Should I revoke HR’s everyday admin access without final confirmation?

0
2
Asked By MellowPine47 On

I recently became the system administrator at a small company after working there as an operations administrator. I'm implementing a policy that removes privileged access from employees' normal Microsoft 365 accounts and provides separate admin-only accounts for people who need to reset passwords, assign licenses, or manage SharePoint. The owner has approved this approach and is already using a separate unlicensed admin account.

HR is the only person left to transition. I emailed the policy, sent instructions, and provided her new admin-account credentials, which require a password change at first sign-in. She said she would complete it last week, but hasn't confirmed that she did so, and my follow-up hasn't received a response.

Since she has the new account details, can I revoke the admin privileges from her everyday HR account now, or should I get explicit approval from the owner or another decision-maker first? I want to reduce the security risk without creating unnecessary conflict, especially since she has a close relationship with the owner.

4 Answers

Answered By QuietLemon22 On

Treat this as an implementation and communication issue, not a confrontation. Send a concise reminder explaining the deadline, what access will be removed, what the new account is for, and who to contact if it doesn’t work. Offer to schedule a short session to help her sign in and change the password. Copy the appropriate manager or owner so the project status is visible, without framing it as a personal complaint.

NorthVale6 -

A firm deadline can help, but make it an approved deadline rather than one you invent yourself. If it passes, escalate with the documented reminders instead of silently changing the account.

Answered By AmberKite31 On

Make sure you’re following the organization’s actual policy and enforcement process. A system administrator may be responsible for carrying out the change, but that doesn’t necessarily mean they have authority to decide when someone loses access. Document the policy approval, notices, attempted contact, and any business impact. If leadership chooses to delay the change, keep that decision in writing so the risk is understood.

Answered By CrispHarbor8 On

Don’t revoke the access unilaterally. Get the owner or your manager to approve the change in writing first, including the expected impact if HR hasn’t completed the transition. Ideally, the decision-maker should send the final notice or join a quick call so HR clearly understands what will change and when. That protects the company and gives you an audit trail if there’s a complaint or an operational problem.

MellowPine47 -

That makes sense. The policy itself has already been reviewed and approved, but I’ll get explicit confirmation about the timing and make sure the owner is involved in the final notice.

Answered By SilverMaple9 On

The separate-account approach is generally a reasonable improvement for privileged Microsoft 365 access, but confirm the exact design with whoever owns security for the company. Depending on the environment, role activation or just-in-time access may also be available. Regardless of the technical method, don’t leave HR unable to perform essential work just because the transition wasn’t confirmed; coordinate the cutover and have a recovery plan ready.

MellowPine47 -

The company is small and HR and the owner are the only people who regularly manage licenses and accounts, so I’m trying to balance a safer setup with keeping their day-to-day work practical.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.