IDENTITY SECURITY · LAB
Require a second step for role holders and keep the last administrator
Confirm that holding a management role forces a second step, list who holds privileged access, see the tenant refuse to lose its last administrator, and close the remembered-browser shortcut for role holders.
Partly readyUses your lab tenant
The lesson
Builds on: Escalating privilege.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.
- G23 Access requests and approvals, access reviews, JIT or temporary access
- G38 Method-aware step-up: require a phishing-resistant method for sensitive actions, not just a recent sign-in
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
Ben, a role holder, completes a second step
Recorded as
account.second_stepsucceeded (second_step_completed) about[email protected].Grant Ben's help desk role only for a task
Recorded as
tenant.users.management_roles.assignsucceeded.The tenant refuses to lose its last Tenant Admin
Recorded as
tenant.administrators.updaterejected.Allow role holders to remember a browser
Recorded as
tenant.authentication.updatesucceeded.Ben forgets his trusted browsers
Recorded as
account.securitysucceeded (trusted_browsers_forgotten) about[email protected].
Setup
Press Start on this page.
In Authentication, confirm Second step asks role holders for a second step (it is on by default) and that the number of days a browser may be remembered is 0.
Ben holds
lab-supportand has an authenticator app from the recovery lab. Cora holds no management role.
Walkthrough
In a private window, sign in as Ben. After his password, the tenant asks for his authenticator code. Sign out, then sign in as Cora: her password is enough under the ordinary policy, because she has no second step enrolled and holds no role.
Why it matters: stronger sign-in for stronger access. Ben's account can act on other people, so the tenant asks more of it than of an account that reaches only its own data.
In Audit, source Protocol activity, find Ben's
account.second_stepevent withsecond_step_completed.
Why it matters: privileged sign-ins should be recorded in full, so an investigator can later tell how each one was completed.
Write your tenant's privileged-access list. Administrators shows the BTL accounts and their roles; Users shows which tenant users, like Ben, hold management roles. For each, write what it can change and why it is needed.
Why it matters: the lesson's "fewer administrators, for less time" starts from knowing who holds what. Help desk access to reset other people's methods is privileged, whatever the job title.
Treat Ben's role as task-based: remove
lab-supportfrom Ben in Users, then give it back only when he has help desk work to do, and note the time you granted it.
Note: this is a manual stand-in for just-in-time access. The tenant has no eligible roles, activation, approval or automatic expiry yet; see Missing infrastructure.
Why it matters: in the lesson's week, a stolen session on a day without administrative work would hold an ordinary account. A role that is not active cannot be used.
Open Administrators. As the only BTL Tenant Admin, try to remove your own Tenant Admin assignment. The tenant refuses: it keeps at least one active BTL Tenant Admin who can manage roles.
Why it matters: an organization can lose control of itself without any attacker. A tenant user such as Ben never counts toward this rule, even with management roles, so tenant credentials alone can never be the last way to manage the tenant.
In Audit, source User directory, filter for the refused
tenant.administrators.updateand fortenant.users.management_roles.assign. Read who acted, on whom, and the outcome.
Why it matters: some changes deserve an alert the moment they happen, such as a new administrator assignment. Refused requests matter as much, because they show someone reaching for more.
Break it
In Authentication, set the number of days a browser may be remembered to 7 and save. Sign in as Ben, tick the option to remember this browser at the second step, sign out, and sign in again. The second step is skipped.
As Ben, open
$ISSUER/account/securityand choose to forget trusted browsers. Sign out and in again: the second step is back.
Why it matters: a remembered browser is a standing skip of the second step, the kind of shortcut the lesson says privileged accounts should not have.
Restore: set the number of days a browser may be remembered back to 0 and save.
Check your work
Check my progress confirms Ben's second step, the task-based role grant, the refused removal of the last Tenant Admin, the remembered-browser policy, and Ben forgetting his trusted browsers.
The refused removal appears in Audit with reason
last_administrator.Your privileged-access list names every role holder, what each can change, and why.
Cleanup
Confirm the remember-browser setting is 0.
Leave
lab-supportassigned to Ben if you plan to continue the track; remove it otherwise.
Missing infrastructure
G23: there are no eligible roles, just-in-time activation, approvals, expiry or break-glass accounts. Once it exists, the lab will make Ben eligible for
lab-support, have him activate it for 30 minutes with a reason, approve it as Tenant Admin, and watch it expire on its own.G38: privileged actions cannot require a phishing-resistant method at the moment of the action, and the role-holder rule asks for any second step. Once it exists, the lab will require a passkey for role holders and see Ben's authenticator code refused for a methods reset.