Somewhere in most Azure tenants sits a small, often overlooked list of accounts holding Global Administrator or equivalent privileged roles, each one capable of undoing every other security control in the environment in a matter of minutes. These roles do not need a sophisticated exploit…