Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

IDENTITY SECURITY · LAB

Delegate role administration and watch the delegation limit hold

Give Ben limited role administration, then see the tenant allow what he holds and refuse an over-broad role, a Tenant Admin assignment and actions after his role is removed.

ReadyUses your lab tenant

The lesson

Builds on: Attacks on recovery and the help desk.

New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.

Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.

Your progress

Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.

  1. Ben creates a role from permissions he holds

    Recorded as tenant.roles.create succeeded.

  2. Remove the lock permission from Ben's role

    Recorded as tenant.roles.update succeeded.

  3. Ben's role with a permission he no longer holds is refused

    Recorded as tenant.roles.create rejected.

  4. Ben cannot assign Tenant Admin to Cora

    Recorded as tenant.users.management_roles.assign rejected.

  5. Remove Ben's role administration

    Recorded as tenant.users.management_roles.assign succeeded.

  6. Ben's next role change is refused

    Recorded as tenant.roles.delete rejected.

Setup

  1. In Roles, create lab-role-admin with these permissions: list roles, create roles, update roles, delete roles, list users, lock users, and assign management roles to users (tenant.roles.read, tenant.roles.create, tenant.roles.update, tenant.roles.delete, tenant.users.read, tenant.users.lock, tenant.users.management_roles.assign).

  2. In Users, give Ben lab-role-admin alongside lab-support.

  3. Press Start on this page.

Walkthrough

  1. In a private window, sign in as Ben and open $ISSUER/manage, then Roles. Create a role named lab-tmp-viewer with only the permission to list users. It is saved. Note that every permission Ben does not hold is greyed out in the editor.

Why it matters: this is the lesson's delegation limit. Ben can grant only what he holds himself, so role administration cannot become a way to hand out user deletion or policy changes.

  1. As Ben, start creating another role, lab-tmp-locker, and tick the permission to lock users, which Ben holds. Do not save yet. In your own window, as Tenant Admin, edit lab-role-admin and remove the lock permission. Now save Ben's role. The tenant refuses it.

Why it matters: the editor showed the box when the page loaded, but the server checks what Ben holds when the request arrives. The lesson's "the service that performs an action has to check the permission itself" is exactly this.

  1. As Ben, open Users, choose Cora, and try to give her the Tenant Admin role. The tenant refuses it.

Why it matters: assigning a role is granting its permissions. Ben does not hold Tenant Admin's permissions, so he cannot give them to anyone, including an account he controls.

  1. As Ben, look at the built-in Tenant Admin role in Roles. It is protected and cannot be edited by anyone.

Why it matters: the lesson's self-edit route works when editing a role a person holds silently grows their own access. A protected recovery role cannot be edited, and the tenant checks every role edit against what the editor holds.

  1. As Tenant Admin, remove lab-role-admin from Ben in Users. As Ben, without refreshing, try to delete lab-tmp-viewer. The tenant refuses it.

Why it matters: the tenant evaluates Ben's current assignments on every request. A role removed at 10:00 stops working at 10:00, not when Ben's session ends.

  1. In Audit, source User directory, search for Ben's user ID as the actor. Read the refusals in order: the over-broad role, the Tenant Admin assignment, and the delete after removal, each with reason access_denied.

Why it matters: refused attempts belong in the records alongside the successes. An ordinary account trying to give itself more is rarely an accident, and the actor field shows who asked.

Break it

  1. As Tenant Admin, try to delete lab-support while Ben still holds it. The tenant refuses it because the role is in use, so a removal that changes who holds power is checked against current assignments. Nothing was removed, so there is nothing to restore.

Check your work

  • Check my progress confirms Ben's role creation, the role edit, the refused role, the refused Tenant Admin assignment, the removal of Ben's role and the refusal afterwards.

  • In Audit, source User directory, the refusals show reason access_denied and the refused deletion of an assigned role shows role_in_use.

Cleanup

  1. As Tenant Admin, delete lab-tmp-viewer (and lab-tmp-locker if it was ever saved).

  2. Delete lab-role-admin once nobody holds it. Keep lab-support assigned to Ben.

Missing infrastructure

  • G45: management roles cannot be assigned to groups or scoped to part of a tenant, so the lesson's nested-group path to user administration has no counterpart. Once it exists, the lab will give a group a role and confirm that only someone who could grant the role directly may change the group's members.

  • G22: there is no authorization engine for application data, so horizontal escalation (reading a colleague's photos by changing an identifier) cannot be practiced against a real API. Once it exists, the lab will request Cora's album as Ava and see the decision refused and recorded.

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab