Security Ninja

Privileged Access Dojo

Conditional Access locks the front door. This is about who holds a key, how many keys there are, and whether they hand them back. Most tenants have more permanent Global Admins than they can name, a helpdesk that can reset the CEO's password, and untested recovery paths. Answer five organisation questions and review a model with optional restricted management and its recovery limits.

Recorded progress
0 / 1000
Current Rank
No belt yet
0 in use 0 built 0 in scope

User-recorded progress; not tenant-verified.

Size up your environment

Describe your organisation, licences and whether restricted management is appropriate. The designer builds a model from your answers — and tells you honestly what your licence can't do. If you've been through another dojo, your licence is already filled in.

Which licences do you hold? Select all that apply.
More products and add-ons

Check assignments for each affected user, cloud and feature. Education and government packages can be recorded as Other with confirmed P1/P2 features.

Microsoft Learn licensing reference ↗

How many people do admin work?

Is your IT split into separate teams?

Does a helpdesk reset passwords?

Execs or VIPs needing extra protection?

Do apps or scripts write to your directory?

Administration boundaries

Compare AUs, restricted management and PIM
ToolWhat it doesWhere to use it
Ordinary AUDelegates a supported role over selected users, groups or devices. Tenant-wide administrators retain access.Regional or divisional administration, or a helpdesk-managed user population — even with one IT team.
Restricted management AUBlocks direct changes to its Entra member objects unless the administrator has an explicit role at that restricted scope.Executive accounts/devices; emergency accounts only as an advanced opt-in with tested recovery.
PIMControls when a role is active, with time limits and activation requirements. Supported Entra roles can use AU scope.Govern the selected roles in the PIM Dojo. PIM for Groups and other governance features have RMAU membership limitations.

Membership trap: adding a group to an AU scopes the group object; its users must be added directly for user administration. Membership is static and manually defined in this designer.

Roles and licensing: organisational examples use User Administrator; helpdesk examples use Password Administrator for non-admin users. AU-scoped sensitive actions have additional target-role limits. Use the supported role list and task limits. AU creation is free; each scoped administrator needs P1. PIM separately needs P2 or Governance.

RMAU compatibility and recovery: tenant-wide Graph application permissions do not allow writes to protected objects; review provisioning and scoped service-principal roles. Keep role groups outside RMAUs. GA/PRA can remove members, manage scoped roles or delete the RMAU; protected Global Administrator password recovery requires removing the account first. Test recovery and audit these changes before adoption.

Service boundaries: RMAUs restrict Entra objects. Exchange mailbox settings, Intune policy and related SharePoint operations have separate permissions and are not protected by that restriction.

Administrative Units ↗ · RMAU limitations ↗ · PIM role scope ↗

Confirm each boundary separately. Earlier IT-structure and global RMAU answers are preserved, but do not select these new choices.

Ordinary AUs for delegation?
Executive RMAU?

For executive accounts and devices; review support roles and workflow compatibility.

Emergency-account RMAU?

Advanced, optional protection. Keep two tested, permanently active emergency Global Administrators and document removal from the RMAU for password recovery.

Step 0.5 — Your identity model

Everything else in these dojos is a checklist. This isn't. An identity model is a design, and "you should use administrative units" is useless advice — so here are your administrative units, what goes in them, which role sits at which scope, and the PowerShell to build it. It's a starting point built from your answers, not a substitute for knowing your own tenant.

Answer the organisation questions above to view your model. Boundary decisions and unresolved prerequisites are shown separately.

Break-glass accounts live here now

Emergency access accounts are a privileged access problem, so this dojo owns them end to end: create two, keep them cloud-only and permanently Global Admin, give them phishing-resistant credentials stored somewhere physically secure, alert on every sign-in, and consider restricted management after testing recovery and governance compatibility with a documented route for removing protected accounts from the AU when recovery requires it.

The Conditional Access Dojo still gates on them, because protecting them from restrictive CA policy lockout is a Conditional Access job. Everything else about them is here. Full guidance: Manage emergency access accounts in Microsoft Entra ID ↗

Walk out with a plan

Your plan reflects recorded answers and progress, including unresolved and deferred controls. Configuration examples require review of permissions, licensing, dependencies and placeholders. PowerShell bundles include an execution stop; read and edit them before deliberately running a selected section. The designer script is scaffolding: creating and testing emergency accounts, assignments, membership and PIM configuration still require the documented steps.