Privileged Access Dojo

Tenant Defence Score
0 / 1000
Current Rank
No belt yet
0 in use 0 built 0 in scope

Conditional Access locks the front door. This is about who holds a key, how many keys there are, and whether they hand them back. Most tenants have more permanent Global Admins than they can name, a helpdesk that can reset the CEO's password, and no idea that Microsoft ships a way to lock even a Global Admin out of an account. Answer five questions and walk out with a model.

Size up your environment

Five questions about the shape of your organisation, plus your licence mix. The designer builds a model from your answers — and tells you honestly what your licences can and can't do. If you've been through another dojo, your licence mix is already filled in.

Which licences do you have in the tenant? Select all that apply.

How many people do admin work?

Is your IT split into separate teams?

Does a helpdesk reset passwords?

Execs or VIPs needing extra protection?

Do apps or scripts write to your directory?

Step 0.5 — Your identity model

Everything else in these dojos is a checklist. This isn't. An identity model is a design, and "you should use administrative units" is useless advice — so here are your administrative units, what goes in them, which role sits at which scope, and the PowerShell to build it. It's a starting point built from five answers, not a substitute for knowing your own tenant.

Answer all five questions above and your model appears here.

Break-glass accounts live here now Emergency access account guidance

Emergency access accounts are a privileged access problem, so this dojo owns them end to end: create two, keep them cloud-only and permanently Global Admin, give them phishing-resistant credentials stored somewhere physically secure, alert on every sign-in, and — the part almost nobody does — protect them with a restricted management administrative unit so a compromised Global Admin can't delete the very accounts you'd use to recover from a compromised Global Admin.

The Conditional Access Dojo still gates on them, because excluding them from every CA policy is a Conditional Access job. Everything else about them is here. Full guidance: Manage emergency access accounts in Microsoft Entra ID ↗

Walk out with a plan

Your deployment plan lists every in-scope control with its status, MITRE references and Microsoft Learn source. The PowerShell is the Designer's — it knows your answers, so it emits the actual administrative unit and group names for your model, in dependency order, behind a safety stop you have to disarm deliberately.