July 30, 2026
How Many Global Admins Should Your Company Actually Have?
Short answer first, since this is the kind of question that deserves one: 2 to 4 Global Administrators. Not one, not a dozen. This range isn't just a rule of thumb we're asserting — it lines up with Microsoft's own CIS benchmark guidance and shows up consistently across independent research from sources like OurCloudNetwork.
The two failure modes
Too few — usually one. A single Global Admin is a single point of failure. If that person leaves the company, loses access to their MFA device, or is simply on vacation when something urgent needs admin access, there's no one else who can act. It also means every administrative task funnels through one person, which doesn't scale even for a small company.
Too many. The opposite mistake is just as common: Global Admin gets handed out generously because it's the path of least resistance — someone needs to reset a password, and rather than figuring out the right scoped role, they get made a Global Admin "for now." Every additional Global Admin is another full-tenant blast radius if that one account is ever compromised. There's rarely a good reason for double-digit Global Admin counts in a small or mid-sized tenant.
Why 2-4 is the right range
Two is the practical minimum for redundancy — one primary, one backup, so a single person being unavailable never blocks urgent work. Four is a reasonable ceiling for most small-to-mid tenants before you should be asking whether some of those admins actually need a more scoped role instead (Exchange Administrator, User Administrator, etc., rather than full Global Admin).
If you're managing a client tenant and you count more than four, that's worth a conversation — not because someone did something wrong, but because it's usually the result of role sprawl over time, not a deliberate decision.
The more urgent version of this question
Counting Global Admins is useful, but there's a sharper, more urgent variant: how many of those Global Admins don't have MFA registered?
A Global Admin account is the highest-value target in the entire tenant — full access to everything, by definition. An admin account without MFA isn't just a gap, it's the gap an attacker is specifically looking for. This is worth checking on its own, separately from the raw admin count, because a tenant with exactly 2 Global Admins and one of them unprotected is in worse shape than a tenant with 4 admins who all have MFA registered.
What to actually do about it
- Pull the current list of Global Administrators for the tenant.
- For each one, confirm they actually need full Global Admin — or whether a scoped role (Exchange, SharePoint, User Administrator) covers what they actually do.
- Confirm MFA is registered for every remaining Global Admin, with no exceptions.
- If Privileged Identity Management (PIM) is available on the tenant's licensing tier, consider moving from standing Global Admin access to just-in-time elevation instead — reduces the attack surface further, though it's a bigger change than the first three steps.
ScopedIQ checks both the Global Admin count and specifically flags any admin without MFA registered, by name, as part of every scan — because the second check is the one that actually matters most.