A clinic needs more than one recovery path, but that does not mean every manager or IT technician should be a Global Administrator.
A balanced model
- Maintain at least two tested, clinic-controlled administrative paths for tenant recovery.
- Use named everyday administrator accounts with the least privilege needed for routine work.
- Keep emergency access accounts separate from daily email and browsing.
- Grant outside IT providers delegated or named access rather than sharing the clinic owner password.
Limit broad roles
- Global Administrator should be reserved for tasks that truly require it.
- Use service-specific roles for user, password, Exchange, SharePoint, security, or billing work when practical.
- Review assignments after staffing, ownership, or vendor changes.
Test and document
- Verify each recovery account can reach the expected portal.
- Record role assignments, MFA ownership, recovery methods, and last test date.
- Alert on emergency-account use and investigate unexpected sign-ins.
Related ClinicsIT guidance
Practical note: Technology, licensing, vendor capabilities, and regulatory obligations vary. Confirm the clinic’s current configuration before making changes.
Recommended model
A small clinic should avoid both extremes: one irreplaceable global administrator and many unnecessary global administrators. Maintain at least two clinic-controlled recovery-capable administrators, while assigning narrower roles for routine work.
Separate daily and emergency use
Use named accounts for normal administration and reserve emergency accounts for lockout recovery. Do not rely on two accounts that share the same phone, mailbox, or employee.
Review roles
Quarterly, review global, billing, user, Exchange, SharePoint, security, and help-desk roles. Remove stale assignments and document why each privileged role exists.
Need help applying this to your clinic?
ClinicsIT can review the current environment and build a practical, documented next-step plan.
Request a consultation