Hello All,
I’m currently auditing our security posture and would love your insight on industry best practices for laying out core administrative access for a small user base (8 users).
For context, ownership of the company/environment is split between two people (Owner-A and Owner-B), and I am the sole IT Administrator (User-A).
Our Current Layout:
-
Domain:
example.com -
Master Account: One (1) external Gmail account acts as the master recovery and admin login for our M365 tenant and camera systems. Three people currently have the credentials, but only I (User-A) access it frequently for administrative purposes.
-
M365 Environment: Currently federated through GoDaddy.
-
Bitwarden: Owner-A, Owner-B, and I (User-A) all have individual Bitwarden accounts tied to our
example.comdomain, but we are currently relying on the Master Gmail account as the ultimate backup/recovery strategy.
My Proposed Plan: Dedicate a wiped laptop strictly for administrative work to access this Master Gmail and GoDaddy account, locking it down with three YubiKeys (one for me, and one for each of the two owners). I plan to harden this laptop so it is only used for admin tasks, never daily browsing.
My Questions:
-
Architecture: Is relying on an external Gmail account + a dedicated admin laptop a flawed approach for a “Master” identity? How do you typically structure top-level admin access for your SMB clients?
-
GoDaddy Defederation: I want to move our M365 environment from GoDaddy directly to Microsoft without breaking our existing tenant. Do you have experience with this defederation process, and what “gotchas” should I look out for?
-
Break-Glass MFA: For storing emergency credentials, are hardware keys your absolute standard, or do you utilize a different offline TOTP method?
-
Resources: Are there any specific guides you highly recommend for mapping out and securing these core services correctly?
Thank you for all for your help and any guidance you can provide to point me in the right direction.
