Size up your environment
Describe your organisation, licences and whether restricted management is appropriate. The designer builds a model from your answers — and tells you honestly what your licence can't do. If you've been through another dojo, your licence is already filled in.
How many people do admin work?
Is your IT split into separate teams?
Does a helpdesk reset passwords?
Execs or VIPs needing extra protection?
Do apps or scripts write to your directory?
Administration boundaries
Compare AUs, restricted management and PIM
| Tool | What it does | Where to use it |
|---|---|---|
| Ordinary AU | Delegates a supported role over selected users, groups or devices. Tenant-wide administrators retain access. | Regional or divisional administration, or a helpdesk-managed user population — even with one IT team. |
| Restricted management AU | Blocks direct changes to its Entra member objects unless the administrator has an explicit role at that restricted scope. | Executive accounts/devices; emergency accounts only as an advanced opt-in with tested recovery. |
| PIM | Controls when a role is active, with time limits and activation requirements. Supported Entra roles can use AU scope. | Govern the selected roles in the PIM Dojo. PIM for Groups and other governance features have RMAU membership limitations. |
Membership trap: adding a group to an AU scopes the group object; its users must be added directly for user administration. Membership is static and manually defined in this designer.
Roles and licensing: organisational examples use User Administrator; helpdesk examples use Password Administrator for non-admin users. AU-scoped sensitive actions have additional target-role limits. Use the supported role list and task limits. AU creation is free; each scoped administrator needs P1. PIM separately needs P2 or Governance.
RMAU compatibility and recovery: tenant-wide Graph application permissions do not allow writes to protected objects; review provisioning and scoped service-principal roles. Keep role groups outside RMAUs. GA/PRA can remove members, manage scoped roles or delete the RMAU; protected Global Administrator password recovery requires removing the account first. Test recovery and audit these changes before adoption.
Service boundaries: RMAUs restrict Entra objects. Exchange mailbox settings, Intune policy and related SharePoint operations have separate permissions and are not protected by that restriction.
Administrative Units ↗ · RMAU limitations ↗ · PIM role scope ↗
Confirm each boundary separately. Earlier IT-structure and global RMAU answers are preserved, but do not select these new choices.
Step 0.5 — Your identity model
Everything else in these dojos is a checklist. This isn't. An identity model is a design, and "you should use administrative units" is useless advice — so here are your administrative units, what goes in them, which role sits at which scope, and the PowerShell to build it. It's a starting point built from your answers, not a substitute for knowing your own tenant.
Answer the organisation questions above to view your model. Boundary decisions and unresolved prerequisites are shown separately.
Break-glass accounts live here now
Emergency access accounts are a privileged access problem, so this dojo owns them end to end: create two, keep them cloud-only and permanently Global Admin, give them phishing-resistant credentials stored somewhere physically secure, alert on every sign-in, and consider restricted management after testing recovery and governance compatibility with a documented route for removing protected accounts from the AU when recovery requires it.
The Conditional Access Dojo still gates on them, because protecting them from restrictive CA policy lockout is a Conditional Access job. Everything else about them is here. Full guidance: Manage emergency access accounts in Microsoft Entra ID ↗
Walk out with a plan
Your plan reflects recorded answers and progress, including unresolved and deferred controls. Configuration examples require review of permissions, licensing, dependencies and placeholders. PowerShell bundles include an execution stop; read and edit them before deliberately running a selected section. The designer script is scaffolding: creating and testing emergency accounts, assignments, membership and PIM configuration still require the documented steps.