Access Control

Limit and Review Administrator Access

Give people and applications only the administrative permissions they need, with a recoverable way to remove unnecessary access.

Content review: 2026-09-22 · Estimated effort: Medium

Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.

Before you start

Before starting: name an access owner and protect a tested emergency administrator route. Record current assignments and an approved recovery process. Do not remove the last usable administrator or change a service identity without its owner's involvement.

Put it into practice

  1. List privileged users, groups, application identities, and external IT-provider access across email, cloud services, devices, and backups. Include inherited group membership and delegated access. Record purpose, approver, owner, and last review in a restricted spreadsheet; never include passwords or recovery codes.
  2. Match each task to the narrowest supported role and scope. In Microsoft Entra, use Roles & admins > All roles and the linked role guidance. Check separate service roles and local device administrators too; an Entra role review is not a complete inventory of privileges.
  3. Use separate named administrator identities for privileged work and ordinary accounts for daily email and browsing. Require MFA, preferably phishing-resistant where supported. Avoid shared routine admin accounts; protect and monitor emergency accounts rather than using them for daily work.
  4. Pilot reduced access with one owner and test their necessary tasks before expanding. Review application consent and delegated permissions as well as human roles; remove unused grants only after checking dependencies. Document narrowly scoped exceptions instead of retaining broad access for convenience.
  5. Schedule owner reviews and revoke access promptly when responsibilities or employment change. Built-in role lists and a manual review are a low-cost start. Just-in-time privileges and automated access reviews can help, but licensing varies; do not assume Entra PIM is included in a basic subscription.
  6. Verify: using a safe test account, confirm an approved task succeeds and an out-of-scope task is denied. Check group-derived privileges, application access, and audit records after changes. Record approvals and exceptions. If a required task breaks, restore only the documented necessary permission with approval, then refine the role.

Make a start

Tools and templates

Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.

Start without another software subscription

Use existing role listings and the Excel access review worksheet to approve removals and schedule repeat reviews without PIM.

Where this stops: A manual review does not provide just-in-time access, automated expiry or PIM approval workflows. Those capabilities require a suitable licensed system.

See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.

Entra Roles & admins and assignment export

Start with built-in role listing; PIM requires eligible premium licensing

Open Roles & admins > All roles and Download assignments. Review the exported assignments against responsibilities and approved scope.

Limits: Include local administrators, service roles, apps and external providers separately. PIM requires Entra ID P2 or Governance licensing; a CSV review provides no just-in-time enforcement.

Your information: The export contains identity and privilege information. Restrict the downloaded file and remove unneeded copies.

Official instructions: Entra Roles & admins and assignment export ↗

Download a working template

Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.

Fictional worked example

Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.

An employee who moved to a non-IT role still appears in an administrator review.

Use the Administrator access review template.

What to enter before testing

Account or group reference
EXAMPLE-USER-01
Role and scope
Record actual role and scope from the authorized export
Business justification
Role change: current need not confirmed
Decision
Pending owner approval

How to verify

Check direct and inherited assignments and obtain an authorized decision. After an approved removal, check effective access again and confirm ordinary work still succeeds. Protect the remaining authorized administrator and recovery routes.

If the result is unexpected

If privileges remain, investigate group membership and other assignments rather than declaring success. If required work breaks, have the approver identify the minimum justified access; do not automatically restore broad administrator privileges.

Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.

Sources and review approach

Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.

  • NIST CSF 2.0: PR.AA-05: least privilege and reviewed permissions
How this guidance is prepared