01745 616 524 servers@comstat.uk
  • Facebook
  • Facebook
Comstat | Ruthin, North Wales | 01745 616 524
  • Home
  • Web Hosting
  • Web Design
  • How to
    • Index of articles
    • Articles/Help
    • Support
  • Contact
Select Page

Microsoft 365 Global Administrator: Why You Need a Second Admin and How to Assign Roles

by Steve Galloway | Nov 10, 2025

Introduction

The Microsoft 365 Global Administrator role is the most powerful role in your tenant. It grants full control over users, groups, and settings. However, many small businesses assume that one global admin is enough—and that this role automatically includes every privilege. In reality, some critical capabilities, such as billing and advanced authentication management, require additional roles. This article explains what a global administrator does, why you need a second Microsoft 365 global administrator, and how to organize roles for maximum security and continuity.

Click open the headers below to learn more about how to protect your IT assets by establishing a second Microsoft 365 Global Administrator to protect your Microsoft 365 tenancy in the event of force majeure. Support options are available for professional assistance.

What Is a Microsoft 365 Global Administrator?

A global administrator in Microsoft 365 (also known as an Entra ID global admin) can manage all aspects of your tenant, including user accounts, licenses, and security settings. This role is essential for tasks such as:

  • Adding or deleting users
  • Resetting passwords
  • Assigning licenses
  •  Configuring security policies

However, global admin privileges do not automatically include billing or advanced security functions. For example, managing invoices for your tenancy, buying/cancelling licenses, or overriding multifactor authentication (MFA) blocks requires additional separate roles.

Why Is a Seond Micrsoft 365 Global Administrator Is Essential

Microsoft recommends having at least two global administrators. This ensures:

  • Business continuity during emergencies
  • Shared responsibility for critical changes
  • Reduced risk of lockouts caused by lost credentials or MFA issues

Establishing a second Microsoft 365 Global Administrator in your 365 tenancy protects against you against a situation arising that locks you out of server-level administration.

Roles That Complement a Microsoft 365 Global Administrator

To fully mirror the capabilities of your principal Microsoft 365 global administrator, assign these additional roles to the second admin:

  • Billing Administrator – Manages invoices, payment methods, and subscriptions
  • Privileged Authentication Administrator – Overrides MFA and security blocks
  • Authentication Policy Administrator – Configures authentication methods and policies
  • Service Support Administrator – Opens support tickets with Microsoft

These roles can be assigned in the Microsoft 365 Admin Center or Azure AD (Entra) under Roles and administrators.

Does Licensing Affect MFA for Microsoft 365 Global Administrators?

No. If a second Microsoft 365 global administrator account does not have a Microsoft 365 license assigned to it, it can still perform MFA authentication. MFA enforcement is identity-based, not license-based. The only limitation is that an unlicensed admin cannot use services like Outlook or Teams. For email alerts and notifications, consider assigning at least an Exchange Online license.

How to Organize Your Admin Accounts
  1. Create a second global admin account
  2. Assign MFA to both global admins
  3. Add complementary roles (Billing, Privileged Authentication, etc.)
  4. Document your admin strategy for continuity

About ComStat.uk: Internet Service Provider Comstat provides IT support, web hosting, and media services including website design, Microsoft 365 setup, and audio/video production, serving businesses across Denbighshire, North Wales and Wirral from Ruthin, and Lancashire and the Northwest from Bolton.

Microsoft 365 Global Administrator: Why Business Continuity needs 2 global admins

by Steve Galloway | Nov 10, 2025

Introduction

For many small businesses, Microsoft 365 is the backbone of daily operations—email, files, collaboration, and security all depend on it. At the heart of this system is the Microsoft 365 Global Administrator, the most powerful role in your tenant. But what happens if the person holding that role leaves suddenly or becomes unavailable? Without planning, this scenario can lead to a catastrophic lockout, halting your business operations. This article explains the risk and how to prevent it.

Click open the headers below to learn more about how to protect your IT assets by establishing a second Microsoft 365 Global Administrator to protect your Microsoft 365 tenancy in the event of force majeure. Support options are available for professional assistance.

The Risk of a Single Global Administrator

When you set up Microsoft 365, the first account created becomes the principal global administrator. This account controls everything: user management, licenses, security settings, and more. If that person leaves the company, passes away, or loses access because their account has been hijacked, your organization could face:

  • Inability to renew licenses or update billing details
  • Locked-out users due to MFA or security blocks
  • No way to add or remove accounts or assign roles

This is not just inconvenient—it can catastrophically disrupt your organization’s IT.

Why a Second Global Admin Is Crucial

Microsoft recommends having at least two global administrators. This ensures:

  • Business continuity during emergencies
  • Shared responsibility for critical changes
  • Reduced risk of lockouts caused by lost credentials or MFA issues

Establishing a second Microsoft 365 Global Administrator in your 365 tenancy protects against you against a situation arising that locks you out of server-level administration.

Best Practices for Setting Up a Second Global Administrator

1. Create a second Microsoft 365 global administrator account

  • Use a strong password and enable MFA

2. Assign complementary roles

  • Billing Administrator
  • Privileged Authentication Administrator
  • Authentication Policy Administrator

3. Document access and recovery procedures

  • Store credentials securely in a password vault

4. Consider a break-glass account

  • A highly secured emergency account with no MFA, monitored for unusual activity.

See our second article in this series to learn more about how network administrators can configure a second Microsoft 365 Global Administrator. Intervention in Microsoft 365, Entra, and and other advanced services can cause catastrophic operational problems so we recommend that you contact us for experienced assistance.

Do I need to buy another 365 license?

No. If your second Microsoft global administrator does not have a Microsoft 365 license, it can still perform MFA and manage the tenant. Licensing only affects access to services like Outlook or Teams—not administrative capabilities.

In our experience, most users lose access to their Microsoft, Apple, and Google accounts via breaches that happen as a consequence of email scams. So, a tenancy owner who operates a solitary Microsoft 365 global administrator user which also handles daily email poses a significant risk.

An unlicensed Microsoft 365 account cannot operate email which helps to protect the account from breach. However, without email, a non-licensed Microsoft 365 global administrator account might not see system-level emails. This is usually not an issue in a small business. In larger businesses, an inexpensive Exchange Online license is assigned to professional network administrators.

Summary

A single Microsoft 365 global administrator is a single point of failure. By adding a second global admin and assigning the right roles, you protect your business from catastrophic lockouts and ensure continuity. See our following article in this series to learn how network administrators configure roles like Billing Administrator and Privileged Authentication Administrator to mirror the principal Microsoft 365 global administrator account.

About ComStat.uk: Internet Service Provider Comstat provides IT support, web hosting, and media services including website design, Microsoft 365 setup, and audio/video production, serving businesses across Denbighshire, North Wales and Wirral from Ruthin, and Lancashire and the Northwest from Bolton.

How to Set Up a New Windows PC to Sign In Directly with a Microsoft 365 Work Account

by Steve Galloway | Nov 2, 2025

Introduction: Why Use a Microsoft 365 Work Account for Windows Sign-In?

When setting up a new computer for business use, the workstation is typically configured with a Microsoft (personal) account. This means signing in to Windows as a personal user, and then finding one’s way to business email and files in Micrsoft 365’s business profile.

Confusing? …we know. Instead, configure a new computer to sign in directly to a Microsoft 365 account with a Microsoft 365 Work Account.

Businesses configure Windows workstations to sign in directly to a Microsoft 365 work account. This streamlines Windows and offers significant benefits for user and business alike. It ensures seamless access to Microsoft 365 apps, centralized security policies via Microsoft Entra ID, and simplified device management. This approach is ideal for organizations using Microsoft 365 Business or Enterprise plans. Also, this approach offers Enterprise security for high net worth users and for those who are focused on privacy protection.

This way, a work computer does not need a Microsoft personal account operating in the background. This has been a problematic inconvenience in the past. 

If your computer is already set up using a personal Microsoft account, you can follow the steps in this article to add a Microsoft 365 work account:

How to Transition Users to Microsoft 365 Sign-In and Entra ID

Click open the headers below to learn more about configuring workstations with Microsoft 365 work accounts. Support options are available for professional assistance.

Step 1: Choose the Right Setup Path

When setting up a new Windows PC, you’ll encounter options during the Out-of-Box Experience (OOBE). To link the device to your Microsoft 365 environment, select “Set up for work or school” instead of a personal account. This ensures the device joins your organization’s Microsoft Entra ID (formerly Azure AD).

This option is sometimes under “Domain join instead” or “Join Azure AD”, depending on the version.

Key Options During Setup

  • Sign in with your Microsoft 365 credentials: Enter your work email and password associated with your Microsoft 365 subscription.
  • Device Join Type:
    • Microsoft Entra ID Join: Recommended for full integration with Microsoft 365 and centralized management.
    • Hybrid Join: For organizations using on-premises Active Directory alongside Microsoft 365.

 

Step 2: Configure Policies and Security

Once signed in, the device will apply organizational policies automatically if you have Microsoft Intune or similar management tools enabled. This includes:

  1. Using a Personal Microsoft Account Instead of Work Account
    1. This prevents proper device enrollment and policy enforcement.
  2. Skipping Device Management Enrollment
    1. Without Intune or similar, you lose centralized control and compliance features.
  3. Incorrect Licensing
    1. Ensure the user has a Microsoft 365 Business Premium or Enterprise license that supports Device join.
  4. Network Connectivity Issues During Setup
    1. A stable internet connection is essential for authentication and policy application.
Why This Matters for Businesses and High net worth users

Direct sign-in with a Microsoft 365 work account improves security, simplifies IT management, and enhances productivity. It also ensures compliance with organizational standards from day one.

If your computer is already set up using a personal Micrsoft account, you can follow the steps in this article to add a Microsoft 365 work account:

How to Transition Users to Microsoft 365 Sign-In and Entra ID

  • Facebook
Site design by Caistar.com (a Comstat association). Web hosting by ComStat.uk
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
1
Scan the code
WhatsApp
👋Scan the QR code or click open Chat to talk to us on WhatsApp.
Open chat