Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

IDENTITY SECURITY · LAB

Require a second step for role holders and keep the last administrator

Confirm that holding a management role forces a second step, list who holds privileged access, see the tenant refuse to lose its last administrator, and close the remembered-browser shortcut for role holders.

Partly readyUses your lab tenant

The lesson

Builds on: Escalating privilege.

New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.

Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.

Your progress

Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.

  1. Ben, a role holder, completes a second step

    Recorded as account.second_step succeeded (second_step_completed) about [email protected].

  2. Grant Ben's help desk role only for a task

    Recorded as tenant.users.management_roles.assign succeeded.

  3. The tenant refuses to lose its last Tenant Admin

    Recorded as tenant.administrators.update rejected.

  4. Allow role holders to remember a browser

    Recorded as tenant.authentication.update succeeded.

  5. Ben forgets his trusted browsers

    Recorded as account.security succeeded (trusted_browsers_forgotten) about [email protected].

Setup

  1. Press Start on this page.

  2. In Authentication, confirm Second step asks role holders for a second step (it is on by default) and that the number of days a browser may be remembered is 0.

  3. Ben holds lab-support and has an authenticator app from the recovery lab. Cora holds no management role.

Walkthrough

  1. In a private window, sign in as Ben. After his password, the tenant asks for his authenticator code. Sign out, then sign in as Cora: her password is enough under the ordinary policy, because she has no second step enrolled and holds no role.

Why it matters: stronger sign-in for stronger access. Ben's account can act on other people, so the tenant asks more of it than of an account that reaches only its own data.

  1. In Audit, source Protocol activity, find Ben's account.second_step event with second_step_completed.

Why it matters: privileged sign-ins should be recorded in full, so an investigator can later tell how each one was completed.

  1. Write your tenant's privileged-access list. Administrators shows the BTL accounts and their roles; Users shows which tenant users, like Ben, hold management roles. For each, write what it can change and why it is needed.

Why it matters: the lesson's "fewer administrators, for less time" starts from knowing who holds what. Help desk access to reset other people's methods is privileged, whatever the job title.

  1. Treat Ben's role as task-based: remove lab-support from Ben in Users, then give it back only when he has help desk work to do, and note the time you granted it.

Note: this is a manual stand-in for just-in-time access. The tenant has no eligible roles, activation, approval or automatic expiry yet; see Missing infrastructure.

Why it matters: in the lesson's week, a stolen session on a day without administrative work would hold an ordinary account. A role that is not active cannot be used.

  1. Open Administrators. As the only BTL Tenant Admin, try to remove your own Tenant Admin assignment. The tenant refuses: it keeps at least one active BTL Tenant Admin who can manage roles.

Why it matters: an organization can lose control of itself without any attacker. A tenant user such as Ben never counts toward this rule, even with management roles, so tenant credentials alone can never be the last way to manage the tenant.

  1. In Audit, source User directory, filter for the refused tenant.administrators.update and for tenant.users.management_roles.assign. Read who acted, on whom, and the outcome.

Why it matters: some changes deserve an alert the moment they happen, such as a new administrator assignment. Refused requests matter as much, because they show someone reaching for more.

Break it

  1. In Authentication, set the number of days a browser may be remembered to 7 and save. Sign in as Ben, tick the option to remember this browser at the second step, sign out, and sign in again. The second step is skipped.

  2. As Ben, open $ISSUER/account/security and choose to forget trusted browsers. Sign out and in again: the second step is back.

Why it matters: a remembered browser is a standing skip of the second step, the kind of shortcut the lesson says privileged accounts should not have.

Restore: set the number of days a browser may be remembered back to 0 and save.

Check your work

  • Check my progress confirms Ben's second step, the task-based role grant, the refused removal of the last Tenant Admin, the remembered-browser policy, and Ben forgetting his trusted browsers.

  • The refused removal appears in Audit with reason last_administrator.

  • Your privileged-access list names every role holder, what each can change, and why.

Cleanup

  1. Confirm the remember-browser setting is 0.

  2. Leave lab-support assigned to Ben if you plan to continue the track; remove it otherwise.

Missing infrastructure

  • G23: there are no eligible roles, just-in-time activation, approvals, expiry or break-glass accounts. Once it exists, the lab will make Ben eligible for lab-support, have him activate it for 30 minutes with a reason, approve it as Tenant Admin, and watch it expire on its own.

  • G38: privileged actions cannot require a phishing-resistant method at the moment of the action, and the role-holder rule asks for any second step. Once it exists, the lab will require a passkey for role holders and see Ben's authenticator code refused for a methods reset.

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab