← Back to insights

Practice · 20 August 2026 · 6 min

Standing admin rights are a reporting problem before they are a security problem

Permanent admin roles rarely cause the breach. They make it impossible to explain what happened afterwards — and that is what an auditor asks about.

Every argument against standing admin rights is framed as a breach argument: a compromised account with Global Administrator can do anything. That is true, and it is also the least likely thing to happen in a well-run tenant with conditional access and phishing-resistant MFA.

The everyday cost is different. When twelve people can change anything at any time, nobody can reconstruct why a change was made. The sign-in log tells you an account did something at 14:22. It does not tell you who asked for it, who approved it, or whether anyone did.

The audit question is never "who could"

Auditors ask a narrow question: show me the basis for this access. Not the capability, the basis. A directory audit log answers the first half — an object changed, an actor changed it — and is silent on the second.

Most organizations close the gap with a ticketing system. The ticket holds the reason and the approval; the directory holds the change. Correlating them is manual, and the correlation breaks the first time someone does the work before the ticket is filed, which happens on every busy Friday.

Make the order the change

The alternative is to make the approved request the thing that executes. The requester states the reason once. The approver sees the exact change and the cost. The platform performs it. Request, reason, approval and result end up in the same record because they were never in different systems.

Once that holds, standing rights become unnecessary rather than forbidden. Nobody needs a permanent role to do work that runs through an approved order — and the people who kept their admin role "just in case" stop needing the exception.

What to check in your own tenant this week

Count the accounts holding a privileged directory role permanently, including service accounts and break-glass accounts, and write down the justification for each one. Then take a change from three months ago and try to produce, in under five minutes, the reason it was made and the name of the person who approved it.

If the second exercise takes longer than the first, the problem is the record, not the roles.

RELEVANT SOLUTION

See how this is handled in practice: