Managed service providers · 19 August 2026 · 4 min
Standing admin rights are an MSP's biggest concentration risk
Every technician holding permanent Global Administrator in a client tenant is an attack path into all of your clients at once. The answer is not fewer technicians — it is zero standing rights.
The operating model of a typical MSP has a built-in dilemma. For the service desk to deliver, technicians need rights in client tenants. Hand the rights out broadly, and you have multiplied the attack surface by your headcount. Keep them with a select few, and you have built a bottleneck where every client waits in the same queue — and the few people holding the keys can never take holiday at the same time.
The security consequence is worse than the queue. A compromised technician account with standing rights in twenty client tenants is not one incident — it is twenty. Attacks through service providers are an established tactic precisely because one successful phish against an MSP technician opens many doors at once.
Microsoft's answer is Privileged Identity Management: rights that are activated temporarily instead of held permanently. PIM is real progress, and if you have one tenant and a team with the time to configure it properly, it takes you far. But PIM does not change the underlying model: whoever activates the role still holds broad access for the duration of the activation window, and still makes the changes manually, directly in the directory. What was approved and what was done are still two different things — connected by trust, not by architecture.
Entra Logic inverts the model. Nobody — not the service desk, not second line, not the client's own administrators — needs standing admin rights in the tenant. Instead, they browse a continuously synchronised copy of the client's Entra ID and M365 environment and submit change requests: an "order." The order is routed to the right approver — on your side or the client's, depending on what the per-tenant configuration says — and only then does a central execution engine carry out the change against Microsoft Graph. Exactly what was approved. Nothing else.
The maths for an MSP then changes. The number of people who can act on identity can grow with the business — more service desk staff, delegated roles at the client, even HR. The number of people with privileged access does not grow with it, because the privilege sits in the system's service identity, not in the humans. Growth in client base no longer requires growth in risk.
And when the client asks — or when the insurer's questionnaire asks, ever more precisely — "who at your provider has admin access to our environment?", there are few better answers than: nobody, permanently. Every change has a request, an approval and an execution, bound together in one trail.
That is the difference between having control and being able to prove it. For an MSP, the latter is what sells.
Norwegian version: Les artikkelen på norsk
Related reading
- The audit trail is no longer internal — it is something your clients buy
Managed service providers · 4 min
- Copilot credits turn group hygiene into a budget question
Managed service providers · 4 min
- One console, many tenants: what MSPs actually need from Entra ID tooling
Practice · 6 min