Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

IDENTITY GOVERNANCE · LAB

Give privileged work its own account, a stronger sign-in and a time limit

Move privilege onto a separate admin account that must pass a second step, hold a powerful role only for a ticketed window, review what was done in it, and see that the recovery path cannot be removed.

Partly readyUses your lab tenant

The lesson

Builds on: Why access needs governance.

New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.

Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.

Your progress

Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.

  1. Require a second step for management role holders

    Recorded as tenant.authentication.update succeeded.

  2. Grant the admin account its role for the window

    Recorded as tenant.users.management_roles.assign succeeded.

  3. The admin account passes the second step

    Recorded as account.second_step succeeded (second_step_completed).

  4. Do the ticketed task inside the window

    Recorded as tenant.users.methods.reset succeeded about [email protected].

  5. An action beyond the role's reach is refused

    Recorded as tenant.users.lock rejected (access_denied) about [email protected].

  6. The last Tenant Admin cannot be removed

    Recorded as tenant.administrators.update rejected (last_administrator).

Setup

Ben's everyday account answers the help desk queue, reads email and follows links. The lesson's EHR_ADMIN becomes a powerful records role here, and Ben gets a separate account to hold it.

  1. Press Start on the lab page.

  2. In User Management > Roles, create lab-tmp-records-admin with tenant.users.read, tenant.users.update, tenant.users.lock, tenant.users.unlock, tenant.users.credentials.set, tenant.users.methods.reset and tenant.audit.read.

  3. Create Ben's administration account on Users: [email protected], first name Ben, last name "Okafor (admin)". Set a password, keep it in your password manager, and assign no roles.

  4. Have an authenticator app ready for TOTP.

Walkthrough

  1. Inventory standing privilege. On Users, list every tenant user with a management role, and on Roles, every BTL administrator. For each, mark whether the role is used daily or for a few hours a month.

Why it matters: this is "Access that should not stay". Standing access is fine for daily work. Rarely used, powerful access is risk every hour it sits unused.

  1. Require stronger sign-in for privilege. In Authentication, make TOTP (or passkeys) available, and set the second step to apply to management role holders. Save. Note the previous setting if you want to return to it later.

Why it matters: this is "Privileged accounts". Role holders get stronger evidence by policy, not by habit. Ben's everyday account holds Help desk, so it now needs the second step too.

  1. Elevate the admin account for a window. Write a start time and a ticket in your notes: "CHG-LAB-01: reset Cora's sign-in methods and set her a new password, two hours". Assign lab-tmp-records-admin to [email protected]. In a private window, sign in at $ISSUER/manage as that account: after the password, the tenant requires the second step, and you enroll TOTP if prompted. Then sign in as Ava at $ISSUER/account in another private window: no second step. Audit records account.second_step with second_step_completed for the admin account.

Why it matters: this is "Access for a while". The privilege lands on an account that never reads email, and only after a fresh, stronger proof of who is asking.

  1. Do the ticketed task. As the admin account, open Cora on Users, use Reset sign-in methods, then Set password with a new value you record for Cora. Audit records tenant.users.methods.reset and tenant.users.credentials.set with the admin account as actor.

  2. Try to go beyond the ticket. Still as the admin account, try to lock Ben. Refused with access_denied: Ben holds Help desk, which includes a permission (tenant.groups.update) that lab-tmp-records-admin lacks, and nobody can change a user whose roles reach further than their own.

  3. Close the window. At the end time, remove lab-tmp-records-admin from the admin account in your own window. In the admin account's still-open /manage tab, try any action, such as Set password on Cora: access_denied, because permissions are evaluated against current assignments on every request.

Why it matters: what a task needs includes time. Here you were the timer; in the planned version the tenant is.

  1. Review what happened. Copy the admin account's User ID and search Audit for it. Every action in the window is listed. Compare each with the ticket, and confirm that nothing succeeded outside the window. Write the review in your notes with a reviewer other than Ben.

Why it matters: this is "Reviewing what happened". Someone other than the person who used the privilege compares the record with the reason given.

  1. The recovery path cannot be removed. On Roles, open your own BTL administrator entry and try to remove Tenant Admin from it. If you are the only active Tenant Admin, the tenant refuses with last_administrator: "Keep at least one active Tenant Admin." If another BTL user also holds Tenant Admin in this tenant, the change would succeed, so skip this step.

Why it matters: this is "Breaking the glass". Your BTL account is the route back into the tenant when everything else fails, and the tenant keeps it from being removed by accident or by a delegated administrator. Tenant users never count toward it.

  1. After an emergency, new credentials. Treat the admin account as if it had been used in an emergency: Set password to a new value and Reset sign-in methods. Audit records tenant.users.credentials.set and tenant.users.methods.reset for it.

Why it matters: the step that slipped at Harbor was rotating the emergency credential afterwards. Doing it is cheap; skipping it leaves a working credential that bypasses every other control.

Planned walkthrough

Once G23 and G30 exist, the window runs itself.

  1. As the admin account, request lab-tmp-records-admin for two hours with the reason "CHG-LAB-01" and the ticket reference. The request goes to someone other than Ben.

  2. Cora, as approver, approves it. The role is assigned at the start of the window, and every Audit event in the window carries the request ID.

  3. At the end of the window, the tenant removes the role and ends the admin account's open sessions (G30), and records both against the request.

  4. An emergency route lets an administrator take the role at once with a typed reason. The tenant raises an alert and opens a review item for someone else to decide within a few days.

Check your work

Press Check my progress. The checks look for, in order:

  • tenant.authentication.update succeeded (step 2)

  • tenant.users.management_roles.assign succeeded (step 3)

  • account.second_step succeeded with second_step_completed (step 3)

  • tenant.users.methods.reset succeeded for Cora (step 4)

  • tenant.users.lock rejected with access_denied for Ben (step 5)

  • tenant.administrators.update rejected with last_administrator (step 8)

Cleanup

  1. Delete [email protected] and the lab-tmp-records-admin role.

  2. Give Cora a password you record, if step 4's is not kept.

  3. Keep the second step for role holders, which is the secure setting, or return to the value you noted in step 2.

Missing infrastructure

  • G23: there is no request for a role for a window, approved by someone else, granted at the start and removed at the end, with the request ID on every event in between. There is also no break-glass route with a recorded reason, an alert and a review item.

  • G30: when the window closes, there is no admin action to list and end the admin account's open sessions. Removing the role stops its permissions at once, but the session itself stays until it expires.

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab