{"id":3214,"date":"2026-08-30T15:44:47","date_gmt":"2026-08-30T12:44:47","guid":{"rendered":"https:\/\/www.jussimetso.com\/?p=3214"},"modified":"2026-08-30T15:47:54","modified_gmt":"2026-08-30T12:47:54","slug":"enterprise-access-model-eam-part-of-red-tenant-story","status":"publish","type":"post","link":"https:\/\/www.jussimetso.com\/index.php\/2026\/08\/30\/enterprise-access-model-eam-part-of-red-tenant-story\/","title":{"rendered":"Enterprise Access Model (EAM) &#8211; part of Red tenant story"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div>\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3214\" class=\"elementor elementor-3214\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9e8048b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9e8048b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-76b2ca1\" data-id=\"76b2ca1\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-948aa5b elementor-toc--minimized-on-tablet elementor-widget elementor-widget-table-of-contents\" data-id=\"948aa5b\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;headings_by_tags&quot;:[&quot;h2&quot;,&quot;h3&quot;,&quot;h4&quot;,&quot;h5&quot;],&quot;exclude_headings_by_selector&quot;:[],&quot;no_headings_message&quot;:&quot;No headings were found on this page.&quot;,&quot;marker_view&quot;:&quot;numbers&quot;,&quot;minimize_box&quot;:&quot;yes&quot;,&quot;minimized_on&quot;:&quot;tablet&quot;,&quot;hierarchical_view&quot;:&quot;yes&quot;,&quot;min_height&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"table-of-contents.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-toc__header\">\n\t\t\t\t\t\t<h4 class=\"elementor-toc__header-title\">\n\t\t\t\tTable of Contents\t\t\t<\/h4>\n\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-toc__toggle-button elementor-toc__toggle-button--expand\" role=\"button\" tabindex=\"0\" aria-controls=\"elementor-toc__948aa5b\" aria-expanded=\"true\" aria-label=\"Open table of contents\"><i aria-hidden=\"true\" class=\"fas fa-chevron-down\"><\/i><\/div>\n\t\t\t\t<div class=\"elementor-toc__toggle-button elementor-toc__toggle-button--collapse\" role=\"button\" tabindex=\"0\" aria-controls=\"elementor-toc__948aa5b\" aria-expanded=\"true\" aria-label=\"Close table of contents\"><i aria-hidden=\"true\" class=\"fas fa-chevron-up\"><\/i><\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<div id=\"elementor-toc__948aa5b\" class=\"elementor-toc__body\">\n\t\t\t<div class=\"elementor-toc__spinner-container\">\n\t\t\t\t<i class=\"elementor-toc__spinner eicon-animation-spin eicon-loading\" aria-hidden=\"true\"><\/i>\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6104486 elementor-widget elementor-widget-text-editor\" data-id=\"6104486\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The third part. I now assume that you have read the previous <a href=\"https:\/\/www.jussimetso.com\/index.php\/2026\/08\/07\/red-forest-the-predecessor-of-eam\/\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">post<\/span><\/a> which was about ESAE &#8211; Enhanced Security Administative Environment.<\/p><p>In the on-premises Active Directory world, Microsoft used to recommend the <i>Enhanced Security Administrative Environment<\/i> , a dedicated, hardened AD forest used only for administering your production forest. It was widely nicknamed the &#8220;Red Forest.&#8221; Microsoft has since retired ESAE\u00a0as a general recommendation, replacing it with a modern, identity-centric strategy. The &#8220;<strong>red<\/strong>&#8221; in &#8220;<strong>red tenant<\/strong>&#8221; is a descendant of this terminology.<\/p><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dceebf9 elementor-widget elementor-widget-heading\" data-id=\"dceebf9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The Enterprise Access Model and privileged-access strategy<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3be7ac4 elementor-widget elementor-widget-text-editor\" data-id=\"3be7ac4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This is Microsoft&#8217;s current guidance and the real substance. Its <span style=\"text-decoration: underline;\">core principles<\/span> are:<\/p><ul><li>Treating identity as the security perimeter rather than the network.<\/li><li>Tiering\/segmenting access by sensitivity (the classic Tier 0 \/ Tier 1 \/ Tier 2, now expressed as control plane \/ management plane \/ data-and-workload planes, with security levels of Privileged, Specialized, and Enterprise).<\/li><li>Using dedicated hardened devices: Privileged Access Workstations (PAWs) for admin work, so privileged accounts never touch a normal, internet-browsing endpoint.<\/li><li>Just-in-time elevation via Privileged Identity Management (PIM), strong Conditional Access, and Zero Trust throughout.