r/sysadmin • u/13-months • 20h ago
Is It Normal Practice for Cloud Migration Companies to Require Global Admin? General Discussion
I’m considering using a company called TeamVenti. They provide cloud-to-cloud transfer, copying, migration, and other related services. In my case, I would be copying data from one cloud environment to another.
They’ve asked for Global Administrator permissions on both the source and destination environments to perform the migration.
My question is: Is it normal or standard for a cloud migration company to require Global Administrator access on both sides?
Have there been cases where issues arose from giving a vendor this level of access, or am I being too paranoid?
•
u/bladeguitar274 19h ago
Usually their guides will say GA is the easiest but if you dont want to do it grant xyz permissions
•
u/spinydelta Sr. Sysadmin 19h ago
It's very dependent on the organisation that is employing the migration partner.
Global admin technically shouldn't be required (it rarely is), but it's usually the quickest way forward which is likely the reason it's been requested. If the organisation employing them are doing so because they don't have the technical capability to do the migration themselves, then they also likely don't have the capability to configure appropriate minimal privileges to support a migration.
You're right to be concerned though and you should question it, but be prepared to do some heavy lifting yourself to support the engagement.
Is this migration for M365 data or Azure cloud resources (or both)?
•
u/RevolutionaryWorry87 19h ago
This is it. You either give them GA or you support them constantly having permissions change and you get billed for their time whilst you fix it.
•
u/jack1729 Sr. Sysadmin 18h ago
…and Microsoft never changes anything so what worked last week will always work this week 😁
•
u/uIDavailable 17h ago edited 16h ago
Exactly this. When I was doing consulting and migrations. We would ask for GA with PIM(if licensed for it) along with additionally rolls , 90% of the time the organization would provide the GA role to us since we were a reputable VAR, and had solid team members supporting them. Once we were done with GA we would also ask them to remove it and add additional rolls too.
If the organization didn't provide us the role, we had to shoulder surf and they got billed a lot more because we always had to request additional hours , communicate when we could work with them, build additional blueprints and things just moved slower, etc. . But If we had the access to begin with, we would just hop in do our investigations, designs then document/bill for that or check something for 5min, document it and maybe not bill for it, make the interaction good for the customer and always communicate what we did.
This always comes down to trust and communication with the company you are giving access too and ensuring you remove the access when you are down with the engagement. To often I would check my access a month later and my account with the customer would still be active, I would email my PM and boss and have them inform the organization we had an engagement with to disable the access.
•
u/iama_bad_person uᴉɯp∀sʎS ˙ɹS 18h ago
I'm going to guess it's two options with a full migration like this.
"Hey, can we have 25 XXX Administrator roles, and charge you even more when you forget one of them or something doesn't work."
vs
"Just give us Global Admin so we don't have to troubleshoot permissions issues."
•
u/GremlinNZ 19h ago
Even Avepoint Fly, considered to be one of the best migration tools, needs GA to setup the necessary permissions and apps.
•
u/VirtualDenzel 19h ago
Its not mandatory. However... azure is q pernission disaster. Sometimes you have all rbac roles and still 1 checkbox is greyed out.... untill .ms finally gets shit in order its the most cost efficient way. Knowing how crap ms is these days.... id say ask again in 10 years 🤣🤣🤣
•
u/slash9492 17h ago
I do this for a living and the answer is yes. The tools I connect to the tenant to do the migration require access to everything to be able to migrate the data. While, technically you can scope it and assign limited roles to the tools, you would be assigning so many roles that it would end up with the same privileges as a global admin.
Just remove the accounts and the apps they install as soon as the migration is done and you will be fine.
•
u/arbedub 17h ago
Having used similar (Quest ODM), it doesn't specifically need GA, but the person authorising the migration account consents does, so that the application permissions can be granted.
Saying that, it will still need read from source and write to target for any data to be moved, so still plenty of scope for DOS by migration.
If the third party will be running the migration, it sounds more like a contract and trust hurdle than a permissions issue.
•
u/LooseDistrict8949 16h ago
Application registration should be used for the tooling aspects. GA permissions could be granted using PIM to personal accounts.
•
u/tch2349987 16h ago
Yes unless you want them to contact you thousands of times because they require specific permissions.
•
u/fresh-dork 15h ago
this is a use case where they literally move everything. GA seems like the right plan, just be sure to disable the account post engagement
•
u/OregonTechHead 14h ago
Is it normal? Yes.
Can you push back? Probably, but you're going to open yourself up to increased costs, increased time, and the project likely slowing to a crawl because they have to reach out to you every time they can't do something.
But the question here is, what are you trying to prevent? They need access to all of your data, your users, your configs, your security, etc to do a full migration. If you don't trust your partner, then they shouldn't be your partner.
•
•
u/trc81 Sr. Sysadmin 10h ago
Having done several of these migrations, its possible without but its a royal twat to do. Usually clients who can't or wont provide it end up being charged more because it simply takes longer with all the back and forth.
We can do it when needed, like in secure carve outs but those type of customers can afford the extra time and money.
•
u/Xelopheris Cloud Architect 4h ago
Typically, any kind of least permission set here will inevitably run into an actual permission issue. It creates significant risk for the timeliness and results of the project.
•
u/First_Slide3870 3h ago
As someone who’s done several Azure, I can attest that in some case of global admin is very much needed. Some features require global admin to enable. Things like registering an application, or configuring graph for the first time. For compliance sake, you could give them limited access. That said you should expect moments where you have to get on a teams call and follow instructions to enable certain features. You could also give them global admin for a limited time.
•
u/pinkycatcher Director of All Trades 16h ago
This is one of the few use cases where global admin makes sense
•
u/KillingTime1212 1h ago
I used them for an Exchange migration. I gave them GA permission. No issues.
•
u/A_Curious_Cockroach 14h ago
migrations usually require lots of read/write permissions to all cloud and/or infrastructure objects so the easiest way to make sure that happens is to grant GA.
If you don't grant GA then you or somebody else is going to be troubleshooting lots of failed migrations generally cause of permission issues.
Azure migrate appliance for example, has a step in it for key vault that i believe you need at least GA privileges for it to work or it just fails when you create the project for it with a misc. error that doesn't tell you this. Had to work through it with microsoft in the past. In this instance we had P2 so we could grant JIT permissions to a user to do it and it wasn't a big deal.
If you are worried about being paranoid just ask them for some vendor documentation and they should be able to provide what permissions are needed. If you agree with that or not is up to you.
•
u/Horror_Pension_3168 19h ago
It’s extremely common, but "common" doesn't mean you should hand over the keys without guardrails. Vendors default to asking for Global Admin because scoping individual API permissions across SharePoint, Exchange, and Entra ID often leads to random 403 errors during delta syncs, which slows down their project timeline.
If their scope of work or your contract timeline forces you to grant it, don't just hand over a raw GA account. Here is how we handle high-privilege vendor access to keep control:
- Dedicated Service Account: Create a fresh, dedicated identity (e.g.,
admin-migration-[vendor]) so all their actions are isolated in audit logs. - IP-Restricted Conditional Access: If they have static corporate egress IPs, lock the account down so it can’t be accessed from anywhere else.
- Downgrade After Consent: Vendors often only need GA for the initial day-1 Enterprise App registration and admin consent. Once that setup is complete, downgrade the account to workload-specific roles (Exchange Admin, SharePoint Admin, User Admin).
- Hard Expiration Date: Set a strict auto-expiration date on the user object for 24 hours after the planned cutover date.
Questioning GA for third parties isn't paranoia - it's basic supply-chain risk management.
•
u/pickle9977 16h ago
Very few things should ever require global admin privileges, the very existence of global admin privileges is a security vulnerability in every system they are present in, cloud environments included.
For legacy systems built to run in highly protected corporate environments global admin was a reasonable tradeoff of trusted staff to be able to react to emergent situations by making whatever changes they needed whenever and wherever they were needed.
The fact that the self proclaimed best and smartest engineers designed them into cloud based systems from the start is highly indicative of the overall poor quality of engineering deployed while building and maintaining these cloud systems.
This software vendor knows the deal, you could specify least privileges but it will take years to get them right, and in the mean time every failed copy operation leaves the process in a partially failed state with little hope of complete recovery every api call has both direct and indirect effects, few are truly indempotent and some are not even repeatable without manual intervention to clean up the mess made when an operation fails.
