01745 616 524 servers@comstat.uk
  • Facebook
  • Facebook
Comstat | Ruthin, North Wales | 01745 616 524
  • Home
  • Web Hosting
  • Web Design
  • How to
    • Articles/Help
    • Support
  • Contact
Select Page

Microsoft 365 Global Administrator: Why You Need a Second Admin and How to Assign Roles

by Steve Galloway | Nov 10, 2025

Introduction

The Microsoft 365 Global Administrator role is the most powerful role in your tenant. It grants full control over users, groups, and settings. However, many small businesses assume that one global admin is enough—and that this role automatically includes every privilege. In reality, some critical capabilities, such as billing and advanced authentication management, require additional roles. This article explains what a global administrator does, why you need a second Microsoft 365 global administrator, and how to organize roles for maximum security and continuity.

Click open the headers below to learn more about how to protect your IT assets by establishing a second Microsoft 365 Global Administrator to protect your Microsoft 365 tenancy in the event of force majeure. Support options are available for professional assistance.

What Is a Microsoft 365 Global Administrator?

A global administrator in Microsoft 365 (also known as an Entra ID global admin) can manage all aspects of your tenant, including user accounts, licenses, and security settings. This role is essential for tasks such as:

  • Adding or deleting users
  • Resetting passwords
  • Assigning licenses
  •  Configuring security policies

However, global admin privileges do not automatically include billing or advanced security functions. For example, managing invoices for your tenancy, buying/cancelling licenses, or overriding multifactor authentication (MFA) blocks requires additional separate roles.

Why Is a Seond Micrsoft 365 Global Administrator Is Essential

Microsoft recommends having at least two global administrators. This ensures:

  • Business continuity during emergencies
  • Shared responsibility for critical changes
  • Reduced risk of lockouts caused by lost credentials or MFA issues

Establishing a second Microsoft 365 Global Administrator in your 365 tenancy protects against you against a situation arising that locks you out of server-level administration.

Roles That Complement a Microsoft 365 Global Administrator

To fully mirror the capabilities of your principal Microsoft 365 global administrator, assign these additional roles to the second admin:

  • Billing Administrator – Manages invoices, payment methods, and subscriptions
  • Privileged Authentication Administrator – Overrides MFA and security blocks
  • Authentication Policy Administrator – Configures authentication methods and policies
  • Service Support Administrator – Opens support tickets with Microsoft

These roles can be assigned in the Microsoft 365 Admin Center or Azure AD (Entra) under Roles and administrators.

Does Licensing Affect MFA for Microsoft 365 Global Administrators?

No. If a second Microsoft 365 global administrator account does not have a Microsoft 365 license assigned to it, it can still perform MFA authentication. MFA enforcement is identity-based, not license-based. The only limitation is that an unlicensed admin cannot use services like Outlook or Teams. For email alerts and notifications, consider assigning at least an Exchange Online license.

How to Organize Your Admin Accounts
  1. Create a second global admin account
  2. Assign MFA to both global admins
  3. Add complementary roles (Billing, Privileged Authentication, etc.)
  4. Document your admin strategy for continuity

About ComStat.uk: Internet Service Provider Comstat provides IT support, web hosting, and media services including website design, Microsoft 365 setup, and audio/video production, serving businesses across Denbighshire, North Wales and Wirral from Ruthin, and Lancashire and the Northwest from Bolton.

Microsoft 365 Global Administrator: Why Business Continuity needs 2 global admins

by Steve Galloway | Nov 10, 2025

Introduction

For many small businesses, Microsoft 365 is the backbone of daily operations—email, files, collaboration, and security all depend on it. At the heart of this system is the Microsoft 365 Global Administrator, the most powerful role in your tenant. But what happens if the person holding that role leaves suddenly or becomes unavailable? Without planning, this scenario can lead to a catastrophic lockout, halting your business operations. This article explains the risk and how to prevent it.

Click open the headers below to learn more about how to protect your IT assets by establishing a second Microsoft 365 Global Administrator to protect your Microsoft 365 tenancy in the event of force majeure. Support options are available for professional assistance.

The Risk of a Single Global Administrator

When you set up Microsoft 365, the first account created becomes the principal global administrator. This account controls everything: user management, licenses, security settings, and more. If that person leaves the company, passes away, or loses access because their account has been hijacked, your organization could face:

  • Inability to renew licenses or update billing details
  • Locked-out users due to MFA or security blocks
  • No way to add or remove accounts or assign roles

This is not just inconvenient—it can catastrophically disrupt your organization’s IT.

Why a Second Global Admin Is Crucial

Microsoft recommends having at least two global administrators. This ensures:

  • Business continuity during emergencies
  • Shared responsibility for critical changes
  • Reduced risk of lockouts caused by lost credentials or MFA issues

Establishing a second Microsoft 365 Global Administrator in your 365 tenancy protects against you against a situation arising that locks you out of server-level administration.

Best Practices for Setting Up a Second Global Administrator

1. Create a second Microsoft 365 global administrator account

  • Use a strong password and enable MFA

2. Assign complementary roles

  • Billing Administrator
  • Privileged Authentication Administrator
  • Authentication Policy Administrator

3. Document access and recovery procedures

  • Store credentials securely in a password vault

4. Consider a break-glass account

  • A highly secured emergency account with no MFA, monitored for unusual activity.

See our second article in this series to learn more about how network administrators can configure a second Microsoft 365 Global Administrator. Intervention in Microsoft 365, Entra, and and other advanced services can cause catastrophic operational problems so we recommend that you contact us for experienced assistance.

Do I need to buy another 365 license?

No. If your second Microsoft global administrator does not have a Microsoft 365 license, it can still perform MFA and manage the tenant. Licensing only affects access to services like Outlook or Teams—not administrative capabilities.

In our experience, most users lose access to their Microsoft, Apple, and Google accounts via breaches that happen as a consequence of email scams. So, a tenancy owner who operates a solitary Microsoft 365 global administrator user which also handles daily email poses a significant risk.

An unlicensed Microsoft 365 account cannot operate email which helps to protect the account from breach. However, without email, a non-licensed Microsoft 365 global administrator account might not see system-level emails. This is usually not an issue in a small business. In larger businesses, an inexpensive Exchange Online license is assigned to professional network administrators.

Summary

A single Microsoft 365 global administrator is a single point of failure. By adding a second global admin and assigning the right roles, you protect your business from catastrophic lockouts and ensure continuity. See our following article in this series to learn how network administrators configure roles like Billing Administrator and Privileged Authentication Administrator to mirror the principal Microsoft 365 global administrator account.

About ComStat.uk: Internet Service Provider Comstat provides IT support, web hosting, and media services including website design, Microsoft 365 setup, and audio/video production, serving businesses across Denbighshire, North Wales and Wirral from Ruthin, and Lancashire and the Northwest from Bolton.

  • Facebook
Site design by Caistar.com (a Comstat association). Web hosting by ComStat.uk
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
1
Scan the code
WhatsApp
👋Scan the QR code or click open Chat to talk to us on WhatsApp.
Open chat