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f68e109 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f68e109\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f5f4f1d\" data-id=\"f5f4f1d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-92a35eb elementor-widget elementor-widget-heading\" data-id=\"92a35eb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">The EAM tiering model<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8a3f1ff elementor-widget elementor-widget-text-editor\" data-id=\"8a3f1ff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-olk-copy-source=\"MessageBody\">The Enterprise Access Model (EAM) is Microsoft&#8217;s modern successor to the older Active Directory &#8220;tier model&#8221; (Tier 0 \/ Tier 1 \/ Tier 2). The original tiering idea was about containing credential theft: assets were sorted by the control they exert, with<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div data-olk-copy-source=\"MessageBody\"><strong>Tier 0<\/strong> holding the identity infrastructure that everything else depends on (domain controllers, AD, ADFS, PKI),<\/div><div data-olk-copy-source=\"MessageBody\"><strong>Tier 1<\/strong> holding servers and business-critical applications, and<\/div><div data-olk-copy-source=\"MessageBody\"><strong>Tier 2<\/strong> holding user workstations and the helpdesk that supports them.<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div data-olk-copy-source=\"MessageBody\">The governing rule was that a higher-tier credential must never be exposed on a lower-tier system. You never sign a Tier 0 admin account into a Tier 2 laptop, because a compromise of that laptop would then hand the attacker the keys to the identity fabric.<\/div><div>\u00a0<\/div><div>EAM keeps that containment principle but reframes it for a hybrid and cloud world where AD is no longer the center of gravity. Instead of tiers tied to on-prem domains, it organizes around\u00a0access planes:<\/div><div>\u00a0<\/div><div>a <strong>control <\/strong>plane (the modern equivalent of Tier 0 \u2014 identity systems and privileged access),<\/div><div>a <strong>management<\/strong> plane, and<\/div><div>the <strong>data\/workload<\/strong> plane where the actual apps and data live,<\/div><div>plus separate <strong>user-access<\/strong> and <strong>app-access<\/strong> paths.<\/div><div>\u00a0<\/div><div>The point of the reframing is to bring Entra ID, SaaS, and just-in-time privileged access in as first-class concerns rather than bolting them onto an AD-centric picture.<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2cfb0fa elementor-widget elementor-widget-image\" data-id=\"2cfb0fa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_eam.png?ssl=1\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"redt_eam\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6MzIyMCwidXJsIjoiaHR0cHM6XC9cL3d3dy5qdXNzaW1ldHNvLmNvbVwvd3AtY29udGVudFwvdXBsb2Fkc1wvMjAyNlwvMDhcL3JlZHRfZWFtLnBuZyJ9\">\n\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"640\" height=\"480\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_eam.png?fit=640%2C480&amp;ssl=1\" class=\"attachment-large size-large wp-image-3220\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_eam.png?w=1448&amp;ssl=1 1448w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_eam.png?resize=300%2C225&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_eam.png?resize=1024%2C768&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_eam.png?resize=768%2C576&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_eam.png?resize=850%2C638&amp;ssl=1 850w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_eam.png?w=1280&amp;ssl=1 1280w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">Copyright  of image Jussi Metso - Click to enlarge<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2542ec6 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"2542ec6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f8fbf46 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f8fbf46\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f1c21c7\" data-id=\"f1c21c7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-44d41e8 elementor-widget elementor-widget-heading\" data-id=\"44d41e8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">What a \"red tenant\" actually is in Entra ID and M365\/Azure terms<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8f8497e elementor-widget elementor-widget-text-editor\" data-id=\"8f8497e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-olk-copy-source=\"MessageBody\">The cloud-era version of the Red Forest idea is a\u00a0separate, dedicated Entra ID tenant used exclusively for privileged identities and their administrative endpoints, isolated from the production\/user tenant. In practice that means:<\/div><ul><li><b>Entra ID:<\/b>\u00a0admin accounts live in this isolated tenant rather than alongside regular users. They reach the production tenant(s) through controlled cross-tenant access (B2B), and the isolation limits lateral movement and privilege escalation if a normal user endpoint is compromised. Access is governed by Conditional Access, PIM, and often Global Secure Access (Entra Private Access \/ Internet Access) to restrict where those identities can connect.