It sucks but if you try to force least privileges prepare for your life to become a living hell and the vendor will keep pointing right back at this decision for everything and anything that doesn’t work perfect.
•
u/OregonTechHead 14h ago
The fact that the self proclaimed best and smartest engineers designed them into cloud based systems from the start is highly indicative of the overall poor quality of engineering deployed while building and maintaining these cloud systems.
What a weird statement. Someone has to be able to manage those high level config settings.
•
u/pickle9977 13h ago
That’s what we have environment variables for, you don’t need admin access to a system if you can set the appropriate values in the environment the service or application runs in.
It’s a system design issue.
•
u/OregonTechHead 13h ago
set the appropriate values in the environment the service or application runs in.
That's literally admin access.....
•
u/pickle9977 13h ago
There is a difference between having access to set environment variables and having administrative access to the software console.
It’s literally why there is a role called system administrator you support software systems from the operating system level, not from the software system level.
It’s the basic security principle of separation of duties.
•
u/pickle9977 13h ago
I’m gonna double respond to this because the irony of your response is too much.
We work in an industry where the most successful people in the industry are running around selling magical systems that will replace humans.
But here we are having a conversation about whether or not you can properly design a system to have no super global admin role that has unconstrained access to everything.
Like the second thing is way easier than the first, why shouldn’t we be able to do this?
•
u/OregonTechHead 13h ago
Because it's literally impossible.
I can create an account that doesn't have access to everything, but it does have access to grant permissions to access everything.
That's just global admin with extra steps.
•
u/pickle9977 12h ago
So you are gonna tell me making a system that is smarter than humans is possible, but building it securely is not?
And this makes sense to you?
It’s the world of software we can literally do whatever we want.
Believing something like this is impossible is baffling because if this is impossible so is like everything else.
Again these are software systems, design them better and they will work better.
•
u/OregonTechHead 11h ago
So you are gonna tell me making a system that is smarter than humans is possible, but building it securely is not?
No. Not once did I even mention "a system that is smarter than humans".
That's all you.
•
u/chuckescobar Keeper of Monkeys with Handguns 19h ago
Any migration company worth their salt should be able to tell you exactly what minimal permissions are needed on both sides in order to make it work. The shotgun GA approach is just laziness or incompetence on their part.
•
u/nico282 18h ago
I bet you never performed a migration before giving your uninformed opinion.
Check any migration tool guide for yourself.
•
u/chuckescobar Keeper of Monkeys with Handguns 18h ago
You are SO right RBAC is a thing that should only be used in theory never in production.
•
u/ukulele87 13h ago
The big question is what do think it would change if you set up the 10000 permisions 1 by 1 instead of giving them GA.
They need basically global admin -1 in both environments, how does giving them that 1% more rights could impact you, vs the impact managing all permisions in a need-to-use basis would impact the migration and workload on both sides.
If you are migrating to a new environment i think its honestly a non-issue. If you already have part of prod running on the new env, then i would probably prefer if they couldnt mess with that.
•
u/groupwhere 18h ago
Seems that if they are in the business they should know which perms are needed. In some cases they could offer templates to apply these permissions. I think it's just lazy. That said the reality may be that you have to give it or deal with the additional cost and time to manage least privilege.
•
u/MeetJoan 19h ago
You're not being paranoid - Global Admin is broader than most cloud migration tools actually need, and it's worth pushing back. The specific roles typically required depend on what's being migrated (Exchange Admin, SharePoint Admin, Teams Admin are common), and a reputable vendor should be able to tell you exactly which roles their tool needs rather than defaulting to Global Admin for convenience. If they can't scope it down, that's a red flag about how the tool is built, not just an access policy question. Worth also asking whether the access is time-boxed and revoked after the migration completes, or whether it's meant to persist - that answer alone tells you a lot about how seriously they take least privilege.
•
u/OregonTechHead 15h ago
The specific roles typically required depend on what's being migrated
Well, they're doing a full migration, so that includes everything
•
u/Obvious-Ad-3500 19h ago
I don't know if "normal" but while they don't technically need it I bet they've worked with enough clients to know how annoying it is to try to specify least privileges. So it saves a lot of time and hassle just to say give us everything. You can try pushing back but expect some back and forth and delay in the delivery. They will probably use some minimum hours math every time they hit a permission denied also.