Microsoft Azure Global Administrator Security Account Access

This agreement establishes the security responsibilities of individuals granted Microsoft Azure Global Administrator privileges. Global Administrator is the highest level of privilege within Microsoft Entra ID (Azure AD) and provides extensive access to cloud services, security settings, identity management, compliance controls, and administrative functions.

This form must be submitted by the employee requesting access.

Because Global Administrator access represents a significant organizational risk if improperly used, individuals granted these privileges are expected to adhere to the highest standards of cybersecurity, professionalism, and responsibility.

By accepting, the administrator acknowledges responsibility for securing organizational resources and agrees to comply with all requirements contained within this agreement.

 

Administrator Responsibilities

1. Security First Principle

Global Administrators shall perform all administrative activities with security and risk reduction as primary objectives.

Administrators will:

  • Follow the Principle of Least Privilege.
  • Utilize elevated access only when necessary.
  • Protect organizational identities, systems, and cloud resources from unauthorized access.
  • Ensure cloud services are administered according to organizational cybersecurity standards.
  • Consider security impact before making administrative changes.
  • Administrative convenience shall never outweigh security requirements.

 

2. Privileged Access Management

Global Administrators must:

  • Use a dedicated administrative account for privileged activities.
  • Use a separate standard account for daily business operations.
  • Authenticate using a FIDO key for Multi-Factor Authentication (MFA).
  • Activate privileged roles only when required to perform authorized duties.
  • Log out of administrative sessions immediately following completion of administrative tasks.

 

3. Account Protection Requirements

Administrators shall:

  • Use a unique username separate from your standard account that will only be used for this administrative access.
  • Maintain unique passwords compliant with college standards.
  • Never share privileged credentials.
  • Protect authentication devices and security tokens.
  • Immediately report suspected account compromise.
  • Promptly complete required password changes and account remediation activities.
  • Administrative accounts shall never be used by multiple individuals.

 

4. Identity and Access Management Responsibilities

Global Administrators are responsible for maintaining a secure identity platform.

Administrators will:

  • Review privileged role assignments regularly.
  • Remove unnecessary access promptly.
  • Maintain role-based access control (RBAC) principles.
  • Enforce Conditional Access policies.
  • Ensure MFA remains enforced across privileged accounts.
  • Review emergency access accounts periodically.
  • Validate business justification for elevated privileges.
  • Privilege escalation without Director approval is prohibited.

 

5. Azure Tenant and Security Configuration

Administrators are responsible for protecting the Microsoft tenant and associated cloud services.

This includes:

  • Identity security settings.
  • Microsoft Entra configuration.
  • Authentication methods.
  • Conditional Access configurations.
  • Administrative role assignments.
  • Tenant-wide security settings.
  • Integration of cloud services and applications.
  • Changes affecting tenant security must be reviewed, documented, and approved before implementation.

 

6. Change Management

Global Administrators shall:

  • Document significant tenant-wide changes.
  • Obtain appropriate approvals for high-risk modifications.
  • Assess business and security impacts before implementation.
  • Test changes in non-production environments whenever possible.
  • Maintain rollback procedures for critical modifications.
  • Unauthorized production changes are prohibited.

 

7. Monitoring and Audit Responsibilities

Administrators must:

  • Regularly review Azure audit logs.
  • Monitor privileged account activity.
  • Review administrative sign-in activity.
  • Investigate suspicious authentication attempts.
  • Participate in security reviews and audits.
  • Preserve logs required for investigations.
  • All privileged activity is subject to monitoring, review, and audit.
  • Global Administrators acknowledge that no expectation of privacy exists when using administrative accounts.

 

8. Incident Reporting

Administrators shall immediately report:

  • Suspected account compromise.
  • Unauthorized privilege escalation.
  • Security incidents involving Microsoft 365 or Azure.
  • Authentication failures indicating malicious activity.
  • Security control failures.
  • Unauthorized configuration changes.
  • Data exposure or breach events.

 

9. Compliance Responsibilities

Administrators agree to:

  • Follow all organizational security policies.
  • Support regulatory compliance requirements.
  • Participate in mandatory security awareness training.
  • Cooperate with audits and security assessments.
  • Maintain awareness of Microsoft security best practices.
  • Support organizational cybersecurity initiatives.

 

11. Prohibited Activities

The following actions are strictly prohibited:

  • Sharing Global Administrator credentials.
  • Bypassing security controls.
  • Disabling MFA without authorization.
  • Circumventing Conditional Access policies.
  • Granting unauthorized privileged access.
  • Creating unapproved privileged accounts.
  • Performing administrative functions for personal benefit.
  • Disabling logging, auditing, or security monitoring.
  • Using privileged access outside legitimate business purposes.
  • Modifying security controls without approval.

 

12. Responsibilities

Global Administrators are responsible for all actions performed using assigned administrative credentials.

Administrators are responsible for:

  • Administrators shall protect institutional data in accordance with applicable policies, including FERPA, GLBA, and other regulatory requirements. Administrative privileges shall not be used to access user content or institutional data except as required for legitimate business operations.
  • Understanding the impact of administrative actions.
  • Protecting privileged accounts from misuse.
  • Maintaining accurate records of significant changes.
  • Following documented procedures and security standards.
  • Exercising sound judgment when administering cloud resources.
  • To ensure proper identity verification and protect privileged access, all administrative account password resets and MFA modifications must be performed in person. Remote requests, including phone calls, chats, emails, or other communication methods, are strictly prohibited.
  • Services or tasks not specifically covered by this agreement require written approval from the Director prior to any work being performed.

 

Annual Acknowledgment

I acknowledge that Azure Global administrative privileges provide elevated access to organizational content, systems, and security controls. I understand my responsibilities and agree to comply with all requirements contained within this agreement.

By submitting this ticket, I understand that violations of this agreement may result in revocation of administrative access, notification to the reporting supervisor, and other corrective measures deemed appropriate.