[E 8] Roles, Custom Roles, and Delegated Administration

Delegation is giving people exactly the authority their job requires and not a scrap more, because the width of a role assignment is the width of a breach.

Delegation is giving people exactly the authority their job requires and not a scrap more, because the width of a role assignment is the width of a breach.

Privilege is the one thing you want people to have and not hold. PIM separates being entitled to a role from possessing it, so power is reached for deliberately, briefly, and on the record.

A strong credential proves who is signing in; it cannot prove the sign-in is safe. Identity Protection is the sensor for that gap, and its value depends on being honest about what a risk engine can and cannot see.

A small portfolio of phishing-resistant credentials, held one device-bound and one portable, chosen deliberately.

Authentication is becoming a ranking the system enforces, steering every user to their strongest credential and asking for the password only when nothing better exists. One policy, system-preferred authentication, registration as the real work, and retiring the weak on purpose.

The shape of a directory is decided before the first policy and ages badly when improvised. One tenant or several, the population-versus-entitlement group model, and the restricted management administrative unit that protects your core from your own administrators.

Every account arrived from somewhere, and where it came from decides where you can change it. Source of authority, the three origins of an identity, the Connect-Sync-to-Cloud-Sync transition now underway, and the slow migration of authority to the cloud.

Microsoft has moved the Entra ID security baseline from recommendations you implement to a floor it enforces. Getting started in 2026 is knowing what is already switched on, and deciding everything the floor does not: privilege, structure, break-glass done the new way, and access that expires.