I'm removing the Global Administrator role from my everyday account and creating a separate account for administrative use. I'd like to protect it as strongly as possible, so I'm considering a Conditional Access policy that requires the account to sign in only from a compliant hybrid-joined device. The main inconvenience is that my browser is signed in with my normal account, so I had to create a separate Edge profile for the administrator account. What approach do you use for dedicated Global Administrator accounts? Is strong MFA or a passkey enough, or should I also require a compliant device, a privileged access workstation, and just-in-time role activation? I already maintain two separate break-glass accounts for emergencies.
4 Answers
Treat Global Administrator as an emergency-level account rather than something used for routine work. Use a separate admin identity from a compliant, MFA-protected device, and keep offline emergency credentials and multiple security keys secured in separate locations. The exact setup depends on your organization’s risk tolerance, but daily administration should use lower-privilege roles whenever possible.
Require both phishing-resistant MFA and a device restriction. A device filter based on the device’s join state can be more dependable than relying only on Intune compliance, since compliance signals can occasionally be delayed or incorrect. Keep your break-glass accounts outside these policies so they remain usable during an outage.
Use a dedicated privileged access workstation and require phishing-resistant MFA, such as a FIDO2 security key or passkey. A separate browser profile is a reasonable way to keep the privileged and everyday sessions isolated.
Put the Global Administrator role behind Privileged Identity Management. The account should normally have no active role, and activation should require MFA, approval or justification where appropriate, and a short expiration time. That also gives you a clear audit trail for every elevation.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures