April 12, 2024, 11:52 a.m. | /u/Equal-Swordfish3662

cybersecurity www.reddit.com

I have a question about permissions for admin users in a fairly large organization with over 10,000 users. Currently, we operate with one admin account per person, granting high privileges across various systems like Azure, Intune, and on-premises infrastructure (we are not global admins).

I understand the principle that privileged accounts should refrain from directly accessing regular user workstations to minimize security risks. Thus, my plan is to create separate accounts for different tasks. One account would handle domain-level activities …

account accounts active directory admin azure cybersecurity directory global high infrastructure intune large organization permissions privileged privileged accounts privileges question systems understand

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Security Operations Manager-West Coast

@ The Walt Disney Company | USA - CA - 2500 Broadway Street

Vulnerability Analyst - Remote (WFH)

@ Cognitive Medical Systems | Phoenix, AZ, US | Oak Ridge, TN, US | Austin, TX, US | Oregon, US | Austin, TX, US

Senior Mainframe Security Administrator

@ Danske Bank | Copenhagen V, Denmark