzureAD-passwords.png\" alt=\"Azure AD password can be 8-256 characters\" width=\"352\" height=\"101\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2019\/04\/AzureAD-passwords.png 352w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2019\/04\/AzureAD-passwords-300x86.png 300w\" sizes=\"(max-width: 352px) 100vw, 352px\" \/><br \/>\n<\/span><\/li>\n<li><span style=\"color: #000000;\">Always create at least one additional Global Admin account as a backup. This account doesn&#8217;t need an Office 365 license.<\/span><\/li>\n<li><span style=\"color: #000000;\">Instead of using <span style=\"text-decoration: underline; color: #0000ff;\">AdminName@YourDomain.com<\/span> account for the Global Admin account, use the\u00a0<span style=\"text-decoration: underline; color: #0000ff;\">AdminName@YourDomain.onmicrosoft.com<\/span> account and DO NOT assign any licenses.<\/span><\/li>\n<li><span style=\"color: #000000;\">Don&#8217;t use your Global Admin account to do your daily tasks. Create a separate account for Global Admin. For example, Trisha@Contoso.com for daily activities and TrishaAdmin@Contoso.com for administrative duties.<\/span><\/li>\n<li><span style=\"color: #000000;\">Create at least two <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/users-groups-roles\/directory-emergency-access\" target=\"_blank\" rel=\"noopener noreferrer\">emergency access accounts<\/a> (also known as <em>break glass accounts<\/em>) that are meant to be used only during an emergency. Exclude the emergency account from all security policies and phone-based multi-factor authentication.<\/span><\/li>\n<li><span style=\"color: #000000;\">Always use a phone number and an <em>Alternative email address<\/em> for your Global Admin account so it can be used for verification by Microsoft, if there&#8217;s a need.<\/span><br \/>\n<span style=\"color: #000000;\"><a style=\"color: #000000;\" href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/configuring-alternative-email.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9170\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/configuring-alternative-email.png\" alt=\"Configuring alternative email for Global Admin\" width=\"832\" height=\"435\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/configuring-alternative-email.png 832w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/configuring-alternative-email-300x157.png 300w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/configuring-alternative-email-768x402.png 768w\" sizes=\"(max-width: 832px) 100vw, 832px\" \/><\/a><\/span><\/li>\n<li><span style=\"color: #000000;\">Limit the number of Global Admins in your organization to as few as possible. The rest of the administrators should be assigned a Customized administrator role, such as Billing administrator, Dynamics 365 service administrator, Exchange administrator, Password administrator, Skype for Business administrator, Power BI service administrator, Reports reader, Service administrator, SharePoint administrator,\u00a0 or User management administrator. Keep in mind you can assign multiple roles to an individual.<\/span><br \/>\n<span style=\"color: #000000;\"><a style=\"color: #000000;\" href=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/customized-administrator.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-9171\" src=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/customized-administrator.png\" alt=\"Customized Administrator Role\" width=\"477\" height=\"490\" srcset=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/customized-administrator.png 477w, https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2018\/01\/customized-administrator-292x300.png 292w\" sizes=\"(max-width: 477px) 100vw, 477px\" \/><\/a><\/span><\/li>\n<\/ol>\n<h4><span style=\"color: #000000;\"><strong>Useful Links<\/strong><\/span><\/h4>\n<p><span style=\"color: #000000;\">Here are some links that you may find helpful.<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/www.zubairalexander.com\/blog\/password-recommendations-for-microsoft-accounts\/\">Password Recommendations for Microsoft Accounts<\/a><\/li>\n<li><a href=\"https:\/\/support.office.com\/en-us\/article\/Set-up-multi-factor-authentication-for-Office-365-users-8f0454b2-f51a-4d9c-bcde-2c48e41621c6?ui=en-US&amp;rs=en-US&amp;ad=US\" target=\"_blank\" rel=\"noopener noreferrer\">Setup Multi-Factor Authentication for Office 365 Users<\/a><\/li>\n<li><a href=\"https:\/\/www.zubairalexander.com\/blog\/best-practices-for-configuring-multifactor-authentication-in-office-365\/\">Best Practices for Configuring Multi-factor Authentication in Office 365<\/a><\/li>\n<li><a href=\"https:\/\/www.zubairalexander.com\/blog\/microsoft-authenticator-to-allow-phone-sign-in-without-a-password\/\">Microsoft Authenticator to Allow Phone Sign In Without a Password<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/users-groups-roles\/directory-emergency-access\" target=\"_blank\" rel=\"noopener noreferrer\">Manage emergency access administrator accounts<\/a><\/li>\n<\/ul>\n<table>\n<tbody>\n<tr>\n<td style=\"background-color: #e3e3e3; text-align: left;\">Thanks for reading my article. If you are interested in IT training &amp; consulting services, please reach out to me. Visit <a href=\"https:\/\/www.zubairalexander.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">ZubairAlexander.com<\/a> for information on my professional background.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<p><span style=\"font-size: xx-small; font-family: Verdana;\">Copyright \u00a9 2019 <a href=\"https:\/\/www.seattlepro.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">SeattlePro Enterprises, LLC<\/a>. All rights reserved.<br \/>\n<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Use the following best practices to secure your Global Admin account in Microsoft Office 365. For maximum security, use the maximum allowed password length for your Global Admin accounts. NOTE: The maximum password length used to be 16 characters with no spaces. As of May 14, 2019, Azure Active Directory supports passwords up to 256 [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":8601,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[43,63,24,11],"tags":[],"class_list":["post-10801","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","category-office-365","category-security","category-tips-tricks"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2017\/08\/Security2.jpg","_links":{"self":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts\/10801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/comments?post=10801"}],"version-history":[{"count":0,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts\/10801\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/media\/8601"}],"wp:attachment":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/media?parent=10801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/categories?post=10801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/tags?post=10801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}