
Privileged Access: Who Can Make Irreversible Changes to Your Network?
asitplan Security Team
Author
Rob Lloyd
Technical Reviewer
06 August 2026
Last Reviewed
Headteachers, IT managers, and DPOs
Target Audience
The Context
Every school network has 'Global Admin' or 'Super Administrator' accounts. These accounts have the power to delete every user, wipe every device, and turn off every security control. Historically, schools have handed these credentials out freely—to internal IT staff, external vendors, and sometimes even non-technical senior leaders.
Who This Guide is For
Headteachers, IT managers, and Data Protection Officers (DPOs).
Why This Matters
Compromising a standard user account is a problem; compromising a Global Admin account is an existential crisis. The vast majority of catastrophic school cyber incidents involve an attacker gaining access to an over-privileged account. If everyone has the keys to the kingdom, you cannot secure the kingdom.
What Good Looks Like
A 'Least Privilege' model. Staff and IT personnel only have the administrative rights necessary to do their specific jobs. Global Admin accounts are exceptionally rare, heavily monitored, protected by strong Multi-Factor Authentication (MFA), and never used for day-to-day tasks like reading email.
Approach and Methodology
- Audit Current Access: Run a report in your directory (e.g., Microsoft Entra ID or Google Workspace) to identify every single account with Global Admin or equivalent rights.
- Purge the Excess: Remove admin rights from anyone who does not absolutely need them. Third-party vendors should not have permanent Global Admin access; provide temporary, scoped access instead.
- Separate Accounts: IT staff must have two accounts: a standard account for reading email and browsing the web, and a separate administrative account used only when making system changes.
- Mandatory MFA: It is non-negotiable that every administrative account is protected by phishing-resistant MFA (such as a hardware security key or an authenticator app, not SMS).
- Implement Just-in-Time Access: For advanced setups (like Azure PIM), require IT staff to formally "request" elevation to admin status for a limited time period (e.g., 2 hours), rather than holding the rights permanently.
- Monitor the Logs: Configure alerts so that leadership is notified whenever a new Global Admin account is created or when a highly destructive action is taken.
Evidence to Retain
- A monthly generated report listing all active administrative accounts.
- Documented approval trails for granting third-party vendors temporary administrative access.
- System logs showing active MFA enforcement for all privileged accounts.
Questions Leadership Should Ask
- "Exactly how many people have the technical ability to delete our entire cloud backup repository today?"
- "Does our IT provider use unique, named administrative accounts for our school, or do they use a single shared login?"
Common Pitfalls
- The "Break Glass" Account Forgotten: Creating an emergency admin account, writing the password on a post-it note in the safe, and forgetting about it until a penetration tester finds it.
- Convenience Over Security: IT staff using their Global Admin account for everything because logging in and out of different accounts is "annoying."
- Vendor Blind Trust: Assuming a third-party educational software vendor needs permanent domain admin rights just to sync user data.
How asitplan Can Help
asitplan allows you to document your access control policies and integrate them as compliance checks. By tracking who holds privileged access as part of your overall security posture, you can easily demonstrate to auditors that you are proactively managing insider and external threats.