For customers of Microsoft 365 and Azure, obtaining the role of Global Administrator (GA) is every attacker's dream – it is the Domain Administrator of the cloud. This makes Global Administrator every organization's nightmare of being owned by a threat group or hacker. Luckily, well-defined role-based access control and a strict application consent model can severely limit who gets their fingers on Global Administrator – or does it? This talk explores a novel discovery that resulted in privilege escalation to Global Administrator in Entra ID (Azure AD). Part conversation about the research background, part discussion of the foundational components involved, this talk will walk step-by-step through the path to privilege escalation, and owning Global Admin.