Updated September 29, 2026
Yes. Anyone who can reset an engineer's password can open everything that engineer can, so the rules treat them, and the computer they work from, as part of what you're protecting.
Picture it. Your engineering files have a tidy list of eight approved people. Your office manager is also an administrator in Microsoft 365, "just in case," and can add herself to that list in ten seconds from the laptop she reads email on. She has never opened a drawing. She's still in scope.
"Scope" is the set of people, computers, and services an assessor inspects under CMMC, the Defense Department's cybersecurity certification for contractors. The files being protected are CUI (controlled unclassified information: drawings, specs, and technical data the government marks as sensitive). Anything that can sign people in to CUI systems, change who has access, or reset passwords and security codes counts as a Security Protection Asset under the rule (32 CFR 170.19). It gets assessed on the requirements tied to what it does, whether or not it ever touches a file.
Every extra admin makes the inspected area bigger, the assessment longer, and one phished password more expensive. The cheapest fix is fewer admins.
What an assessor wants to see
Four requirements carry most of the weight here (NIST SP 800-171 Rev. 2). Give people only the access they need, admins included (3.1.5). Admins use a normal account for normal work like email (3.1.6). Non-admins can't use admin functions, and every admin action is logged (3.1.7). Every admin sign-in needs multi-factor login, meaning a password plus a code or app approval (3.5.3).
A job-title list that says "IT admin" proves none of that. The actual admin assignments in your systems do.
If you run the tenant
This section is for whoever administers Microsoft 365, in-house or at your MSP (managed service provider).
In the Microsoft Entra admin center (Entra is Microsoft's account and sign-in system), go to Entra ID → Roles & admins → All roles and sort by Assignments. Microsoft labels the roles that can raise privileges as PRIVILEGED, and recommends fewer than five Global Administrators and fewer than ten privileged role assignments overall (Entra role best practices). A 30-person company with eleven Global Admins is common, and it's a finding.
Then look past Global Admin. Helpdesk Administrator can reset passwords for non-admin users, which includes every engineer. Authentication Administrator can change a non-admin's multi-factor methods. Privileged Authentication Administrator can do that for anyone, Global Admins included (who can reset what). Whoever holds those roles can take over an engineer's account, so they're in scope.
For each name, write down the person, the reason, and the device they administer from. Remove anything you can't justify. Microsoft recommends two cloud-only emergency "break-glass" accounts holding Global Admin; keep those, store the credentials offline, and alert on every sign-in. With Entra ID P2 licenses, make the remaining admins eligible through Privileged Identity Management, so admin rights switch on only while someone is using them.
Google Workspace has the same problem under different names: Super Admin, and any custom admin role that can manage users. The same logic reaches any service account that deploys into CUI systems, such as a software team's build pipeline.
Where an old MSP's access hides
After you change IT providers, the old one's reach rarely lives in one place. It sits in the partner relationship in your tenant (Microsoft calls it granular delegated admin privileges, or GDAP), in the remote-management agent still installed on every laptop, in recovery phone numbers and emails on admin accounts, and in passwords stored on app registrations. Disabling the old help-desk mailbox leaves all four in place. Ask your new MSP for a screenshot of each one, cleared. Changing tools or MSPs
Trust you didn't choose
Entra can be set to accept another company's multi-factor check or device approval as if it were your own. When that's on, their security becomes part of your sign-in decision. By default Entra trusts neither; turning it on is a choice in cross-tenant access settings, and it needs Entra ID P1 (cross-tenant access). If someone turned it on for a partner, write down why.
Whether one shared Microsoft 365 account can work at all is a separate question, covered in shared tenants. So is an app that asks for tenant-wide permissions. This one is only about who holds the keys.
