azureblog.co.uk
← cd ~/learn
// learning path · intermediate

Locking down admin access

Emergency accounts, just-in-time roles, strong activation and safer app permissions.

0 of 6 read · about 15 minutes in total
start with part 1 →
  1. 01Break-glass accounts done rightEmergency access accounts are the one thing you hope never to use and must never get wrong. A practical checklist for setting them up and keeping them safe.2 min✓ read
  2. 02Activate PIM roles from PowerShell with Microsoft GraphThe portal is fine for occasional use, but if you activate roles every day, a few lines of Graph PowerShell are faster. Here's how to list eligible roles and activate one.4 min✓ read
  3. 03Require phishing-resistant MFA on every PIM activationPIM can now require a Conditional Access authentication context every time someone activates a role, and it's generally available. Here's how to set it up properly.2 min✓ read
  4. 04Lock down app consent without blocking your usersIllicit consent grants are a favourite way to steal mailbox data. Restricting user consent and turning on the admin consent workflow closes the door without making life miserable.2 min✓ read
  5. 05Key Vault: move from access policies to Azure RBACKey Vault has two permission models. Azure RBAC is the recommended one, and switching is simpler than it looks if you plan the role mapping first.2 min✓ read
  6. 06Entra Backup and Recovery is here: an undo button for your tenantEntra ID now keeps daily backups of your critical directory objects and lets you compare and roll back changes. It's on by default, but you need to know how it works before you need it.3 min✓ read

Progress is saved in this browser only. A post counts as read once you've scrolled most of the way through it.