The Microsoft Entra role with complete control over the directory. On its own it gives no rights over Azure resources; the holder must elevate access to manage all subscriptions first.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104SC-500AB-900SC-200SC-401MD-102
Each book explains Global Administrator in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Deployment modes
The two ways ARM can deploy: Incremental, the default, creates or updates what the template lists and ignores everything else; Complete also removes resource group contents absent from the template.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Elevate access
A toggle under Entra Properties; when the signed-in Global Administrator switches it on, that one admin becomes User Access Administrator at root scope (/).
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
Related terms
- Custom security attributes
An organisation's own key-value data for users and enterprise applications, kept in attribute sets and used to filter directory objects or to power Azure ABAC. Only the Attribute Definition and Attribute Assignment roles can work with them by default; a Global Administrator cannot.
- Customer Lockbox
Ensures Microsoft support engineers can't open customer content until the organisation explicitly says yes. The yes comes from a Global Administrator or someone holding the access approver role, and any request still pending after 12 hours expires.
- DAP
The older CSP model for partner access, which handed partners permanent, wide-ranging administrator rights in customer tenants, Global Administrator included. It is being phased out and replaced by granular delegated admin privileges (GDAP).
- Emergency access account
A cloud-only, non-personal account that holds Global Administrator permanently and sits outside Conditional Access, reserved for situations where regular admins can't get in. Microsoft advises having two or more.
- Global Reader
An admin role that can see everything a Global Administrator can across the Microsoft 365 admin centers but cannot change anything. Subscriptions purchased through a partner do not offer it.
- Partner-built agent
Agent for Security Copilot obtained from a partner in the Security Store. Should it need permissions on Microsoft product data, setup by an owner or contributor can only finish after a Global Administrator approves them.
- Tenant Creator
A Microsoft Entra built-in role allowed to create new tenants even if non-admin users are blocked from doing so. Whoever creates the tenant becomes its Global Administrator.
- Unmanaged tenant
Created when somebody signs up with a work email address and nobody becomes Global Administrator. To manage it or move its domain away, an admin takeover is required.