The admin account nobody meant to create
Here's a pattern I see often enough that I now look for it first. An owner buys Microsoft 365. Somewhere in that purchase, an account gets created — often a slight variation of their own name, one character different from the address they actually intended to use. Microsoft makes that account the Global Administrator. Then everyone forgets it exists and starts using the other one.
Why it matters more than it sounds
The Global Administrator can do everything. Add and remove users. Buy and cancel licences. Reset any password. Move the domain. Delete the whole thing.
If that role sits on an account you don't think of as yours — one you never log into, whose password lives in a browser you replaced two laptops ago — then you don't fully control your own business systems. You've been borrowing access to them.
Nothing looks wrong day to day. Mail arrives. Files open. It only surfaces the moment you need to make a change, or the day someone else does.
The deletion that locks you out permanently
The instinct, once this is explained, is reasonable: delete the duplicate.
Don't — not first. If that duplicate is the only Global Administrator, deleting it locks you out of your own tenant, and the way back is a Microsoft support case with proof of domain ownership. That's days, not minutes, and your business runs on this.
The order that works:
- Promote the account you actually want to Global Administrator.
- Sign out completely and sign back in as it. Confirm you can reach users, billing and domains. If you can't, the promotion didn't take.
- Create a second admin account you don't use daily — the break-glass account. Microsoft recommends two admins for exactly this reason.
- Only then decide what to do with the duplicate. Often the best answer isn't deletion at all — convert it to an alias so mail sent to it still reaches you.
Promote, verify, then clean up. Never in one sitting.
What else tends to be sitting there
When one thing is unmanaged, others usually are too. The recurring findings:
- Licences that don't do what you assumed. Business Basic includes no installed Word, Excel or Outlook — web and mobile only. Plenty of owners pay for it and can't work out why the desktop apps won't activate. It isn't broken; it was never included.
- Seats for people who left. Nobody cancels a licence when someone resigns. It bills quietly for years.
- Unlicensed accounts nobody can explain. Usually a shared address that would be free as a shared mailbox.
- Business files on a personal account. The most dangerous one — company data on someone's personal OneDrive or Google account, with no company control and, occasionally, an expiry date attached to it.
- Ex-staff and contractors who still have access. The leak in small firms is almost never the firewall. It's a shared folder nobody revoked.
How to check in about ten minutes
Sign in at admin.microsoft.com (or admin.google.com) and look at three things:
- Who holds admin rights. Is it you — the account you actually use?
- Your active licences. How many are you paying for, and do the names on them still work here?
- Every account listed. Do you recognise all of them?
If you can't get into the admin centre at all, that's the finding. It means the keys are on an account that isn't the one you think of as yours.
Not sure who controls your tenant? The Systems & Operations Audit maps accounts, admin rights, licensing and access — and hands you a plain-English document showing exactly where things stand. Or book a free 15 minutes and we'll look at the admin centre together.
Book a free 15-minute call