Azure admin access should expire. Standing administrative access gives an adversary a durable target; temporary, reviewed, conditional access makes any foothold harder to extend.
Start by separating active access from activatable access. A user with no active admin role may still be eligible to activate one through Privileged Identity Management. Done well — deliberate, logged, time-bound, protected — that is exactly the point. Done carelessly, eligibility becomes privilege no dashboard shows. A contractor whose project ended months ago, still eligible to activate a subscription role. The privilege review should ask who can activate power, not only who currently holds it.
Review Entra roles and Azure RBAC together. Global Administrator, Privileged Role Administrator, Owner, User Access Administrator, and subscription-level roles interact in ways that create more power than any single list suggests.
Scope matters as much as role. An assignment at a management group reaches far more than one scoped to a resource group. Narrow task, narrow scope.
Conditional Access should protect both activation and use: strong authentication, trusted devices where appropriate, sign-in risk checks, and clear exceptions. A privileged path that can be activated from an unmanaged device after a weak sign-in is not controlled.
Permanent privilege turns yesterday's exception into tomorrow's compromise path. Access reviews keep eligibility from fossilizing into permanent background risk. Review privileged users, power-conveying groups, guest accounts, and emergency exceptions, and remove whatever no longer has a current business reason.
Break-glass accounts need their own discipline: few, monitored, tested, excluded only where necessary, and governed by procedures that assume their use is exceptional.
And do not ignore non-human privilege. Service principals, managed identities, automation accounts, and CI/CD systems hold powerful roles too. Their assignments need owners, scopes, expiration expectations, and monitoring, like anyone else's.
What to check now: active admins, PIM eligibility and activation settings, approvers, role scopes, access-review cadence, stale groups, guest users, break-glass monitoring, and service principal assignments.
The goal is not to make administration painful. It is to make powerful access explicit when needed, visible while active, and gone when the reason for it ends.