<\/li><li><b>M365\/Azure:<\/b> the admin infrastructure including PAWs (or virtual equivalents), policy baselines, and access rules are provisioned cloud-natively in M365\/Azure, frequently deployed and maintained &#8220;as code&#8221; so the whole hardened configuration is version-controlled and repeatable.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-db10de1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"db10de1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4225145\" data-id=\"4225145\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-87ed28b elementor-widget elementor-widget-heading\" data-id=\"87ed28b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Two tenant model:<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5799241 elementor-widget elementor-widget-heading\" data-id=\"5799241\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Isolated red admin tenant and cross-tenant access to Blue tenant<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e782a8d elementor-widget elementor-widget-text-editor\" data-id=\"e782a8d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-olk-copy-source=\"MessageBody\">An isolated admin tenant is a separate Entra ID tenant that houses\u00a0<strong>only<\/strong>\u00a0privileged administrative identities, kept apart from the production tenant where users and workloads live.<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div data-olk-copy-source=\"MessageBody\">The motivation is blast-radius reduction: the admin identities get their own Conditional Access, their own security baselines, and their own lifecycle, so a compromise of the production tenant doesn&#8217;t automatically expose the accounts that administer it (and vice versa).<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div data-olk-copy-source=\"MessageBody\">It&#8217;s the tenant-level expression of the same &#8220;don&#8217;t put your most powerful credentials where the most exposure is&#8221; idea. The obvious question that creates is if the admins live in tenant A, how do they administer resources in tenant B? That&#8217;s what cross-tenant access mechanisms handle.<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div data-olk-copy-source=\"MessageBody\">Entra ID&#8217;s cross-tenant access settings let the production tenant trust MFA and device-compliance claims coming from the admin tenant, so an admin arriving as an external\/B2B identity doesn&#8217;t have to re-satisfy MFA and <strong>importantly<\/strong> you can require that the access originates from a compliant, hardened device.<\/div><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-222233e elementor-widget elementor-widget-image\" data-id=\"222233e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?ssl=1\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"eam_twotenant_security_bridge_model\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6MzI1MywidXJsIjoiaHR0cHM6XC9cL3d3dy5qdXNzaW1ldHNvLmNvbVwvd3AtY29udGVudFwvdXBsb2Fkc1wvMjAyNlwvMDhcL2VhbV90d290ZW5hbnRfc2VjdXJpdHlfYnJpZGdlX21vZGVsLnBuZyJ9\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"640\" height=\"360\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?fit=640%2C360&amp;ssl=1\" class=\"attachment-large size-large wp-image-3253\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?w=1672&amp;ssl=1 1672w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?resize=300%2C169&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?resize=1024%2C576&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?resize=768%2C432&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?resize=1536%2C864&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?resize=850%2C478&amp;ssl=1 850w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_twotenant_security_bridge_model.png?w=1280&amp;ssl=1 1280w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">Copyright  of image  Jussi Metso - Click to enlarge<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5f35cd0 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"5f35cd0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-aabaad7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"aabaad7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8ed4bc2\" data-id=\"8ed4bc2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-252d995 elementor-widget elementor-widget-heading\" data-id=\"252d995\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">The Bridge controls: PIM and Conditional Access<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b41f737 elementor-widget elementor-widget-text-editor\" data-id=\"b41f737\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div><b>Privileged Identity Management (PIM)<\/b>\u00a0attacks the problem of standing privilege. Rather than an account permanently holding an admin role, the role is made\u00a0<i>eligible<\/i>\u00a0and must be activated just-in-time for a limited window, typically requiring justification, MFA, and sometimes approval, with everything logged. That shrinks the amount of always-on privilege an attacker could steal.