{"id":3287,"date":"2026-09-01T23:34:30","date_gmt":"2026-09-01T20:34:30","guid":{"rendered":"https:\/\/www.jussimetso.com\/?p=3287"},"modified":"2026-09-01T23:34:32","modified_gmt":"2026-09-01T20:34:32","slug":"descriptions-some-instructions-for-the-red-tenant","status":"publish","type":"post","link":"https:\/\/www.jussimetso.com\/index.php\/2026\/09\/01\/descriptions-some-instructions-for-the-red-tenant\/","title":{"rendered":"Descriptions (&amp; some instructions) for the Red Tenant"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div>\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3287\" class=\"elementor elementor-3287\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-cbf0206 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cbf0206\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8374b93\" data-id=\"8374b93\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6f2423e elementor-widget elementor-widget-text-editor\" data-id=\"6f2423e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>I started this journey on March 30, 2026 with post called <a href=\"https:\/\/www.jussimetso.com\/index.php\/2026\/03\/31\/red-tenant-intro\/\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Red Tenant intro<\/span><\/a>. It was really short post but I had to do it because of it I started actually studying everything around it.<\/p><p>Anyway there was this crappy image and I will now open those layers and descriptions (&amp; instructions).<\/p><p>I will also list some license requirements for the setup.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-20c294b elementor-widget elementor-widget-image\" data-id=\"20c294b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"300\" height=\"294\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?fit=300%2C294&amp;ssl=1\" class=\"attachment-medium size-medium wp-image-3031\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?w=1082&amp;ssl=1 1082w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=300%2C294&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=1024%2C1003&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=768%2C752&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/rt_mockup_layers.png?resize=850%2C833&amp;ssl=1 850w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-13485d2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"13485d2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-25665d4\" data-id=\"25665d4\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0e73558 elementor-widget elementor-widget-heading\" data-id=\"0e73558\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Reference architecture<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e007b0d elementor-widget elementor-widget-text-editor\" data-id=\"e007b0d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Dictionary<\/strong><\/p>\n<p>PAW = Privileged Access Workstation<\/p>\n<p>MFA = Multifactor Authentication<\/p>\n<p>JIT = Just-in-Time<\/p>\n<p>PIM = Privileged Identity Management<\/p>\n<p>SIEM = Security Information and Event Management<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ae5c59d elementor-widget elementor-widget-heading\" data-id=\"ae5c59d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">1. Core design<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dff1f49 elementor-widget elementor-widget-text-editor\" data-id=\"dff1f49\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"555\" data-end=\"585\">Think of it as <strong data-start=\"570\" data-end=\"584\">two planes<\/strong>:<\/p>\n<ul data-start=\"587\" data-end=\"1156\">\n<li data-section-id=\"1tb7918\" data-start=\"587\" data-end=\"727\"><strong data-start=\"589\" data-end=\"616\">Production \/ user plane<\/strong>: normal workforce tenant(s), user devices, M365 workloads, Azure subscriptions, Intune-managed end-user fleet.<\/li>\n<li data-section-id=\"ka641p\" data-start=\"728\" data-end=\"1156\"><strong data-start=\"730\" data-end=\"756\">Privileged \/ red plane<\/strong>: a <strong data-start=\"760\" data-end=\"785\">separate Entra tenant<\/strong> containing privileged identities, admin groups, hardened admin devices, stricter access policies, and monitoring for privileged operations. This follows Microsoft\u2019s enterprise access model and privileged access deployment guidance, even though Microsoft usually describes it as a privileged-access strategy rather than Red Tenant.<\/li>\n<li data-section-id=\"ka641p\" data-start=\"728\" data-end=\"1156\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-strategy\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-strategy<\/span><\/a><\/li>\n<\/ul>\n<p>A simple logical flow:<\/p>\n<p>for Admin user<br \/>-&gt; dedicated admin account in Red Tenant<br \/>-&gt; hardened PAW\u00a0<br \/>-&gt; phishing-resistant MFA<br \/>-&gt; Conditional Access checks<br \/>-&gt; JIT\u00a0 elevation via PIM<br \/>-&gt; access to production tenant admin interfaces \/ Azure \/ Intune \/ on-prem admin paths<br \/>-&gt; all privileged actions logged to SIEM.<\/p>\n<p>Microsoft\u2019s guidance is explicit that meaningful privileged-access protection needs <strong data-start=\"1596\" data-end=\"1663\">secure accounts, secure devices, and secure interfaces together<\/strong>, not just one of them.\u00a0<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-deployment\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-deployment<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7fafc36 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7fafc36\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-cf131b5\" data-id=\"cf131b5\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-99c9ef4 elementor-widget elementor-widget-heading\" data-id=\"99c9ef4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">2. Identity layer<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b26ac49 elementor-widget elementor-widget-text-editor\" data-id=\"b26ac49\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"1749\" data-end=\"1779\">Inside the red tenant, create:<\/p>\n<ul data-start=\"1781\" data-end=\"2240\">\n<li data-section-id=\"1eo1etb\" data-start=\"1781\" data-end=\"1850\"><strong data-start=\"1783\" data-end=\"1824\">Dedicated cloud-only admin identities<\/strong> for privileged work only.<\/li>\n<li data-section-id=\"n77ki2\" data-start=\"1851\" data-end=\"1919\"><strong data-start=\"1853\" data-end=\"1883\">Role-specific admin groups<\/strong> rather than broad Global Admin use.<\/li>\n<li data-section-id=\"1jesisy\" data-start=\"1920\" data-end=\"2004\"><strong data-start=\"1922\" data-end=\"1950\">PIM-eligible assignments<\/strong> for admin roles instead of permanent standing access.<\/li>\n<li data-section-id=\"1praf9w\" data-start=\"2005\" data-end=\"2240\"><strong data-start=\"2007\" data-end=\"2050\">Emergency access \/ break-glass accounts<\/strong> with tightly controlled storage and monitoring. Microsoft recommends maintaining emergency access accounts and separately documents how to manage them.<\/li>\n<\/ul>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"2242\" data-end=\"2265\">Recommended role tiers:<\/p>\n<ul data-start=\"2267\" data-end=\"2565\">\n<li data-section-id=\"1x0sznm\" data-start=\"2267\" data-end=\"2422\"><strong data-start=\"2269\" data-end=\"2295\">Tier 0 \/ control plane<\/strong>: Global Admin, Privileged Role Admin, Conditional Access Admin, Security Admin, Intune Admin, key Azure root management roles.<\/li>\n<li data-section-id=\"5wkud1\" data-start=\"2423\" data-end=\"2489\"><strong data-start=\"2425\" data-end=\"2452\">Tier 1 \/ platform admin<\/strong>: workload or service-specific roles.<\/li>\n<li data-section-id=\"ii8mef\" data-start=\"2490\" data-end=\"2565\"><strong data-start=\"2492\" data-end=\"2512\">Tier 2 \/ support<\/strong>: helpdesk, device ops, app ops with least privilege.<\/li>\n<\/ul>\n<p data-start=\"2567\" data-end=\"2725\">That tiered approach aligns to Microsoft\u2019s privileged access security levels and best-practice guidance for Entra roles.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/id-governance\/privileged-identity-management\/pim-getting-started\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/entra\/id-governance\/privileged-identity-management\/pim-getting-started<\/span><\/a><\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/role-based-access-control\/best-practices\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/role-based-access-control\/best-practices<\/span><\/a><\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/role-based-access-control\/security-emergency-access\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/role-based-access-control\/security-emergency-access<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-422e611 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"422e611\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fd791a6\" data-id=\"fd791a6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-fbed11c elementor-widget elementor-widget-heading\" data-id=\"fbed11c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">3. Device layer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b390526 elementor-widget elementor-widget-text-editor\" data-id=\"b390526\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"2748\" data-end=\"2814\">Use <strong data-start=\"2752\" data-end=\"2791\">dedicated privileged access devices<\/strong> for red-tenant admins:<\/p>\n<ul data-start=\"2816\" data-end=\"3094\">\n<li data-section-id=\"13dqz8u\" data-start=\"2816\" data-end=\"2838\">Enrolled into Intune<\/li>\n<li data-section-id=\"11ugido\" data-start=\"2839\" data-end=\"2890\">Separate device policy baseline from user laptops<\/li>\n<li data-section-id=\"rc8bdf\" data-start=\"2891\" data-end=\"2964\">No email \/ general collaboration apps on highest-security admin devices<\/li>\n<li data-section-id=\"1ingjh0\" data-start=\"2965\" data-end=\"3016\">Application allowlisting \/ restricted browser use<\/li>\n<li data-section-id=\"he8o89\" data-start=\"3017\" data-end=\"3060\">Aggressive patching and compliance checks<\/li>\n<li data-section-id=\"h83etx\" data-start=\"3061\" data-end=\"3094\">Defender for Endpoint onboarded<\/li>\n<\/ul>\n<p data-start=\"3096\" data-end=\"3320\">Microsoft states that privileged access workstations\/devices should reduce attack surface and that the highest security level should avoid normal productivity usage and general browsing.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-devices\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-devices<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b3e73ee elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b3e73ee\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2e10a4c\" data-id=\"2e10a4c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8bbdb92 elementor-widget elementor-widget-heading\" data-id=\"8bbdb92\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">4. Access policy layer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e0b2649 elementor-widget elementor-widget-text-editor\" data-id=\"e0b2649\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"3350\" data-end=\"3399\">For red-tenant sign-in and privileged interfaces:<\/p>\n<ul data-start=\"3401\" data-end=\"3747\">\n<li data-section-id=\"1qtkauh\" data-start=\"3401\" data-end=\"3452\">Require <strong data-start=\"3411\" data-end=\"3437\">phishing-resistant MFA<\/strong> where possible<\/li>\n<li data-section-id=\"1lm9vzf\" data-start=\"3453\" data-end=\"3494\">Require <strong data-start=\"3463\" data-end=\"3494\">compliant &amp; managed devices<\/strong><\/li>\n<li data-section-id=\"156a584\" data-start=\"3495\" data-end=\"3524\">Block legacy authentication<\/li>\n<li data-section-id=\"1unxrwr\" data-start=\"3525\" data-end=\"3604\">Restrict access to admin portals and admin actions through Conditional Access<\/li>\n<li data-section-id=\"ooeu73\" data-start=\"3605\" data-end=\"3674\">Use authentication strength \/ interface targeting where appropriate<\/li>\n<li data-section-id=\"1trszi4\" data-start=\"3675\" data-end=\"3747\">Create dedicated admin access policies separate from end-user policies<\/li>\n<\/ul>\n<p data-start=\"3749\" data-end=\"3993\">Microsoft describes Conditional Access as the Zero Trust policy engine and specifically recommends protecting privileged interfaces and blocking legacy auth, while accounting for emergency access scenarios.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/overview\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/overview<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a76f728 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a76f728\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7a2252d\" data-id=\"7a2252d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-db52cf9 elementor-widget elementor-widget-heading\" data-id=\"db52cf9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">5. Elevation and governance layer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b63bbb0 elementor-widget elementor-widget-text-editor\" data-id=\"b63bbb0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"4034\" data-end=\"4038\">Use:<\/p>\n<ul data-start=\"4040\" data-end=\"4325\">\n<li data-section-id=\"r0dvxx\" data-start=\"4040\" data-end=\"4090\"><strong data-start=\"4042\" data-end=\"4049\">PIM<\/strong> for Entra roles, Azure roles, and groups<\/li>\n<li data-section-id=\"7ivmy3\" data-start=\"4091\" data-end=\"4144\">Approval and justification for high-risk elevations<\/li>\n<li data-section-id=\"qo3bux\" data-start=\"4145\" data-end=\"4176\">Time-bound activation windows<\/li>\n<li data-section-id=\"1ithqww\" data-start=\"4177\" data-end=\"4247\">Access reviews for privileged role eligibility and privileged groups<\/li>\n<li data-section-id=\"1qhnidg\" data-start=\"4248\" data-end=\"4325\">Entitlement management for controlled admin package assignment where useful<\/li>\n<\/ul>\n<p data-start=\"4327\" data-end=\"4539\">Microsoft documents PIM as the control for time-based and approval-based admin activation, and access reviews \/ entitlement management as identity-governance building blocks.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/id-governance\/entitlement-management-overview\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/entra\/id-governance\/entitlement-management-overview<\/span><\/a><\/p>\n<p>\u00a0<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/id-governance\/access-reviews-overview\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/entra\/id-governance\/access-reviews-overview<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-14c6cca elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"14c6cca\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-02743b2\" data-id=\"02743b2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2b87027 elementor-widget elementor-widget-heading\" data-id=\"2b87027\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">6. Monitoring and response layer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7b1d879 elementor-widget elementor-widget-text-editor\" data-id=\"7b1d879\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"4579\" data-end=\"4631\">Send all of the following into SIEM \/ SOC workflows:<\/p>\n<ul data-start=\"4633\" data-end=\"4801\">\n<li data-section-id=\"42yim1\" data-start=\"4633\" data-end=\"4654\">Privileged sign-ins<\/li>\n<li data-section-id=\"1szwgre\" data-start=\"4655\" data-end=\"4680\">Role assignment changes<\/li>\n<li data-section-id=\"u0n4nv\" data-start=\"4681\" data-end=\"4698\">PIM activations<\/li>\n<li data-section-id=\"hq8ush\" data-start=\"4699\" data-end=\"4728\">Conditional Access failures<\/li>\n<li data-section-id=\"wncded\" data-start=\"4729\" data-end=\"4748\">Break-glass usage<\/li>\n<li data-section-id=\"s7742u\" data-start=\"4749\" data-end=\"4801\">Device risk \/ endpoint detections on admin devices<\/li>\n<\/ul>\n<p data-start=\"4803\" data-end=\"4970\">Microsoft\u2019s privileged account operations guidance stresses monitoring privileged accounts and activity as a separate discipline.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-success-criteria\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-success-criteria<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-57b1cae elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"57b1cae\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2516369\" data-id=\"2516369\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-30807c9 elementor-widget elementor-widget-heading\" data-id=\"30807c9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">7. Hybrid \/ multi-tenant considerations<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9fb67aa elementor-widget elementor-widget-text-editor\" data-id=\"9fb67aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"5017\" data-end=\"5036\">If you also manage:<\/p>\n<ul data-start=\"5038\" data-end=\"5142\">\n<li data-section-id=\"15tm56o\" data-start=\"5038\" data-end=\"5068\">multiple production tenants,<\/li>\n<li data-section-id=\"1pjbsr1\" data-start=\"5069\" data-end=\"5091\">Azure subscriptions,<\/li>\n<li data-section-id=\"p9na7j\" data-start=\"5092\" data-end=\"5114\">Intune environments,<\/li>\n<li data-section-id=\"1glvesn\" data-start=\"5115\" data-end=\"5142\">on-prem Active Directory<\/li>\n<\/ul>\n<p data-start=\"5144\" data-end=\"5569\">then define the <strong data-start=\"5160\" data-end=\"5185\">admin path explicitly <\/strong>from which red-tenant identity, from which admin device, using which JIT role, to which production scope. This is where many implementations fail, too much trust is left implicit.<\/p>\n<p data-start=\"5144\" data-end=\"5569\">Microsoft\u2019s enterprise access model and hybrid privileged-access guidance are built around making those trust paths explicit and minimizing broad standing privilege.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-access-model\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-access-model<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-61c3545 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"61c3545\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-bd6d7f6 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"bd6d7f6\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c5485ab\" data-id=\"c5485ab\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-23f9eaf elementor-widget elementor-widget-heading\" data-id=\"23f9eaf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">License \/ components list<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-108a5a8 elementor-widget elementor-widget-heading\" data-id=\"108a5a8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Minimum viable license stack<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e8e83b9 elementor-widget elementor-widget-text-editor\" data-id=\"e8e83b9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"5828\" data-end=\"5855\"><strong data-start=\"5828\" data-end=\"5855\">Identity and governance<\/strong><\/p>\n<ul data-start=\"5856\" data-end=\"6130\">\n<li data-section-id=\"rq5qud\" data-start=\"5856\" data-end=\"6053\"><strong data-start=\"5858\" data-end=\"5883\">Microsoft Entra ID P2<\/strong> or <strong data-start=\"5887\" data-end=\"5920\">Microsoft Entra ID Governance<\/strong>\n<ul data-start=\"5923\" data-end=\"6053\">\n<li data-section-id=\"920njg\" data-start=\"5923\" data-end=\"5943\">Needed for <strong data-start=\"5936\" data-end=\"5943\">PIM<\/strong><\/li>\n<li data-section-id=\"7pfivk\" data-start=\"5946\" data-end=\"6053\">Also supports governance capabilities such as access reviews and entitlement management, depending on SKU<\/li>\n<\/ul>\n<\/li>\n<li data-section-id=\"83ub9l\" data-start=\"6054\" data-end=\"6098\"><strong data-start=\"6056\" data-end=\"6078\">Conditional Access<\/strong> capability in Entra<\/li>\n<li data-section-id=\"1eqbufr\" data-start=\"6099\" data-end=\"6130\"><strong data-start=\"6101\" data-end=\"6130\">Emergency access accounts<\/strong><\/li>\n<\/ul>\n<p data-start=\"6132\" data-end=\"6366\">Microsoft documents that using PIM requires <strong data-start=\"6176\" data-end=\"6234\">Microsoft Entra ID P2 or Microsoft Entra ID Governance<\/strong>. The current licensing docs also show that Entra Suite includes ID Governance capabilities.<\/p>\n<p data-start=\"6368\" data-end=\"6391\"><strong data-start=\"6368\" data-end=\"6391\">Device and endpoint<\/strong><\/p>\n<ul data-start=\"6392\" data-end=\"6584\">\n<li data-section-id=\"r6mtmr\" data-start=\"6392\" data-end=\"6485\"><strong data-start=\"6394\" data-end=\"6421\">Microsoft Intune Plan 1<\/strong>\n<ul data-start=\"6424\" data-end=\"6485\">\n<li data-section-id=\"ewje6s\" data-start=\"6424\" data-end=\"6443\">Device enrollment<\/li>\n<li data-section-id=\"7hujpx\" data-start=\"6446\" data-end=\"6458\">Compliance<\/li>\n<li data-section-id=\"nz1pa6\" data-start=\"6461\" data-end=\"6485\">Configuration policies<\/li>\n<\/ul>\n<\/li>\n<li data-section-id=\"1pcsa7e\" data-start=\"6486\" data-end=\"6584\"><strong data-start=\"6488\" data-end=\"6530\">Microsoft Defender for Endpoint Plan 2<\/strong>\n<ul data-start=\"6533\" data-end=\"6584\">\n<li data-section-id=\"z6jglb\" data-start=\"6533\" data-end=\"6584\">Strongly recommended for privileged admin devices<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p data-start=\"6586\" data-end=\"6844\">Microsoft documents Intune Plan 1 license availability across Microsoft 365 E3\/E5, EMS E3\/E5 and Business Premium. Defender for Endpoint P2 is available standalone and in several E5-level bundles.<\/p>\n<p data-start=\"6586\" data-end=\"6844\">\u00a0<\/p>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-section-id=\"sry6p\" data-start=\"7608\" data-end=\"7636\">Practical bundle options<\/h3>\n<p data-start=\"7638\" data-end=\"7661\">Common bundle patterns:<\/p>\n<p data-start=\"7663\" data-end=\"7691\"><strong data-start=\"7663\" data-end=\"7691\">Option A: Lean \/ focused<\/strong><\/p>\n<ul data-start=\"7692\" data-end=\"7748\">\n<li data-section-id=\"19gqfpn\" data-start=\"7692\" data-end=\"7705\">Entra ID P2<\/li>\n<li data-section-id=\"1e0iwx3\" data-start=\"7706\" data-end=\"7721\">Intune Plan 1<\/li>\n<li data-section-id=\"1l2rr3h\" data-start=\"7722\" data-end=\"7748\">Defender for Endpoint P2<\/li>\n<\/ul>\n<p data-start=\"7750\" data-end=\"7783\"><strong data-start=\"7750\" data-end=\"7783\">Option B: Enterprise standard<\/strong><\/p>\n<ul data-start=\"7784\" data-end=\"7912\">\n<li data-section-id=\"12bvtke\" data-start=\"7784\" data-end=\"7826\">Microsoft 365 E5 for admin users\/devices<\/li>\n<li data-section-id=\"1y01dq0\" data-start=\"7827\" data-end=\"7912\">Add separate red-tenant licensing only where needed for isolated identities\/devices<\/li>\n<\/ul>\n<p data-start=\"7914\" data-end=\"7944\"><strong data-start=\"7914\" data-end=\"7944\">Option C: Governance-heavy<\/strong><\/p>\n<ul data-start=\"7945\" data-end=\"8050\">\n<li data-section-id=\"1cm5464\" data-start=\"7945\" data-end=\"7991\">Microsoft Entra ID Governance or Entra Suite<\/li>\n<li data-section-id=\"we3d61\" data-start=\"7992\" data-end=\"8023\">Intune Plan 1 or Intune Suite<\/li>\n<li data-section-id=\"1l2rr3h\" data-start=\"8024\" data-end=\"8050\">Defender for Endpoint P2<\/li>\n<\/ul>\n<p data-start=\"8052\" data-end=\"8332\">Because licensing terms change and bundling differs by agreement, validate your exact entitlement set against your tenant\u2019s commercial agreement before procurement. Microsoft\u2019s current docs are the source of truth for included capabilities.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-deployment\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-deployment<\/span><\/a><\/p>\n<p data-start=\"8052\" data-end=\"8332\">\u00a0<\/p>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-section-id=\"aki6j6\" data-start=\"8334\" data-end=\"8364\">Component list by function<\/h3>\n<div class=\"group TyagGW_tableContainer\">\n<div class=\"TyagGW_tableWrapper flex flex-col-reverse w-fit\" tabindex=\"-1\">\n<table class=\"w-fit min-w-(--thread-content-width)\" data-start=\"8366\" data-end=\"8999\">\n<thead data-start=\"8366\" data-end=\"8400\">\n<tr data-start=\"8366\" data-end=\"8400\">\n<th class=\"last:pe-10\" data-start=\"8366\" data-end=\"8377\" data-col-size=\"md\">Function<\/th>\n<th class=\"last:pe-10\" data-start=\"8377\" data-end=\"8400\" data-col-size=\"sm\">Microsoft component<\/th>\n<\/tr>\n<\/thead>\n<tbody data-start=\"8411\" data-end=\"8999\">\n<tr data-start=\"8411\" data-end=\"8478\">\n<td data-start=\"8411\" data-end=\"8443\" data-col-size=\"md\">Privileged identity isolation<\/td>\n<td data-start=\"8443\" data-end=\"8478\" data-col-size=\"sm\">Separate Microsoft Entra tenant<\/td>\n<\/tr>\n<tr data-start=\"8479\" data-end=\"8524\">\n<td data-start=\"8479\" data-end=\"8501\" data-col-size=\"md\">JIT admin elevation<\/td>\n<td data-start=\"8501\" data-end=\"8524\" data-col-size=\"sm\">Microsoft Entra PIM<\/td>\n<\/tr>\n<tr data-start=\"8525\" data-end=\"8574\">\n<td data-start=\"8525\" data-end=\"8552\" data-col-size=\"md\">Admin policy enforcement<\/td>\n<td data-start=\"8552\" data-end=\"8574\" data-col-size=\"sm\">Conditional Access<\/td>\n<\/tr>\n<tr data-start=\"8575\" data-end=\"8621\">\n<td data-start=\"8575\" data-end=\"8601\" data-col-size=\"md\">Admin device management<\/td>\n<td data-start=\"8601\" data-end=\"8621\" data-col-size=\"sm\">Microsoft Intune<\/td>\n<\/tr>\n<tr data-start=\"8622\" data-end=\"8690\">\n<td data-start=\"8622\" data-end=\"8655\" data-col-size=\"md\">Admin device threat protection<\/td>\n<td data-start=\"8655\" data-end=\"8690\" data-col-size=\"sm\">Microsoft Defender for Endpoint<\/td>\n<\/tr>\n<tr data-start=\"8691\" data-end=\"8753\">\n<td data-start=\"8691\" data-end=\"8735\" data-col-size=\"md\">Privileged group \/ access recertification<\/td>\n<td data-start=\"8735\" data-end=\"8753\" data-col-size=\"sm\">Access Reviews<\/td>\n<\/tr>\n<tr data-start=\"8754\" data-end=\"8816\">\n<td data-start=\"8754\" data-end=\"8790\" data-col-size=\"md\">Controlled assignment \/ packaging<\/td>\n<td data-start=\"8790\" data-end=\"8816\" data-col-size=\"sm\">Entitlement Management<\/td>\n<\/tr>\n<tr data-start=\"8817\" data-end=\"8860\">\n<td data-start=\"8817\" data-end=\"8836\" data-col-size=\"md\">Emergency access<\/td>\n<td data-start=\"8836\" data-end=\"8860\" data-col-size=\"sm\">Break-glass accounts<\/td>\n<\/tr>\n<tr data-start=\"8861\" data-end=\"8937\">\n<td data-start=\"8861\" data-end=\"8897\" data-col-size=\"md\">Restricted elevation on endpoints<\/td>\n<td data-start=\"8897\" data-end=\"8937\" data-col-size=\"sm\">Intune Endpoint Privilege Management<\/td>\n<\/tr>\n<tr data-start=\"8938\" data-end=\"8999\">\n<td data-start=\"8938\" data-end=\"8977\" data-col-size=\"md\">Remote support for managed endpoints<\/td>\n<td data-start=\"8977\" data-end=\"8999\" data-col-size=\"sm\">Intune Remote Help<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cee27d8 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"cee27d8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6bc26faa elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6bc26faa\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1ace674f\" data-id=\"1ace674f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-39de02a elementor-widget elementor-widget-author-box\" data-id=\"39de02a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<div  class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2024\/07\/jussi_06_2024.jpg?fit=262%2C300&#038;ssl=1\" alt=\"Picture of Jussi Metso\" loading=\"lazy\">\n\t\t\t\t<\/div>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<div >\n\t\t\t\t\t\t<h6 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\tJussi Metso\t\t\t\t\t\t<\/h6>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future. <\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>I started this journey on March 30, 2026 with post called Red Tenant intro. It&#8230;<\/p>\n","protected":false},"author":1,"featured_media":3029,"comment_status":"closed","ping_status":"open","sticky":false,"template":"elementor_theme","format":"standard","meta":{"advanced_seo_description":"Some instructions for the red tenant","jetpack_seo_html_title":"Some instructions for the red tenant","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[72],"tags":[74,70],"class_list":["post-3287","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity_access","tag-identityaccess-2","tag-redtenant"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pes24X-R1","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/03\/redtenant.png?fit=347%2C241&ssl=1","_links":{"self":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/comments?post=3287"}],"version-history":[{"count":18,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3287\/revisions"}],"predecessor-version":[{"id":3345,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3287\/revisions\/3345"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media\/3029"}],"wp:attachment":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media?parent=3287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/categories?post=3287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/tags?post=3287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}