{"id":3265,"date":"2026-09-06T09:15:00","date_gmt":"2026-09-06T06:15:00","guid":{"rendered":"https:\/\/www.jussimetso.com\/?p=3265"},"modified":"2026-09-05T14:47:36","modified_gmt":"2026-09-05T11:47:36","slug":"the-paw-pim-and-the-conditional-access-setup-and-some-entra-id-attack-vectors","status":"publish","type":"post","link":"https:\/\/www.jussimetso.com\/index.php\/2026\/09\/06\/the-paw-pim-and-the-conditional-access-setup-and-some-entra-id-attack-vectors\/","title":{"rendered":"The PAW, PIM and the Conditional Access setup and some Entra ID attack vectors"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div>\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3265\" class=\"elementor elementor-3265\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-783669d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"783669d\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5c712d8\" data-id=\"5c712d8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a261db0 elementor-toc--minimized-on-tablet elementor-widget elementor-widget-table-of-contents\" data-id=\"a261db0\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;headings_by_tags&quot;:[&quot;h2&quot;,&quot;h3&quot;,&quot;h4&quot;,&quot;h5&quot;],&quot;exclude_headings_by_selector&quot;:[],&quot;no_headings_message&quot;:&quot;No headings were found on this page.&quot;,&quot;marker_view&quot;:&quot;numbers&quot;,&quot;minimize_box&quot;:&quot;yes&quot;,&quot;minimized_on&quot;:&quot;tablet&quot;,&quot;hierarchical_view&quot;:&quot;yes&quot;,&quot;min_height&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"table-of-contents.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-toc__header\">\n\t\t\t\t\t\t<h4 class=\"elementor-toc__header-title\">\n\t\t\t\tTable of Contents\t\t\t<\/h4>\n\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-toc__toggle-button elementor-toc__toggle-button--expand\" role=\"button\" tabindex=\"0\" aria-controls=\"elementor-toc__a261db0\" aria-expanded=\"true\" aria-label=\"Open table of contents\"><i aria-hidden=\"true\" class=\"fas fa-chevron-down\"><\/i><\/div>\n\t\t\t\t<div class=\"elementor-toc__toggle-button elementor-toc__toggle-button--collapse\" role=\"button\" tabindex=\"0\" aria-controls=\"elementor-toc__a261db0\" aria-expanded=\"true\" aria-label=\"Close table of contents\"><i aria-hidden=\"true\" class=\"fas fa-chevron-up\"><\/i><\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<div id=\"elementor-toc__a261db0\" class=\"elementor-toc__body\">\n\t\t\t<div class=\"elementor-toc__spinner-container\">\n\t\t\t\t<i class=\"elementor-toc__spinner eicon-animation-spin eicon-loading\" aria-hidden=\"true\"><\/i>\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d58bb6f elementor-widget elementor-widget-text-editor\" data-id=\"d58bb6f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>My previous <a href=\"https:\/\/www.jussimetso.com\/index.php\/2026\/08\/30\/enterprise-access-model-eam-part-of-red-tenant-story\/\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">post<\/span><\/a> was about Microsoft Enterprise Access Model (EAM) and the last section handled the two tenant model with bridge controls PIM and CA policies.\u00a0<\/p><p>I will shortly continue this. What is idea of PAW, PIM and CA setup.<\/p><p data-start=\"8718\" data-end=\"8893\" data-is-last-node=\"\" data-is-only-node=\"\">This got little longer than I first thought because I added some MITRE ATT&amp;CK Tactics &amp; Techniques. Anyway I hope this some insight for someone.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6a974a9 elementor-widget elementor-widget-image\" data-id=\"6a974a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"640\" height=\"500\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca.png?fit=640%2C500&amp;ssl=1\" class=\"attachment-large size-large wp-image-3270\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca.png?w=1044&amp;ssl=1 1044w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca.png?resize=300%2C234&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca.png?resize=1024%2C800&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca.png?resize=768%2C600&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca.png?resize=850%2C664&amp;ssl=1 850w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-aee0ca1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"aee0ca1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7a73f07\" data-id=\"7a73f07\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f828d74 elementor-widget elementor-widget-text-editor\" data-id=\"f828d74\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-olk-copy-source=\"MessageBody\">A\u00a0<b>Privileged Access Workstation, PAW (Inside the Red Tenant box)<\/b>\u00a0is a hardened, dedicated device used\u00a0<i>only<\/i> for administrative work, deliberately separated from the user&#8217;s everyday machine that browses the web and reads email, the two biggest infection vectors. It follows the &#8220;clean source&#8221; principle:<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div data-olk-copy-source=\"MessageBody\">you should administer a secure system only from a system that is at least as secure, so PAWs are tightly locked down with application allowlisting, no general internet access, and strict managed baselines.<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div><b>Privileged Identity Management (PIM)<\/b>\u00a0attacks the problem of standing privilege. Rather than an account permanently holding an admin role, the role is made\u00a0<i>eligible<\/i>\u00a0and must be activated just-in-time for a limited window, typically requiring justification, MFA, and sometimes approval, with everything logged. That shrinks the amount of always-on privilege an attacker could steal.\u00a0<\/div><div>\u00a0<\/div><div><b>Conditional Access<\/b> is the policy engine that ties it together by gating access on signals:<\/div><div>*device compliance,<\/div><div>*user or sign-in risk,<\/div><div>*location,<\/div><div>*role,<\/div><div>so you can enforce, for example, that a privileged role can only be activated from a compliant PAW using phishing-resistant MFA.<\/div><div>\u00a0<\/div><div>Putting together, the pattern is:<\/div><div>*just-in-time privilege (PIM),<\/div><div>*exercised from a hardened origin device (PAW) and<\/div><div>*gated by policy (Conditional Access).<\/div><div>\u00a0<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c1402d elementor-widget elementor-widget-image\" data-id=\"7c1402d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca_setup.png?ssl=1\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"eam_paw_pim_ca_setup\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6MzI1NywidXJsIjoiaHR0cHM6XC9cL3d3dy5qdXNzaW1ldHNvLmNvbVwvd3AtY29udGVudFwvdXBsb2Fkc1wvMjAyNlwvMDhcL2VhbV9wYXdfcGltX2NhX3NldHVwLnBuZyJ9\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"640\" height=\"480\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca_setup.png?fit=640%2C480&amp;ssl=1\" class=\"attachment-large size-large wp-image-3257\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca_setup.png?w=1448&amp;ssl=1 1448w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca_setup.png?resize=300%2C225&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca_setup.png?resize=1024%2C768&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca_setup.png?resize=768%2C576&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca_setup.png?resize=850%2C638&amp;ssl=1 850w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/eam_paw_pim_ca_setup.png?w=1280&amp;ssl=1 1280w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6baa1a7 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"6baa1a7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-25da127 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"25da127\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1346d9a\" data-id=\"1346d9a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4f74e72 elementor-widget elementor-widget-heading\" data-id=\"4f74e72\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What does this mean?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ceb2568 elementor-widget elementor-widget-text-editor\" data-id=\"ceb2568\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"157\" data-end=\"232\">This setup is designed to make <strong data-start=\"188\" data-end=\"218\">administrator access safer<\/strong> by combining:<\/p><ul data-start=\"234\" data-end=\"405\"><li data-section-id=\"2z9cbb\" data-start=\"234\" data-end=\"277\"><strong data-start=\"236\" data-end=\"243\">PAW<\/strong> = Privileged Access Workstation<\/li><li data-section-id=\"hwblcv\" data-start=\"278\" data-end=\"322\"><strong data-start=\"280\" data-end=\"287\">PIM<\/strong> = Privileged Identity Management<\/li><li data-section-id=\"y95fjn\" data-start=\"323\" data-end=\"405\"><strong data-start=\"325\" data-end=\"347\">Conditional Access<\/strong> = policies that control how and when sign-in is allowed<\/li><\/ul><p data-start=\"407\" data-end=\"426\">The idea is simple:<\/p><blockquote data-start=\"428\" data-end=\"582\"><p data-start=\"430\" data-end=\"582\">An admin should only perform privileged work from a secure device, under strict sign-in controls, and only receive admin rights temporarily when needed.<\/p><\/blockquote>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1fa44a8 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1fa44a8\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e373b92\" data-id=\"e373b92\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-850a182 elementor-widget elementor-widget-heading\" data-id=\"850a182\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">The administrator starts with a dedicated admin account<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-119054a elementor-widget elementor-widget-text-editor\" data-id=\"119054a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"651\" data-end=\"713\">The admin has a privileged identity in <strong data-start=\"690\" data-end=\"712\">Microsoft Entra ID<\/strong>.<\/p><p data-start=\"715\" data-end=\"740\">Best practice is usually:<\/p><ul data-start=\"741\" data-end=\"841\"><li data-section-id=\"1b7actq\" data-start=\"741\" data-end=\"789\">a normal user account for email and daily work<\/li><li data-section-id=\"8whq0s\" data-start=\"790\" data-end=\"841\">a separate <strong data-start=\"803\" data-end=\"820\">admin account<\/strong> for privileged tasks<\/li><\/ul><p data-start=\"843\" data-end=\"935\">This reduces the chance that a compromise of the normal account gives away admin privileges.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4446511 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4446511\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-35adec7\" data-id=\"35adec7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-69d7629 elementor-widget elementor-widget-heading\" data-id=\"69d7629\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">The admin signs in from a PAW<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ea4e5d5 elementor-widget elementor-widget-text-editor\" data-id=\"ea4e5d5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-section-id=\"9xeie5\" data-start=\"589\" data-end=\"650\">\u00a0A <strong data-start=\"980\" data-end=\"1019\">PAW (Privileged Access Workstation)<\/strong> is a dedicated, hardened device used only for admin work.<\/p><p data-start=\"1079\" data-end=\"1107\">Typical PAW characteristics:<\/p><ul data-start=\"1108\" data-end=\"1246\"><li data-section-id=\"61vz9v\" data-start=\"1108\" data-end=\"1135\">managed and secured by IT<\/li><li data-section-id=\"1tfndr6\" data-start=\"1136\" data-end=\"1175\">not used for casual browsing or email<\/li><li data-section-id=\"skcvq2\" data-start=\"1176\" data-end=\"1197\">restricted software<\/li><li data-section-id=\"orswm3\" data-start=\"1198\" data-end=\"1226\">strong endpoint protection<\/li><li data-section-id=\"3inu5i\" data-start=\"1227\" data-end=\"1246\">monitored closely<\/li><\/ul><p data-start=\"1248\" data-end=\"1390\"><strong>Why this matters:<\/strong><br \/>If admins use their everyday laptop for privileged work, malware or phishing on that laptop could capture admin credentials.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a198432 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a198432\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-85e2cf2\" data-id=\"85e2cf2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-40a8d91 elementor-widget elementor-widget-heading\" data-id=\"40a8d91\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">\u00a0Conditional Access checks whether sign-in is allowed<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-253eb9b elementor-widget elementor-widget-text-editor\" data-id=\"253eb9b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"1456\" data-end=\"1527\">Before access is granted, <strong data-start=\"1482\" data-end=\"1504\">Conditional Access<\/strong> evaluates the sign-in.<\/p><p data-start=\"1529\" data-end=\"1552\">Typical checks include:<\/p><ul data-start=\"1553\" data-end=\"1773\"><li data-section-id=\"1psslrl\" data-start=\"1553\" data-end=\"1574\"><strong data-start=\"1555\" data-end=\"1574\">MFA is required<\/strong><\/li><li data-section-id=\"8y5dj4\" data-start=\"1575\" data-end=\"1621\">the device must be <strong data-start=\"1596\" data-end=\"1609\">compliant<\/strong> and trusted<\/li><li data-section-id=\"1ym55oz\" data-start=\"1622\" data-end=\"1665\">the device should be the approved <strong data-start=\"1658\" data-end=\"1665\">PAW<\/strong><\/li><li data-section-id=\"1x1z9nw\" data-start=\"1666\" data-end=\"1722\">optional checks for sign-in risk, location, or network<\/li><li data-section-id=\"m67do6\" data-start=\"1723\" data-end=\"1773\">block access from unmanaged or non-admin devices<\/li><\/ul><p data-start=\"1775\" data-end=\"1827\">So Conditional Access acts like a <strong data-start=\"1809\" data-end=\"1826\">security gate<\/strong>:<\/p><ul data-start=\"1828\" data-end=\"1932\"><li data-section-id=\"vgbdf9\" data-start=\"1828\" data-end=\"1904\">if the admin is on the right device and completes MFA, access can continue<\/li><li data-section-id=\"7u4s08\" data-start=\"1905\" data-end=\"1932\">if not, access is blocked<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e3a56fd elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e3a56fd\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f09d620\" data-id=\"f09d620\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-de49cf2 elementor-widget elementor-widget-heading\" data-id=\"de49cf2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Entra ID authenticates the admin<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e6256c4 elementor-widget elementor-widget-text-editor\" data-id=\"e6256c4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"1978\" data-end=\"2068\">Once the sign-in passes Conditional Access, <strong data-start=\"2022\" data-end=\"2044\">Microsoft Entra ID<\/strong> authenticates the user.<\/p><p data-start=\"2070\" data-end=\"2165\">At this point, the admin is signed in, but they may still <strong data-start=\"2128\" data-end=\"2164\">not yet have active admin rights<\/strong>.<\/p><p data-start=\"2167\" data-end=\"2197\">That\u2019s where <strong data-start=\"2180\" data-end=\"2187\">PIM<\/strong> comes in.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-d5bc922 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d5bc922\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-68b15d5\" data-id=\"68b15d5\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a429c95 elementor-widget elementor-widget-heading\" data-id=\"a429c95\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">PIM gives admin rights only when needed<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ea596a9 elementor-widget elementor-widget-text-editor\" data-id=\"ea596a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"2250\" data-end=\"2348\">With <strong data-start=\"2255\" data-end=\"2295\">Privileged Identity Management (PIM)<\/strong>, the admin does not permanently hold powerful roles.<\/p><p data-start=\"2350\" data-end=\"2410\">Instead, the admin is made <strong data-start=\"2377\" data-end=\"2389\">eligible<\/strong> for a role, such as:<\/p><ul data-start=\"2411\" data-end=\"2549\"><li data-section-id=\"allmc8\" data-start=\"2411\" data-end=\"2433\">Global Administrator<\/li><li data-section-id=\"1vx8g4c\" data-start=\"2434\" data-end=\"2465\">Privileged Role Administrator<\/li><li data-section-id=\"1fjmd0h\" data-start=\"2466\" data-end=\"2498\">Azure Subscription Contributor<\/li><li data-section-id=\"1tgdkx4\" data-start=\"2499\" data-end=\"2523\">Exchange Administrator<\/li><li data-section-id=\"po7b9o\" data-start=\"2524\" data-end=\"2549\">another privileged role<\/li><\/ul><p data-start=\"2551\" data-end=\"2613\">When the admin needs to do a task, they <strong data-start=\"2591\" data-end=\"2603\">activate<\/strong> the role.<\/p><p data-start=\"2615\" data-end=\"2641\">Activation often requires:<\/p><ul data-start=\"2642\" data-end=\"2722\"><li data-section-id=\"1uj1nky\" data-start=\"2642\" data-end=\"2653\">MFA again<\/li><li data-section-id=\"1ovjzc\" data-start=\"2654\" data-end=\"2669\">justification<\/li><li data-section-id=\"xoebtb\" data-start=\"2670\" data-end=\"2685\">ticket number<\/li><li data-section-id=\"1ncrhvz\" data-start=\"2686\" data-end=\"2696\">approval<\/li><li data-section-id=\"lnihgd\" data-start=\"2697\" data-end=\"2722\">limited activation time<\/li><\/ul><p data-start=\"2724\" data-end=\"2766\">This is called <strong data-start=\"2739\" data-end=\"2765\">just-in-time elevation<\/strong>.<\/p><p data-start=\"2768\" data-end=\"2851\">So instead of having permanent access all day, the admin only gets elevated rights:<\/p><ul data-start=\"2852\" data-end=\"2912\"><li data-section-id=\"1mu986u\" data-start=\"2852\" data-end=\"2875\">for a specific reason<\/li><li data-section-id=\"820n0j\" data-start=\"2876\" data-end=\"2898\">for a limited period<\/li><li data-section-id=\"8f1egd\" data-start=\"2899\" data-end=\"2912\">under audit<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4c1408b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4c1408b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-64d80d2\" data-id=\"64d80d2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-01a17d8 elementor-widget elementor-widget-heading\" data-id=\"01a17d8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">The admin accesses protected targets<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0e50c8a elementor-widget elementor-widget-text-editor\" data-id=\"0e50c8a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"2962\" data-end=\"3050\">After the privileged role is activated, the admin can work on protected systems such as:<\/p><ul data-start=\"3052\" data-end=\"3211\"><li data-section-id=\"nr9i3n\" data-start=\"3052\" data-end=\"3092\"><strong data-start=\"3054\" data-end=\"3092\">Azure Portal \/ Azure subscriptions<\/strong><\/li><li data-section-id=\"1a8cmwr\" data-start=\"3093\" data-end=\"3126\"><strong data-start=\"3095\" data-end=\"3126\">Microsoft 365 admin centers<\/strong><\/li><li data-section-id=\"1e6ngxs\" data-start=\"3127\" data-end=\"3151\"><strong data-start=\"3129\" data-end=\"3151\">Entra admin center<\/strong><\/li><li data-section-id=\"5xlk01\" data-start=\"3152\" data-end=\"3173\"><strong data-start=\"3154\" data-end=\"3173\">privileged apps<\/strong><\/li><li data-section-id=\"1jhm9y4\" data-start=\"3174\" data-end=\"3211\"><strong data-start=\"3176\" data-end=\"3211\">servers or management platforms<\/strong><\/li><\/ul><p data-start=\"3213\" data-end=\"3230\"><strong>The key point is:<\/strong><\/p><blockquote data-start=\"3232\" data-end=\"3375\"><p data-start=\"3234\" data-end=\"3375\">Access to these admin targets happens only after the person used a secure PAW, passed Conditional Access, and activated the role through PIM.<\/p><\/blockquote><p data-section-id=\"1uzpvyl\" data-start=\"3670\" data-end=\"3703\"><strong>End-to-end flow in one sentence<\/strong><\/p><p data-start=\"3705\" data-end=\"3932\">A privileged user signs in from a hardened <strong data-start=\"3748\" data-end=\"3755\">PAW<\/strong>, passes <strong data-start=\"3764\" data-end=\"3786\">Conditional Access<\/strong> checks like MFA and device compliance, then uses <strong data-start=\"3836\" data-end=\"3843\">PIM<\/strong> to temporarily activate an admin role, and only then accesses sensitive admin resources.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7049d40 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"7049d40\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e133cc9 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e133cc9\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b3b7475\" data-id=\"b3b7475\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-44afdc5 elementor-widget elementor-widget-heading\" data-id=\"44afdc5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Why this is secure<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-802d664 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"802d664\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fa33822\" data-id=\"fa33822\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5ef67ef elementor-widget elementor-widget-heading\" data-id=\"5ef67ef\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">PAW reduces credential theft<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4a518a4 elementor-widget elementor-widget-text-editor\" data-id=\"4a518a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Admin credentials are only used on a hardened device, which lowers the risk of them being stolen by malware or phishing.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-410b011 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"410b011\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-acf7124\" data-id=\"acf7124\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f64f871 elementor-widget elementor-widget-heading\" data-id=\"f64f871\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Conditional Access enforces policy<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2e0aff1 elementor-widget elementor-widget-text-editor\" data-id=\"2e0aff1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Only approved devices, trusted conditions, and MFA-backed sign-ins are allowed.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e78ce86 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e78ce86\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2d76868\" data-id=\"2d76868\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-73d2467 elementor-widget elementor-widget-heading\" data-id=\"73d2467\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">PIM enforces least privilege<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f8701ea elementor-widget elementor-widget-text-editor\" data-id=\"f8701ea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Admins do not have permanent high privilege. They only elevate when necessary.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-144ad30 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"144ad30\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-bc86860\" data-id=\"bc86860\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-211dcac elementor-widget elementor-widget-heading\" data-id=\"211dcac\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Time-limited admin access reduces exposure<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5df874c elementor-widget elementor-widget-text-editor\" data-id=\"5df874c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Even if an attacker got access later, the privileged role may already be gone.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2770a03 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2770a03\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-47be8c8\" data-id=\"47be8c8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8041cf2 elementor-widget elementor-widget-heading\" data-id=\"8041cf2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Auditing is improved<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f0f83d3 elementor-widget elementor-widget-text-editor\" data-id=\"f0f83d3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"4496\" data-end=\"4564\">PIM activations and sign-ins are logged, making it easier to review:<\/p><ul data-start=\"4565\" data-end=\"4647\"><li data-section-id=\"145byba\" data-start=\"4565\" data-end=\"4579\">who elevated<\/li><li data-section-id=\"1rma36\" data-start=\"4580\" data-end=\"4600\">when they elevated<\/li><li data-section-id=\"1werun4\" data-start=\"4601\" data-end=\"4620\">why they elevated<\/li><li data-section-id=\"ok5mr8\" data-start=\"4621\" data-end=\"4647\">what approvals were used<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7b899fb elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7b899fb\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-017d0ab\" data-id=\"017d0ab\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a0b55d0 elementor-widget elementor-widget-heading\" data-id=\"a0b55d0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">A practical example<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fc33540 elementor-widget elementor-widget-text-editor\" data-id=\"fc33540\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Imagine an Azure admin needs to change access on a production subscription.<\/p><p data-section-id=\"1yav5c3\" data-start=\"4754\" data-end=\"4776\"><strong>Without this model<\/strong><\/p><p data-start=\"4777\" data-end=\"4858\">They may log in from their normal laptop and keep permanent admin rights all day.<\/p><p data-section-id=\"1oyebyl\" data-start=\"4860\" data-end=\"4879\"><strong>With this model<\/strong><\/p><ol data-start=\"4880\" data-end=\"5142\"><li data-section-id=\"1aktnh9\" data-start=\"4880\" data-end=\"4905\">They use their <strong data-start=\"4898\" data-end=\"4905\">PAW<\/strong><\/li><li data-section-id=\"mp4lc5\" data-start=\"4906\" data-end=\"4934\">They sign in with <strong data-start=\"4927\" data-end=\"4934\">MFA<\/strong><\/li><li data-section-id=\"3xoa2x\" data-start=\"4935\" data-end=\"4990\"><strong data-start=\"4938\" data-end=\"4960\">Conditional Access<\/strong> confirms the PAW is compliant<\/li><li data-section-id=\"f8149r\" data-start=\"4991\" data-end=\"5011\">They open <strong data-start=\"5004\" data-end=\"5011\">PIM<\/strong><\/li><li data-section-id=\"gefija\" data-start=\"5012\" data-end=\"5073\">They activate the needed Azure admin role for, say, 1 hour<\/li><li data-section-id=\"za5glc\" data-start=\"5074\" data-end=\"5097\">They make the change<\/li><li data-section-id=\"1lgd0zz\" data-start=\"5098\" data-end=\"5142\">The privileged role expires automatically<\/li><\/ol><p data-start=\"5144\" data-end=\"5163\">That is much safer.<\/p><h3 class=\"PDq2pG_selectionAnchorContainer\" data-section-id=\"a4ge5v\" data-start=\"5170\" data-end=\"5180\">In short<\/h3><p data-start=\"5182\" data-end=\"5225\">This setup works by combining three layers:<\/p><ul data-start=\"5227\" data-end=\"5425\"><li data-section-id=\"1tcw22y\" data-start=\"5227\" data-end=\"5273\"><strong data-start=\"5229\" data-end=\"5236\">PAW<\/strong> \u2192 secure device for admin activity<\/li><li data-section-id=\"xg962z\" data-start=\"5274\" data-end=\"5354\"><strong data-start=\"5276\" data-end=\"5298\">Conditional Access<\/strong> \u2192 allows admin sign-in only under approved conditions<\/li><li data-section-id=\"5ua6uu\" data-start=\"5355\" data-end=\"5425\"><strong data-start=\"5357\" data-end=\"5364\">PIM<\/strong> \u2192 gives admin rights only temporarily and only when needed<\/li><\/ul><p data-start=\"5427\" data-end=\"5447\"><strong>Together, they help:<\/strong><\/p><ul data-start=\"5448\" data-end=\"5554\"><li data-section-id=\"zk4h9s\" data-start=\"5448\" data-end=\"5476\">reduce credential exposure<\/li><li data-section-id=\"15pucbi\" data-start=\"5477\" data-end=\"5505\">block risky admin sign-ins<\/li><li data-section-id=\"oxmo8e\" data-start=\"5506\" data-end=\"5531\">enforce least privilege<\/li><li data-section-id=\"18p18l9\" data-start=\"5532\" data-end=\"5554\">improve auditability<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d74201c elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"d74201c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-40b461a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"40b461a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-22f2949\" data-id=\"22f2949\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3efab20 elementor-widget elementor-widget-heading\" data-id=\"3efab20\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Insecurities without these<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c334e5b elementor-widget elementor-widget-text-editor\" data-id=\"c334e5b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"0\" data-end=\"327\">Without PAW, PIM, and Conditional Access, the main problem is that <strong data-start=\"67\" data-end=\"152\">privileged access becomes easier to steal, easier to reuse, and harder to contain<\/strong>. The attacker does not necessarily need to \u201chack M356\/Azure\u201d directly, they can compromise an administrator, their device, or their session and inherit the administrator\u2019s access.<\/p><p data-start=\"329\" data-end=\"363\">A useful way to think about it is:<\/p><div class=\"group TyagGW_tableContainer\"><div class=\"TyagGW_tableWrapper flex flex-col-reverse w-fit\" tabindex=\"-1\"><table class=\"w-fit min-w-(--thread-content-width)\" data-start=\"365\" data-end=\"868\"><thead data-start=\"365\" data-end=\"435\"><tr data-start=\"365\" data-end=\"435\"><th class=\"last:pe-10\" data-start=\"365\" data-end=\"383\" data-col-size=\"sm\">Missing control<\/th><th class=\"last:pe-10\" data-start=\"383\" data-end=\"403\" data-col-size=\"md\">Security weakness<\/th><th class=\"last:pe-10\" data-start=\"403\" data-end=\"435\" data-col-size=\"md\">Typical attacker opportunity<\/th><\/tr><\/thead><tbody data-start=\"450\" data-end=\"868\"><tr data-start=\"450\" data-end=\"576\"><td data-start=\"450\" data-end=\"463\" data-col-size=\"sm\"><strong data-start=\"452\" data-end=\"462\">No PAW<\/strong><\/td><td data-col-size=\"md\" data-start=\"463\" data-end=\"514\">Admin credentials are used on ordinary endpoints<\/td><td data-col-size=\"md\" data-start=\"514\" data-end=\"576\">Phishing, malware, credential dumping, token\/session theft<\/td><\/tr><tr data-start=\"577\" data-end=\"691\"><td data-start=\"577\" data-end=\"590\" data-col-size=\"sm\"><strong data-start=\"579\" data-end=\"589\">No PIM<\/strong><\/td><td data-col-size=\"md\" data-start=\"590\" data-end=\"635\">Powerful roles remain permanently assigned<\/td><td data-col-size=\"md\" data-start=\"635\" data-end=\"691\">Compromised account immediately has admin privileges<\/td><\/tr><tr data-start=\"692\" data-end=\"868\"><td data-start=\"692\" data-end=\"720\" data-col-size=\"sm\"><strong data-start=\"694\" data-end=\"719\">No Conditional Access<\/strong><\/td><td data-col-size=\"md\" data-start=\"720\" data-end=\"801\">Sign-ins are not sufficiently constrained by device, MFA, risk, location, etc.<\/td><td data-col-size=\"md\" data-start=\"801\" data-end=\"868\">Stolen credentials can be used from attacker-controlled devices<\/td><\/tr><\/tbody><\/table><\/div><\/div><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6b2e0b3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6b2e0b3\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c1afd4b\" data-id=\"c1afd4b\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-37f9234 elementor-widget elementor-widget-heading\" data-id=\"37f9234\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Without PAW the administrator's workstation becomes an attack path<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0b23e95 elementor-widget elementor-widget-text-editor\" data-id=\"0b23e95\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"946\" data-end=\"1118\">If an administrator performs privileged work from the same laptop used for email, web browsing, Teams, downloads, and normal office work, the attack surface is much larger.<\/p><p data-start=\"1120\" data-end=\"1405\">An attacker may use phishing or malicious attachments to compromise the workstation. Once they have code running on that endpoint, they can potentially target cached credentials, browser sessions, authentication tokens, management tools, PowerShell sessions, or administrator activity.<\/p><p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"1407\" data-end=\"1448\">A common attack chain looks roughly like:<\/p><p data-start=\"1450\" data-end=\"1566\"><strong data-start=\"1450\" data-end=\"1566\">Phishing \u2192 user workstation compromise \u2192 wait for admin login \u2192 steal credential\/session \u2192 use privileged access<\/strong><\/p><p data-start=\"1568\" data-end=\"1767\">This is one of the reasons privileged workstations exist: they try to prevent a low-trust activity such as reading email from sharing the same security boundary as high-trust administrative activity.<\/p><p data-start=\"1769\" data-end=\"1802\">Potential attack vectors include:<\/p><ul data-start=\"1804\" data-end=\"2110\"><li data-section-id=\"1lrffk\" data-start=\"1804\" data-end=\"1833\">credential-stealing malware<\/li><li data-section-id=\"12tj3ag\" data-start=\"1834\" data-end=\"1863\">browser\/session-token theft<\/li><li data-section-id=\"13ornfo\" data-start=\"1864\" data-end=\"1894\">malicious browser extensions<\/li><li data-section-id=\"1wcmjep\" data-start=\"1895\" data-end=\"1943\">credential dumping from a compromised endpoint<\/li><li data-section-id=\"dj396k\" data-start=\"1944\" data-end=\"1956\">keylogging<\/li><li data-section-id=\"y4yykh\" data-start=\"1957\" data-end=\"1991\">adversary-in-the-middle phishing<\/li><li data-section-id=\"90l8ji\" data-start=\"1992\" data-end=\"2020\">malicious Office documents<\/li><li data-section-id=\"1sjf14l\" data-start=\"2021\" data-end=\"2041\">drive-by downloads<\/li><li data-section-id=\"1b4db9g\" data-start=\"2042\" data-end=\"2065\">remote-access malware<\/li><li data-section-id=\"8xdbyl\" data-start=\"2066\" data-end=\"2110\">abuse of cached administrative credentials<\/li><\/ul><p data-start=\"2112\" data-end=\"2315\">The important architectural issue is <strong data-start=\"2149\" data-end=\"2172\">credential exposure<\/strong>. A Tier 0 \/ control-plane credential should not appear on a workstation that attackers can reasonably compromise through normal user activity.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0ad3fcd elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"0ad3fcd\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2a38a76\" data-id=\"2a38a76\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-abb0cc8 elementor-widget elementor-widget-heading\" data-id=\"abb0cc8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Without PIM compromise can immediately become privileged compromise<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7b10fcf elementor-widget elementor-widget-text-editor\" data-id=\"7b10fcf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"2394\" data-end=\"2502\">Suppose an account has permanent Global Administrator, Privileged Role Administrator, or Azure Owner rights.<\/p><p data-start=\"2504\" data-end=\"2676\">If the attacker obtains that account or its active session, there is no additional privilege boundary to cross. The attacker already possesses the administrative authority.<\/p><p data-start=\"2678\" data-end=\"2735\">This creates what is often called <strong data-start=\"2712\" data-end=\"2734\">standing privilege<\/strong>.<\/p><p data-start=\"2737\" data-end=\"2749\">For example:<\/p><p data-start=\"2751\" data-end=\"2856\"><strong data-start=\"2751\" data-end=\"2856\">Admin account compromised \u2192 account already has Global Admin \u2192 attacker immediately controls Entra ID<\/strong><\/p><p data-start=\"2858\" data-end=\"3039\">With PIM, the same account can instead be merely <em data-start=\"2907\" data-end=\"2917\">eligible<\/em>. An attacker who steals the account may still have to overcome another set of controls before privilege can be activated.<\/p><p data-start=\"3041\" data-end=\"3112\">Without PIM, attackers may exploit permanently assigned permissions to:<\/p><ul data-start=\"3114\" data-end=\"3440\"><li data-section-id=\"1gcmfbt\" data-start=\"3114\" data-end=\"3146\">create new privileged accounts<\/li><li data-section-id=\"15b121z\" data-start=\"3147\" data-end=\"3187\">add themselves to administrative roles<\/li><li data-section-id=\"ydbcle\" data-start=\"3188\" data-end=\"3219\">change authentication methods<\/li><li data-section-id=\"122z3ei\" data-start=\"3220\" data-end=\"3255\">alter Conditional Access policies<\/li><li data-section-id=\"8z58cn\" data-start=\"3256\" data-end=\"3315\">create credentials for applications or service principals<\/li><li data-section-id=\"tkcgsx\" data-start=\"3316\" data-end=\"3363\">modify subscriptions and resource permissions<\/li><li data-section-id=\"w9kkqm\" data-start=\"3364\" data-end=\"3391\">disable security controls<\/li><li data-section-id=\"1w4t989\" data-start=\"3392\" data-end=\"3416\">interfere with logging<\/li><li data-section-id=\"74z0u8\" data-start=\"3417\" data-end=\"3440\">establish persistence<\/li><\/ul><p data-start=\"3442\" data-end=\"3521\">The danger increases significantly if many administrators have permanent roles.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9d4c522 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9d4c522\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-aac3a85\" data-id=\"aac3a85\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5a95359 elementor-widget elementor-widget-heading\" data-id=\"5a95359\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Without Conditional Access stolen credentials become portable<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2b9db56 elementor-widget elementor-widget-text-editor\" data-id=\"2b9db56\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"3594\" data-end=\"3643\">Conditional Access answers an important question:<\/p><blockquote data-start=\"3645\" data-end=\"3755\"><p data-start=\"3647\" data-end=\"3755\">Even if the username and password are correct, <strong data-start=\"3694\" data-end=\"3755\">should this sign-in be allowed under these circumstances?<\/strong><\/p><\/blockquote><p data-start=\"3757\" data-end=\"3836\">Without those policies, a stolen credential may be usable from almost anywhere.<\/p><p data-start=\"3838\" data-end=\"3850\">For example:<\/p><p data-start=\"3852\" data-end=\"3973\"><strong data-start=\"3852\" data-end=\"3973\">Password stolen in Finland \u2192 attacker signs in from an unmanaged machine elsewhere \u2192 Azure accepts the authentication<\/strong><\/p><p data-start=\"3975\" data-end=\"4161\">Proper Conditional Access can add requirements such as a compliant device, phishing-resistant MFA, approved client, acceptable sign-in risk, or specific administrative access conditions.<\/p><p data-start=\"4163\" data-end=\"4205\">Without it, common attack vectors include:<\/p><ul data-start=\"4207\" data-end=\"4508\"><li data-section-id=\"1sqbvsu\" data-start=\"4207\" data-end=\"4226\">password spraying<\/li><li data-section-id=\"1vzn01d\" data-start=\"4227\" data-end=\"4248\">credential stuffing<\/li><li data-section-id=\"1tr5cn6\" data-start=\"4249\" data-end=\"4259\">phishing<\/li><li data-section-id=\"4ro9o0\" data-start=\"4260\" data-end=\"4293\">adversary-in-the-middle attacks<\/li><li data-section-id=\"moep1q\" data-start=\"4294\" data-end=\"4318\">stolen session cookies<\/li><li data-section-id=\"1dnriia\" data-start=\"4319\" data-end=\"4351\">sign-in from unmanaged devices<\/li><li data-section-id=\"47dfyg\" data-start=\"4352\" data-end=\"4403\">sign-in from attacker-controlled virtual machines<\/li><li data-section-id=\"acatij\" data-start=\"4404\" data-end=\"4450\">legacy authentication, where still available<\/li><li data-section-id=\"1iuhm71\" data-start=\"4451\" data-end=\"4508\">repeated authentication attempts from unusual locations<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b0a904a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b0a904a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7222ce9\" data-id=\"7222ce9\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-42b025d elementor-widget elementor-widget-heading\" data-id=\"42b025d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">MFA alone does not solve everything<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-867c027 elementor-widget elementor-widget-text-editor\" data-id=\"867c027\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"4554\" data-end=\"4586\">A frequent mistake is to assume:<\/p><p data-start=\"4588\" data-end=\"4645\"><strong data-start=\"4588\" data-end=\"4645\">\u201cWe have MFA, therefore the admin accounts are safe.\u201d<\/strong><\/p><p data-start=\"4647\" data-end=\"4774\">MFA is important, but attackers have developed ways of attacking the authentication flow rather than simply guessing passwords.<\/p><p data-start=\"4776\" data-end=\"4978\">Examples include phishing pages that proxy the real authentication session and steal the resulting session token. An attacker may also exploit already authenticated endpoints or stolen browser sessions.<\/p><p data-start=\"4980\" data-end=\"5029\">That is why the stronger model combines controls:<\/p><p data-start=\"5031\" data-end=\"5101\"><strong data-start=\"5031\" data-end=\"5101\">PAW + phishing-resistant authentication + Conditional Access + PIM<\/strong><\/p><p data-start=\"5103\" data-end=\"5136\">rather than relying on MFA alone.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0471580 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"0471580\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8374532\" data-id=\"8374532\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8758b88 elementor-widget elementor-widget-heading\" data-id=\"8758b88\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Session\/token theft becomes particularly important<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-938f055 elementor-widget elementor-widget-text-editor\" data-id=\"938f055\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"5197\" data-end=\"5272\">Modern cloud attacks increasingly involve <strong data-start=\"5239\" data-end=\"5271\">tokens rather than passwords<\/strong>.<\/p><p data-start=\"5274\" data-end=\"5410\">If an attacker obtains an authenticated session token, they may sometimes use the existing session without needing to know the password.<\/p><p data-start=\"5412\" data-end=\"5435\">Consider this scenario:<\/p><p data-start=\"5437\" data-end=\"5482\"><strong data-start=\"5437\" data-end=\"5482\">Admin signs into Azure from normal laptop<\/strong><\/p><p data-start=\"5484\" data-end=\"5487\">\u2193<\/p><p data-start=\"5489\" data-end=\"5507\">Laptop compromised<\/p><p data-start=\"5509\" data-end=\"5512\">\u2193<\/p><p data-start=\"5514\" data-end=\"5551\">Attacker steals browser\/session token<\/p><p data-start=\"5553\" data-end=\"5556\">\u2193<\/p><p data-start=\"5558\" data-end=\"5603\">Attacker inherits authenticated Azure session<\/p><p data-start=\"5605\" data-end=\"5608\">\u2193<\/p><p data-start=\"5610\" data-end=\"5684\">If the account has standing privilege, attacker inherits privileged access<\/p><p data-start=\"5686\" data-end=\"5754\">The combination of <strong data-start=\"5705\" data-end=\"5724\">no PAW + no PIM<\/strong> therefore compounds the risk.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f582bc3 elementor-widget elementor-widget-image\" data-id=\"f582bc3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"640\" height=\"308\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_sessiontokentheft_mitreattack.png?fit=640%2C308&amp;ssl=1\" class=\"attachment-large size-large wp-image-3355\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_sessiontokentheft_mitreattack.png?w=1015&amp;ssl=1 1015w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_sessiontokentheft_mitreattack.png?resize=300%2C145&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_sessiontokentheft_mitreattack.png?resize=768%2C370&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_sessiontokentheft_mitreattack.png?resize=850%2C410&amp;ssl=1 850w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">MITRE ATT&amp;CK techniques for Entra ID session\/token theft<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f9706d2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f9706d2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-af4f761\" data-id=\"af4f761\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bba5831 elementor-widget elementor-widget-heading\" data-id=\"bba5831\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Privilege escalation becomes much easier<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-74f97f8 elementor-widget elementor-widget-text-editor\" data-id=\"74f97f8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"5805\" data-end=\"5946\">An attacker rarely begins with the most privileged account. They may initially compromise an ordinary user and then search for a path upward.<\/p><p data-start=\"5948\" data-end=\"6027\">Without strong privileged-access separation, they can potentially move through:<\/p><p data-start=\"6029\" data-end=\"6097\"><strong data-start=\"6029\" data-end=\"6097\">User \u2192 Helpdesk \u2192 Server admin \u2192 Identity admin \u2192 Global control<\/strong><\/p><p data-start=\"6099\" data-end=\"6338\">Examples of pathways they might abuse include overly broad group memberships, permanently assigned roles, exposed admin credentials, compromised management servers, service accounts, automation credentials, or weak application permissions.<\/p><p data-start=\"6340\" data-end=\"6453\">This is the cloud equivalent of the lateral-movement problem that the old Tier 0\/1\/2 architecture tried to solve.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a30c9bb elementor-widget elementor-widget-image\" data-id=\"a30c9bb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"350\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_privilege_escalation_mitreattack.png?fit=640%2C350&amp;ssl=1\" class=\"attachment-large size-large wp-image-3356\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_privilege_escalation_mitreattack.png?w=951&amp;ssl=1 951w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_privilege_escalation_mitreattack.png?resize=300%2C164&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_privilege_escalation_mitreattack.png?resize=768%2C420&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/09\/entra_privilege_escalation_mitreattack.png?resize=850%2C465&amp;ssl=1 850w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">MITRE ATT&amp;CK techniques for Entra ID privilege escalation &amp; persistence<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5445bc5 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5445bc5\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-39bb797\" data-id=\"39bb797\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-36bdcef elementor-widget elementor-widget-heading\" data-id=\"36bdcef\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Persistence becomes easier after the first compromise<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c1b9a3f elementor-widget elementor-widget-text-editor\" data-id=\"c1b9a3f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"6517\" data-end=\"6638\">Obtaining access once is useful to an attacker. Establishing access that survives password changes is much more valuable.<\/p><p data-start=\"6640\" data-end=\"6863\">With sufficient privilege, attackers may try to create alternative access paths such as additional identities, application credentials, authentication methods, role assignments, or other persistent authorization mechanisms.<\/p><p data-start=\"6865\" data-end=\"6894\">The architectural concern is:<\/p><p data-start=\"6896\" data-end=\"6965\"><strong data-start=\"6896\" data-end=\"6965\">Initial compromise \u2192 privilege \u2192 persistence \u2192 difficult recovery<\/strong><\/p><p data-start=\"6967\" data-end=\"7048\">PIM and strong control-plane restrictions reduce the opportunity window for this.<\/p><p data-start=\"6967\" data-end=\"7048\"><strong>MITRE ATT&amp;CK<\/strong> now has an official <strong data-start=\"38\" data-end=\"79\">Enterprise \u2192 Identity Provider matrix<\/strong>, and MITRE explicitly states that it covers cloud identity providers including <strong data-start=\"159\" data-end=\"181\">Microsoft Entra ID<\/strong> and Okta. As of September 2026, it maps <strong data-start=\"222\" data-end=\"235\">9 tactics<\/strong> and <strong data-start=\"240\" data-end=\"271\">23 unique parent techniques<\/strong> to the Identity Provider platform.\u00a0 <a href=\"https:\/\/attack.mitre.org\/matrices\/enterprise\/cloud\/identityprovider\/\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Link<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-475611c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"475611c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-97c960f\" data-id=\"97c960f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-69e3e91 elementor-widget elementor-widget-heading\" data-id=\"69e3e91\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">The worst case is an identity control-plane takeover<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-605b471 elementor-widget elementor-widget-text-editor\" data-id=\"605b471\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"7111\" data-end=\"7222\">The most dangerous scenario is not losing one virtual machine. It is losing control of the <strong data-start=\"7202\" data-end=\"7221\">identity system<\/strong>.<\/p><p data-start=\"7224\" data-end=\"7346\">If an attacker obtains sufficiently powerful Entra ID administrative privileges, they may be able to affect access across:<\/p><ul data-start=\"7348\" data-end=\"7523\"><li data-section-id=\"16ywf75\" data-start=\"7348\" data-end=\"7355\">Azure<\/li><li data-section-id=\"1o1e1rg\" data-start=\"7356\" data-end=\"7371\">Microsoft 365<\/li><li data-section-id=\"1sl7l0r\" data-start=\"7372\" data-end=\"7413\">applications using Entra authentication<\/li><li data-section-id=\"15dxxqe\" data-start=\"7414\" data-end=\"7439\">administrative accounts<\/li><li data-section-id=\"kvlsu0\" data-start=\"7440\" data-end=\"7455\">subscriptions<\/li><li data-section-id=\"kqq5ae\" data-start=\"7456\" data-end=\"7474\">security tooling<\/li><li data-section-id=\"10w2uvy\" data-start=\"7475\" data-end=\"7523\">potentially connected on-premises environments<\/li><\/ul><p data-start=\"7525\" data-end=\"7638\">This is why Entra ID privileged administration corresponds conceptually to <strong data-start=\"7600\" data-end=\"7637\">Tier 0 \/ Enterprise Control Plane<\/strong>.<\/p><p data-start=\"7640\" data-end=\"7679\">The attack can progress something like:<\/p><p data-start=\"7681\" data-end=\"7709\"><strong data-start=\"7681\" data-end=\"7709\">User endpoint compromise<\/strong><\/p><p data-start=\"7711\" data-end=\"7747\">\u2192 <strong data-start=\"7713\" data-end=\"7747\">admin credential\/session theft<\/strong><\/p><p data-start=\"7749\" data-end=\"7776\">\u2192 <strong data-start=\"7751\" data-end=\"7776\">privileged Entra role<\/strong><\/p><p data-start=\"7778\" data-end=\"7815\">\u2192 <strong data-start=\"7780\" data-end=\"7815\">identity control-plane takeover<\/strong><\/p><p data-start=\"7817\" data-end=\"7856\">\u2192 <strong data-start=\"7819\" data-end=\"7856\">access to many downstream systems<\/strong><\/p><p data-start=\"7858\" data-end=\"7957\">That is precisely the type of escalation the privileged-access architecture is intended to prevent.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fa44dab elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"fa44dab\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-df866a5 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"df866a5\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f7cf8fe\" data-id=\"f7cf8fe\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0a2cbec elementor-widget elementor-widget-heading\" data-id=\"0a2cbec\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Comparing the protected and unprotected models<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2d9c100 elementor-widget elementor-widget-text-editor\" data-id=\"2d9c100\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"8011\" data-end=\"8056\">The difference can be summarized very simply:<\/p><p data-start=\"8058\" data-end=\"8072\"><strong data-start=\"8058\" data-end=\"8072\">Weak model<\/strong><\/p><blockquote data-start=\"8074\" data-end=\"8141\"><p data-start=\"8076\" data-end=\"8141\">Normal laptop \u2192 admin login \u2192 permanent admin rights \u2192 Azure\/M365<\/p><\/blockquote><p data-start=\"8143\" data-end=\"8226\">A compromise of the laptop or account can potentially expose everything downstream.<\/p><p data-start=\"8228\" data-end=\"8247\"><strong data-start=\"8228\" data-end=\"8247\">Protected model<\/strong><\/p><blockquote data-start=\"8249\" data-end=\"8358\"><p data-start=\"8251\" data-end=\"8358\">PAW \u2192 Conditional Access \u2192 strong MFA\/device validation \u2192 PIM activation \u2192 temporary privilege \u2192 Azure\/M365<\/p><\/blockquote><p data-start=\"8360\" data-end=\"8429\">The attacker must cross <strong data-start=\"8384\" data-end=\"8428\">multiple independent security boundaries<\/strong>.<\/p><p data-start=\"8431\" data-end=\"8486\">This is the security principle of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Defense_in_depth_(computing)\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\"><strong data-start=\"8465\" data-end=\"8485\">defense in depth<\/strong><\/span><\/a>.<\/p><p data-start=\"8488\" data-end=\"8589\">FINALLY and in very short:<\/p><p data-start=\"8591\" data-end=\"8716\"><strong data-start=\"8591\" data-end=\"8623\">PAW protects the credentials.<\/strong><br data-start=\"8623\" data-end=\"8626\" \/><strong data-start=\"8626\" data-end=\"8682\">Conditional Access protects the authentication path.<\/strong><br data-start=\"8682\" data-end=\"8685\" \/><strong data-start=\"8685\" data-end=\"8716\">PIM protects the privilege.<\/strong><\/p><p data-start=\"8718\" data-end=\"8893\" data-is-last-node=\"\" data-is-only-node=\"\">Remove all three, and an attacker only needs to compromise <strong data-start=\"8777\" data-end=\"8831\">one privileged identity or one privileged endpoint<\/strong> to potentially obtain a direct path toward the control plane.<\/p><p data-start=\"8718\" data-end=\"8893\" data-is-last-node=\"\" data-is-only-node=\"\">That&#8217;s about it folks! This is the end of this study.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-86687a3 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"86687a3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-69864ee3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"69864ee3\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3f9d9bc6\" data-id=\"3f9d9bc6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-328d8a48 elementor-widget elementor-widget-author-box\" data-id=\"328d8a48\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<div  class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2024\/07\/jussi_06_2024.jpg?fit=262%2C300&#038;ssl=1\" alt=\"Picture of Jussi Metso\" loading=\"lazy\">\n\t\t\t\t<\/div>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<div >\n\t\t\t\t\t\t<h6 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\tJussi Metso\t\t\t\t\t\t<\/h6>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future. <\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Table of Contents My previous post was about Microsoft Enterprise Access Model (EAM) and the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":3269,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"elementor_theme","format":"standard","meta":{"advanced_seo_description":"The PAW, PIM and the Conditional Access setup. Some Entra ID Mitre atta&ck Tactics & Techniques.","jetpack_seo_html_title":"The PAW, PIM and the Conditional Access setup","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[72],"tags":[66,75,74,76],"class_list":["post-3265","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity_access","tag-condiftionalaccess","tag-entraid-2","tag-identityaccess-2","tag-mitreattack"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pes24X-QF","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/privileged_access_hologram.png?fit=896%2C644&ssl=1","_links":{"self":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3265","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/comments?post=3265"}],"version-history":[{"count":28,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3265\/revisions"}],"predecessor-version":[{"id":3360,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3265\/revisions\/3360"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media\/3269"}],"wp:attachment":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media?parent=3265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/categories?post=3265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/tags?post=3265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}