How many domain and service accounts are in the Domain Admin Group?
This is a counting question, and the count is a proxy for how many independent ways there are to end your organisation in an afternoon.
What the carrier is actually asking
The carrier wants a number, and it wants the number to include service accounts. In an on-premises estate that is membership of Domain Admins, Enterprise Admins, and any group nested inside them. In a cloud-first estate the equivalent is Global Administrator and the small set of roles that can grant themselves anything else.
Nested groups are where the honest answer usually differs from the first answer. A service group added years ago for a backup product can put a dozen accounts inside Domain Admins without appearing in the membership list at a glance.
Why it is underwritten
Every privileged account is an independent path to total compromise, and service accounts are the worst of them: their passwords rarely change, they often cannot use a second factor, and their credentials sit in scripts and configuration files. Underwriters use the count as a fast, comparable signal because it correlates with sprawl and it cannot be dressed up in policy language.
Where the answer lives in Microsoft 365, Entra ID, and Azure
The cloud half of this is directly countable. The on-premises half is not visible from the tenant and needs evidence from Active Directory itself.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Entra ID | Global Administrator role membership, including eligible assignments | A small number, commonly under five for mid-sized estates, with each holder justified |
| Entra ID | Privileged Role Administrator, Application Administrator, and Cloud Application Administrator | These roles can grant privilege or consent to applications, so they belong in the count even though the form did not name them |
| Entra ID | Service principals holding privileged directory roles | Enumerated separately, with credential ownership and expiry known |
| Azure | Subscription Owner assignments per subscription | A tight count, typically two or three per subscription, rather than a group that accumulated over time |
| Active Directory | Domain Admins, Enterprise Admins, Schema Admins, and nested group membership | A recursive count including nested groups and service accounts. Insurance Posture does not read Active Directory, so this is attested |
A flat membership listing understates almost every real estate. If your number came from looking at a group in a management console rather than from a recursive enumeration, treat it as a draft.
What a defensible yes requires
- The count is recursive, including nested groups, and separates humans from service accounts.
- Every privileged holder has a named business justification and a review date.
- Administrators use separate accounts for privileged work rather than elevating their daily account.
- The cloud and on-premises counts are both stated rather than one standing for both.
- Service accounts with privilege have owners, rotation, and a plan to reduce their permissions.
How this answer goes wrong
Two failure modes dominate. The first is the stale number carried forward from last year's application, when the count has grown through a migration and two acquisitions. The second is the deliberate-sounding but incomplete answer: counting the four people who do administration daily and omitting the six accounts belonging to people who changed roles and kept access.
Frequently asked
We are cloud-only with no Active Directory. What do we answer?
Answer with the Global Administrator count and say the estate is cloud-only. That is a complete answer to the question the carrier means, and it removes an entire category of exposure from your submission if you make it clear.
Should service accounts be included in the number?
Yes, and separated. A count of four humans and eleven service accounts tells a very different story from fifteen, and the honest breakdown reads better than the aggregate.
What number is good?
There is no threshold that guarantees a credit, but the direction is unambiguous: fewer, justified, and reviewed. Most underwriters react to a count that is clearly maintained rather than to a specific figure.
Do eligible assignments count?
Yes. An eligible assignment is a standing entitlement even though it is not currently active, and it should appear in the count with that distinction noted.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture