Global Admin with productivity license
Identifies Global Administrators that also hold productivity licenses (mailbox, Teams, SharePoint).
How to fix it
Use dedicated, license-free admin accounts. Regular work should happen from a separate, non-privileged account.
Required Microsoft Graph permissions
EntraAnalyzer needs the following read-only Graph permissions to evaluate this rule:
Directory.Read.AllRoleManagement.Read.DirectoryUser.Read.All
Further reading
Run this check on your tenant
EntraAnalyzer evaluates this rule automatically on every scan and emails you the results.
Get started — free first scan →