Home/Questions/Access control and privilege/Approval for admin access
Access control and privilege

Does the use and distribution of administrator and privileged access require senior management approval?

This is a governance question with a technical answer available. Approval enforced by the platform is evidence; approval described in a document is a claim.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether administrative privilege is granted through a controlled decision rather than by whoever happens to hold the ability to grant it. Some forms specify senior management, which in practice means an approver outside the requesting team.

Why it is underwritten

Uncontrolled privilege grants are how administrator counts grow, and how a compromised administrator quietly creates a second foothold. Requiring approval also creates a record, which matters in a claims review that has to establish whether an account was legitimately privileged at the time of the loss.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Privileged Identity Management can enforce approval for activation, which converts this from a process assertion into a configuration you can show.

PlatformWhere the setting livesWhat has to be true
Entra IDPIM role settings, approval requirement for activationApproval required for the highest roles, with approvers named and outside the requesting team
Entra IDPIM activation history with justification textActivations carry a justification and an approval record, producing an audit trail per elevation
Entra IDEntitlement management access packages for privileged groupsWhere used, packages carry approval workflows and expiry, which extends approval beyond directory roles
AzureOwner and User Access Administrator assignment processResource-plane privilege follows an equivalent approval path, since it is granted separately from directory roles
Ticketing systemChange or access request recordsApproval evidence for grants made outside the platform. Insurance Posture does not read ticketing systems, so this is attested
Enforced beats documented

If the platform requires approval, the control cannot be skipped under pressure. If a document requires it, the control is exactly as strong as the busiest week of the year.

What a defensible yes requires

  • Approval is required by configuration for the roles that matter most, not only described in policy.
  • Approvers sit outside the requesting team, so the control is a separation of duty rather than a formality.
  • Every grant, whether by activation or by direct assignment, leaves a record tying it to an approval.
  • Resource-plane privilege in Azure follows the same path as directory roles.
  • Emergency grants have a defined break-glass route with after-the-fact review rather than an undocumented exception.

How this answer goes wrong

The usual gap is scope. Approval is enforced for Global Administrator and absent for the workload administrator roles that can achieve much the same outcome. The second gap is the direct assignment path: approval governs activation while nothing prevents an existing administrator from making a permanent assignment that never passes through the workflow.

Frequently asked

Does senior management have to approve personally?

Rarely required literally. What carriers want is an approver with authority who is not the requester. Naming a small approver group in the platform satisfies the intent and is far more auditable.

What about emergency access?

Define a break-glass route with post-hoc review inside a fixed window. An emergency path that exists and is reviewed is stronger than an approval requirement people bypass quietly.

Can we answer yes if approval is only in our ticketing system?

Yes, provided the records exist and cover every grant. It is a weaker evidence position than platform enforcement, so state which one you have.

Does this apply to service principals?

It should. Granting a privileged directory role or a high-privilege application permission to a service principal is a privilege grant, and it is the one that most often bypasses governance entirely.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture