IDENTITY GOVERNANCE · LAB
Give privileged work its own account, a stronger sign-in and a time limit
Move privilege onto a separate admin account that must pass a second step, hold a powerful role only for a ticketed window, review what was done in it, and see that the recovery path cannot be removed.
Partly readyUses your lab tenant
The lesson
Builds on: Why access needs governance.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.
- G23 Access requests and approvals, access reviews, JIT or temporary access
- G30 Admin session listing and kill-session
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
Require a second step for management role holders
Recorded as
tenant.authentication.updatesucceeded.Grant the admin account its role for the window
Recorded as
tenant.users.management_roles.assignsucceeded.The admin account passes the second step
Recorded as
account.second_stepsucceeded (second_step_completed).Do the ticketed task inside the window
Recorded as
tenant.users.methods.resetsucceeded about[email protected].An action beyond the role's reach is refused
Recorded as
tenant.users.lockrejected (access_denied) about[email protected].The last Tenant Admin cannot be removed
Recorded as
tenant.administrators.updaterejected (last_administrator).
Setup
Ben's everyday account answers the help desk queue, reads email and follows links. The lesson's EHR_ADMIN becomes a powerful records role here, and Ben gets a separate account to hold it.
Press Start on the lab page.
In User Management > Roles, create
lab-tmp-records-adminwithtenant.users.read,tenant.users.update,tenant.users.lock,tenant.users.unlock,tenant.users.credentials.set,tenant.users.methods.resetandtenant.audit.read.Create Ben's administration account on Users:
[email protected], first name Ben, last name "Okafor (admin)". Set a password, keep it in your password manager, and assign no roles.Have an authenticator app ready for TOTP.
Walkthrough
Inventory standing privilege. On Users, list every tenant user with a management role, and on Roles, every BTL administrator. For each, mark whether the role is used daily or for a few hours a month.
Why it matters: this is "Access that should not stay". Standing access is fine for daily work. Rarely used, powerful access is risk every hour it sits unused.
Require stronger sign-in for privilege. In Authentication, make TOTP (or passkeys) available, and set the second step to apply to management role holders. Save. Note the previous setting if you want to return to it later.
Why it matters: this is "Privileged accounts". Role holders get stronger evidence by policy, not by habit. Ben's everyday account holds Help desk, so it now needs the second step too.
Elevate the admin account for a window. Write a start time and a ticket in your notes: "CHG-LAB-01: reset Cora's sign-in methods and set her a new password, two hours". Assign
lab-tmp-records-adminto[email protected]. In a private window, sign in at$ISSUER/manageas that account: after the password, the tenant requires the second step, and you enroll TOTP if prompted. Then sign in as Ava at$ISSUER/accountin another private window: no second step. Audit recordsaccount.second_stepwithsecond_step_completedfor the admin account.
Why it matters: this is "Access for a while". The privilege lands on an account that never reads email, and only after a fresh, stronger proof of who is asking.
Do the ticketed task. As the admin account, open Cora on Users, use Reset sign-in methods, then Set password with a new value you record for Cora. Audit records
tenant.users.methods.resetandtenant.users.credentials.setwith the admin account as actor.Try to go beyond the ticket. Still as the admin account, try to lock Ben. Refused with
access_denied: Ben holdsHelp desk, which includes a permission (tenant.groups.update) thatlab-tmp-records-adminlacks, and nobody can change a user whose roles reach further than their own.Close the window. At the end time, remove
lab-tmp-records-adminfrom the admin account in your own window. In the admin account's still-open/managetab, try any action, such as Set password on Cora:access_denied, because permissions are evaluated against current assignments on every request.
Why it matters: what a task needs includes time. Here you were the timer; in the planned version the tenant is.
Review what happened. Copy the admin account's User ID and search Audit for it. Every action in the window is listed. Compare each with the ticket, and confirm that nothing succeeded outside the window. Write the review in your notes with a reviewer other than Ben.
Why it matters: this is "Reviewing what happened". Someone other than the person who used the privilege compares the record with the reason given.
The recovery path cannot be removed. On Roles, open your own BTL administrator entry and try to remove Tenant Admin from it. If you are the only active Tenant Admin, the tenant refuses with
last_administrator: "Keep at least one active Tenant Admin." If another BTL user also holds Tenant Admin in this tenant, the change would succeed, so skip this step.
Why it matters: this is "Breaking the glass". Your BTL account is the route back into the tenant when everything else fails, and the tenant keeps it from being removed by accident or by a delegated administrator. Tenant users never count toward it.
After an emergency, new credentials. Treat the admin account as if it had been used in an emergency: Set password to a new value and Reset sign-in methods. Audit records
tenant.users.credentials.setandtenant.users.methods.resetfor it.
Why it matters: the step that slipped at Harbor was rotating the emergency credential afterwards. Doing it is cheap; skipping it leaves a working credential that bypasses every other control.
Planned walkthrough
Once G23 and G30 exist, the window runs itself.
As the admin account, request
lab-tmp-records-adminfor two hours with the reason "CHG-LAB-01" and the ticket reference. The request goes to someone other than Ben.Cora, as approver, approves it. The role is assigned at the start of the window, and every Audit event in the window carries the request ID.
At the end of the window, the tenant removes the role and ends the admin account's open sessions (G30), and records both against the request.
An emergency route lets an administrator take the role at once with a typed reason. The tenant raises an alert and opens a review item for someone else to decide within a few days.
Check your work
Press Check my progress. The checks look for, in order:
tenant.authentication.updatesucceeded (step 2)tenant.users.management_roles.assignsucceeded (step 3)account.second_stepsucceeded withsecond_step_completed(step 3)tenant.users.methods.resetsucceeded for Cora (step 4)tenant.users.lockrejected withaccess_deniedfor Ben (step 5)tenant.administrators.updaterejected withlast_administrator(step 8)
Cleanup
Delete
[email protected]and thelab-tmp-records-adminrole.Give Cora a password you record, if step 4's is not kept.
Keep the second step for role holders, which is the secure setting, or return to the value you noted in step 2.
Missing infrastructure
G23: there is no request for a role for a window, approved by someone else, granted at the start and removed at the end, with the request ID on every event in between. There is also no break-glass route with a recorded reason, an alert and a review item.
G30: when the window closes, there is no admin action to list and end the admin account's open sessions. Removing the role stops its permissions at once, but the session itself stays until it expires.