Microsoft 365 grants excessive levels of admin privilege
Microsoft 365’s default role-based access control (RBAC) gives admins excessive and dangerous levels of privilege. Admin accounts have tenant-wide powers, so all admins can typically see and manage everything.
With this excessive level of privilege, you’re always only one privileged account compromise away from total tenant takeover.