Access control and privilege

How many domain and service accounts are in the Domain Admin Group?

This is a counting question, and the count is a proxy for how many independent ways there are to end your organisation in an afternoon.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier wants a number, and it wants the number to include service accounts. In an on-premises estate that is membership of Domain Admins, Enterprise Admins, and any group nested inside them. In a cloud-first estate the equivalent is Global Administrator and the small set of roles that can grant themselves anything else.

Nested groups are where the honest answer usually differs from the first answer. A service group added years ago for a backup product can put a dozen accounts inside Domain Admins without appearing in the membership list at a glance.

Why it is underwritten

Every privileged account is an independent path to total compromise, and service accounts are the worst of them: their passwords rarely change, they often cannot use a second factor, and their credentials sit in scripts and configuration files. Underwriters use the count as a fast, comparable signal because it correlates with sprawl and it cannot be dressed up in policy language.

Where the answer lives in Microsoft 365, Entra ID, and Azure

The cloud half of this is directly countable. The on-premises half is not visible from the tenant and needs evidence from Active Directory itself.

PlatformWhere the setting livesWhat has to be true
Entra IDGlobal Administrator role membership, including eligible assignmentsA small number, commonly under five for mid-sized estates, with each holder justified
Entra IDPrivileged Role Administrator, Application Administrator, and Cloud Application AdministratorThese roles can grant privilege or consent to applications, so they belong in the count even though the form did not name them
Entra IDService principals holding privileged directory rolesEnumerated separately, with credential ownership and expiry known
AzureSubscription Owner assignments per subscriptionA tight count, typically two or three per subscription, rather than a group that accumulated over time
Active DirectoryDomain Admins, Enterprise Admins, Schema Admins, and nested group membershipA recursive count including nested groups and service accounts. Insurance Posture does not read Active Directory, so this is attested
Count recursively or do not count at all

A flat membership listing understates almost every real estate. If your number came from looking at a group in a management console rather than from a recursive enumeration, treat it as a draft.

What a defensible yes requires

  • The count is recursive, including nested groups, and separates humans from service accounts.
  • Every privileged holder has a named business justification and a review date.
  • Administrators use separate accounts for privileged work rather than elevating their daily account.
  • The cloud and on-premises counts are both stated rather than one standing for both.
  • Service accounts with privilege have owners, rotation, and a plan to reduce their permissions.

How this answer goes wrong

Two failure modes dominate. The first is the stale number carried forward from last year's application, when the count has grown through a migration and two acquisitions. The second is the deliberate-sounding but incomplete answer: counting the four people who do administration daily and omitting the six accounts belonging to people who changed roles and kept access.

Frequently asked

We are cloud-only with no Active Directory. What do we answer?

Answer with the Global Administrator count and say the estate is cloud-only. That is a complete answer to the question the carrier means, and it removes an entire category of exposure from your submission if you make it clear.

Should service accounts be included in the number?

Yes, and separated. A count of four humans and eleven service accounts tells a very different story from fifteen, and the honest breakdown reads better than the aggregate.

What number is good?

There is no threshold that guarantees a credit, but the direction is unambiguous: fewer, justified, and reviewed. Most underwriters react to a count that is clearly maintained rather than to a specific figure.

Do eligible assignments count?

Yes. An eligible assignment is a standing entitlement even though it is not currently active, and it should appear in the count with that distinction noted.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture