{"id":3027,"date":"2026-03-31T21:47:44","date_gmt":"2026-03-31T18:47:44","guid":{"rendered":"https:\/\/www.jussimetso.com\/?p=3027"},"modified":"2026-03-31T21:50:54","modified_gmt":"2026-03-31T18:50:54","slug":"red-tenant-intro","status":"publish","type":"post","link":"https:\/\/www.jussimetso.com\/index.php\/2026\/03\/31\/red-tenant-intro\/","title":{"rendered":"Red Tenant intro"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div>\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3027\" class=\"elementor elementor-3027\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2fcedbf2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2fcedbf2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7c1dd053\" data-id=\"7c1dd053\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7a0db3eb elementor-widget elementor-widget-text-editor\" data-id=\"7a0db3eb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\n<h2 class=\"wp-block-heading\">Study of Red Tenant<\/h2>\n\n\n\n<p>From pure interest I started to study the thing called Red Tenant. What it is and why it is called Red Tenant.<\/p>\n\n\n\n<p>Red Tenant is not a Microsoft related product name.  There are companies which provide Managed Red Tenant -service but my interest is to clarify for myself what is needed to build the red one without selling it outside. Maybe later&#8230;.<\/p>\n\n\n\n<p>In practice, a \u201cRed Tenant\u201d usually means an isolated admin control plane. The common components are: a dedicated Entra tenant for admin identities, separate admin accounts from normal user accounts, hardened admin devices\/PAWs, strict Conditional Access, just-in-time role activation through Microsoft Entra Privileged Identity Management, monitoring\/auditing for privileged actions, and controlled ways to manage production tenants or on-premise Active Directory without letting compromise in the normal estate spread into the admin estate. <\/p>\n\n\n\n<p>Thought red tenant is not a Microsoft product I&#8217;ll will write it as it would be used with Microsoft products.<\/p>\n\n\n\n<p>This might go south but at least I have tried.  Here&#8217;s some architecture mockup. I&#8217;ll explain later what is included in each layer.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Core <\/li>\n\n\n\n<li>Identity layer<\/li>\n\n\n\n<li>Device layer<\/li>\n\n\n\n<li>Access policy layer<\/li>\n\n\n\n<li>Elevation and governance layer<\/li>\n\n\n\n<li>Monitoring and response layer<\/li>\n\n\n\n<li>Hybrid and Multi-tenant connections<\/li>\n<\/ol>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" data-recalc-dims=\"1\" height=\"627\" width=\"640\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=640%2C627&#038;ssl=1\" alt=\"\" class=\"wp-image-3031\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?w=1082&amp;ssl=1 1082w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=300%2C294&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=1024%2C1003&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=768%2C752&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=850%2C833&amp;ssl=1 850w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/figure>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-327fad2 elementor-widget elementor-widget-text-editor\" data-id=\"327fad2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Here was a very short intro to the Red tenant. I&#8217;ll be back soon.\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8eed7a7 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"8eed7a7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4ea3ee9b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4ea3ee9b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-771fd834\" data-id=\"771fd834\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-47fc11f6 elementor-widget elementor-widget-author-box\" data-id=\"47fc11f6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<div  class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2024\/07\/jussi_06_2024.jpg?fit=262%2C300&#038;ssl=1\" alt=\"Picture of Jussi Metso\" loading=\"lazy\">\n\t\t\t\t<\/div>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<div >\n\t\t\t\t\t\t<h6 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\tJussi Metso\t\t\t\t\t\t<\/h6>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future. <\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Study of Red Tenant From pure interest I started to study the thing called Red&#8230;<\/p>\n","protected":false},"author":1,"featured_media":3029,"comment_status":"open","ping_status":"open","sticky":false,"template":"elementor_theme","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[7],"tags":[61],"class_list":["post-3027","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-entraid-security-governance-management"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/redtenant.png?fit=347%2C241&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/pes24X-MP","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/comments?post=3027"}],"version-history":[{"count":4,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3027\/revisions"}],"predecessor-version":[{"id":3035,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3027\/revisions\/3035"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media\/3029"}],"wp:attachment":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media?parent=3027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/categories?post=3027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/tags?post=3027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}