\u00a0<\/div><div>\u00a0<\/div><div><b>Conditional Access<\/b> is the policy engine that ties it together by gating access on signals:<\/div><div>*device compliance,<\/div><div>*user or sign-in risk,<\/div><div>*location,<\/div><div>*role,<\/div><div>so you can enforce, for example, that a privileged role can only be activated from a compliant PAW using phishing-resistant MFA.<\/div><div>\u00a0<\/div><div>Putting together, the pattern is:<\/div><div>*just-in-time privilege (PIM),<\/div><div>*exercised from a hardened origin device (PAW) and<\/div><div>*gated by policy (Conditional Access).<\/div><div>\u00a0<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-477025a elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"477025a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4509175 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4509175\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7a609d0\" data-id=\"7a609d0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e1726c5 elementor-widget elementor-widget-heading\" data-id=\"e1726c5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Summary<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6eca0c9 elementor-widget elementor-widget-text-editor\" data-id=\"6eca0c9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Here was Enterprise Access Model explained shortly. The next post is about PAW, PIM and Condition access.\u00a0<\/p><p>What does they mean, why the setup is secure and why it could be also insecure if some of the component(s) is\/are missing.<\/p><p><strong>Links:<\/strong><\/p><p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-access-model\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Enterprise Access Model (MS Learn)<\/span><\/a><\/p><p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/zero-trust\/security-adoption-discipline-identity-access-enterprise-model\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Design and Enterprise access architecture (MS Learn)<\/span><\/a><\/p><p id=\"design-a-privileged-access-architecture\"><span style=\"text-decoration: underline;\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/zero-trust\/security-adoption-discipline-identity-access-privileged-model\" target=\"_blank\" rel=\"noopener\">Design a privileged access architecture (MS Learn)<\/a><\/span><\/p><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f7c07d4 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"f7c07d4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5569a3c8 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5569a3c8\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2d3f486f\" data-id=\"2d3f486f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3bf79b97 elementor-widget elementor-widget-author-box\" data-id=\"3bf79b97\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<div  class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2024\/07\/jussi_06_2024.jpg?fit=262%2C300&#038;ssl=1\" alt=\"Picture of Jussi Metso\" loading=\"lazy\">\n\t\t\t\t<\/div>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<div >\n\t\t\t\t\t\t<h6 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\tJussi Metso\t\t\t\t\t\t<\/h6>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future. <\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Privileged access strategy is part of an overall enterprise access control strategy. This enterprise access model shows how privileged access fits into an overall enterprise access model.<\/p>\n","protected":false},"author":1,"featured_media":3029,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"elementor_theme","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"The Red tenant: Enterprise Access Model (EAM)","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[72,71],"tags":[70,73],"class_list":["post-3214","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity_access","category-red","tag-redtenant","tag-identityaccess"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pes24X-PQ","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/redtenant.png?fit=347%2C241&ssl=1","_links":{"self":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3214","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/comments?post=3214"}],"version-history":[{"count":24,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3214\/revisions"}],"predecessor-version":[{"id":3280,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3214\/revisions\/3280"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media\/3029"}],"wp:attachment":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media?parent=3214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/categories?post=3214"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/tags?post=3214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}