IDENTITY GOVERNANCE · LAB
Make access drift in your tenant, then try to explain it
Move Ava between teams the way a help desk would, answer an auditor's "who, and why?" from tenant records, and see what happens when the person who can grant access also decides it.
ReadyUses your lab tenant
The lesson
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
Add Ava to Photo moderation and remove nothing
Recorded as
tenant.groups.memberssucceeded.Create the Help desk management role
Recorded as
tenant.roles.createsucceeded.Give Ben the Help desk role
Recorded as
tenant.users.management_roles.assignsucceeded about[email protected].Ben adds himself to a group
Recorded as
tenant.groups.memberssucceeded.Ben's change is refused once the permission is gone
Recorded as
tenant.groups.membersrejected (access_denied).Put the Help desk permission back
Recorded as
tenant.roles.updatesucceeded.
Setup
This lab starts the Identity governance track. Lab Photos plays an organization with staff: Ava Archer works in print support and is about to move to photo moderation, Cora Diaz already works in moderation, and Ben Okafor answers the help desk. The three groups you create here stand in for the lesson's unit groups and are reused by later governance labs.
If you want a clean start, reset the lab tenant with the Lab Photos preset (Overview > Reset tenant). Audit and Logs are preserved by default. The preset creates Ava, Ben and Cora.
In User Management > Users, confirm that
[email protected],[email protected]and[email protected]exist. Use Set password to give Ben a password and keep it in your password manager. You sign in as Ben in a browser later.In User Management > Groups, create three groups:
Print support, the team Ava works in today (the lesson's pediatrics access)Photo moderation, the team Ava is moving to (the lesson's oncology access)Print incident reviews, a review group Ava joined while in print support (the lesson's incident reviews folder)
Add Ava to
Print supportandPrint incident reviews. Add Cora toPhoto moderation.Create the user
[email protected](first name Test, last name Account) and add it toPhoto moderation. Do not write down why. This is the account nobody remembers creating.Note your tenant's address from Overview, such as
https://tenant-<id>.beyondthelogin.dev. The steps write it as$ISSUER.On the lab page, choose Lab Photos as the lab tenant and press Start.
Walkthrough
The transfer. Ava moves to photo moderation. Add Ava to
Photo moderationand do nothing else. Open Ava's row on Users or each group's Members: Ava now belongs to all three groups.
Why it matters: this is "How access drifts". Missing access produces a phone call within the hour. Extra access produces silence, so nothing prompts anyone to remove the print support groups.
The auditor's question, first half. Open
Photo moderation> Members. You see Cora, Ava and Test Account.
Why it matters: the system answers "who" instantly, as Jordan could in "A question nobody can answer".
The auditor's question, second half. Copy the group's ID from the Groups page. Open Audit, choose the Source User directory, paste the ID into Search and run it. Each membership change appears as
tenant.groups.members(Group members changed) with outcomesucceeded, your account as actor, a time and a count of members added. Open one event's detail.
Why it matters: the record proves who changed the group and when. It holds no reason, no approver and no end date, because nothing in the tenant asked for them.
Write Ava's access next to its reason. Fill this table from the Groups page and Audit, the way the lesson does for Sam:
| Access | How it was granted (Audit actor and time) | Can anyone say why today? |
|---|---|---|
| Photo moderation | ||
| Print support | ||
| Print incident reviews |
Why it matters: only one row has a current reason, and no row says when it should end. Each grant was an event, and no event ever took anything away.
Find the decision behind the test account. On Users, open Test Account's details and copy its User ID. Search Audit for it. You find
tenant.users.createandtenant.groups.members, both by you.
Why it matters: the account exists and the record says who made it, yet nobody can say whether it should exist. An account like this is something to investigate, which the orphaned accounts lab does.
Give the help desk the power to change groups. In User Management > Roles, create a management role
Help deskwithtenant.users.read,tenant.groups.readandtenant.groups.update. On Users, open Ben's Management roles action and assignHelp desk. Audit now showstenant.roles.createandtenant.users.management_roles.assign.
Why it matters: this is "Administration and governance". You have arranged the administration half. Nothing yet decides who should get what, so whoever answers the phone will decide.
Sign in as the help desk. In a private window, open
$ISSUER/manageand sign in as Ben. Ben sees only the pages his role allows. Open Groups and add Ben himself toPhoto moderation. It succeeds, and Audit showstenant.groups.memberswith Ben's tenant user ID as actor.
Why it matters: this is "Who decides". Nothing stopped Ben granting access to Ben. When the person who can make a change also decides it, the record shows only that the change happened.
Break it
Still signed in as Ben, look for Lock on Cora and for the Roles page. Neither is offered, because
Help desklacks those permissions. Hidden controls are not the protection, so test the server.As Ben, open
Photo moderation> Members and leave the dialog open. In your own window, removetenant.groups.updatefromHelp deskand save.As Ben, remove yourself from the group in the dialog that is still open and save. The tenant refuses with
access_denied, and Audit recordstenant.groups.memberswith outcomerejectedand Ben as actor. Permissions are evaluated on every request against current assignments, not when the page loaded.
Restore: in your own window, add tenant.groups.update back to Help desk and save. Audit records tenant.roles.update.
Check your work
Press Check my progress. The checks look for, in order:
tenant.groups.memberssucceeded (step 1)tenant.roles.createsucceeded (step 6)tenant.users.management_roles.assignsucceeded for Ben (step 6)tenant.groups.memberssucceeded after the assignment (step 7, Ben adds himself)tenant.groups.membersrejected withaccess_denied(Break it)tenant.roles.updatesucceeded after the refusal (the Restore)
Also check your table from step 4: at least two rows should say "No".
Cleanup
As yourself, remove Ben from
Photo moderation.Delete
[email protected]. Its history stays in Audit.Keep the three groups, Ava's three memberships and the
Help deskrole. Later governance labs start from this drift.