<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Identity Crisis - “An Impostor’s Guide to IAM"]]></title><description><![CDATA["Tackling identity and access challenges as a seasoned impostor.”]]></description><link>https://www.identitycrisis.net</link><image><url>https://substackcdn.com/image/fetch/$s_!VIs5!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f72147f-839b-4f7e-b7ed-ab01f164ffa7_1280x1280.png</url><title>Identity Crisis - “An Impostor’s Guide to IAM&quot;</title><link>https://www.identitycrisis.net</link></image><generator>Substack</generator><lastBuildDate>Wed, 22 Apr 2026 22:14:26 GMT</lastBuildDate><atom:link href="https://www.identitycrisis.net/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Patrick Horne]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[hornep@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[hornep@substack.com]]></itunes:email><itunes:name><![CDATA[Patrick Horne]]></itunes:name></itunes:owner><itunes:author><![CDATA[Patrick Horne]]></itunes:author><googleplay:owner><![CDATA[hornep@substack.com]]></googleplay:owner><googleplay:email><![CDATA[hornep@substack.com]]></googleplay:email><googleplay:author><![CDATA[Patrick Horne]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Entitlement Management isn't enough! - Lock down your Entra groups (Part 2)]]></title><description><![CDATA[&#8220;How to prevent rogue admins and group owners from undermining your access package strategy - The implementation.]]></description><link>https://www.identitycrisis.net/p/entitlement-management-isnt-enough-part2</link><guid isPermaLink="false">https://www.identitycrisis.net/p/entitlement-management-isnt-enough-part2</guid><dc:creator><![CDATA[Patrick Horne]]></dc:creator><pubDate>Mon, 01 Sep 2025 08:08:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZFem!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In <strong><a href="https://www.identitycrisis.net/p/entitlement-management-isnt-enough">Part 1</a> </strong>I talked about a back door in Entra Entitlement Management; group owners and admins can still bypass all that lovely governance and just add whoever they like to groups controlled by Access Packages. That means your carefully crafted access packages are basically optional. Great for chaos, terrible for compliance.<br><br>In this post we'll get hands-on and walk through how to actually lock things down. We'll build a setup where group owners keep their business context but lose their "Wild West" membership rights, and Entitlement Management actually does what it says on the tin.<br><br>By the end, you'll have turned your Entra groups from "open bar at a wedding" into "velvet rope at a club". Only the right people get the right access at the right times.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZFem!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZFem!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZFem!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZFem!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZFem!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZFem!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Security stopping people getting into you Entra groups&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Security stopping people getting into you Entra groups" title="Security stopping people getting into you Entra groups" srcset="https://substackcdn.com/image/fetch/$s_!ZFem!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZFem!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZFem!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZFem!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d3c0c9-b20a-403f-b7ce-c78d670c0fe8_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I should start by saying, officially, the Microsoft docs say Identity Governance can&#8217;t manage groups in restricted Admin Units, it&#8217;s listed in the limitations.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.identitycrisis.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity Crisis - &#8220;An Impostor&#8217;s Guide to IAM"! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N4jT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N4jT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png 424w, https://substackcdn.com/image/fetch/$s_!N4jT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png 848w, https://substackcdn.com/image/fetch/$s_!N4jT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png 1272w, https://substackcdn.com/image/fetch/$s_!N4jT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N4jT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png" width="1297" height="288" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/014d67ac-6365-444f-a87a-074f171e511e_1297x288.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:288,&quot;width&quot;:1297,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23635,&quot;alt&quot;:&quot;Microsoft documentation&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Microsoft documentation" title="Microsoft documentation" srcset="https://substackcdn.com/image/fetch/$s_!N4jT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png 424w, https://substackcdn.com/image/fetch/$s_!N4jT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png 848w, https://substackcdn.com/image/fetch/$s_!N4jT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png 1272w, https://substackcdn.com/image/fetch/$s_!N4jT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014d67ac-6365-444f-a87a-074f171e511e_1297x288.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>But practically, yes, it works. Microsoft vaguely alludes to this further down the page, but if you bailed at the bit that says <em><strong>you can&#8217;t</strong></em>, you probably never read that far. So here&#8217;s the step-by-step setup.</p><p><strong>Step 1. </strong>We need to let Entitlement Management, specifically its service principal, manage groups inside our restricted Admin Units.</p><p>To make that happen, we'll create a custom role with the required permissions, then assign that role to the EM service principal on a permanent basis.</p><p>Go to &#8220;<strong>Roles and admins</strong>&#8221;, &#8220;<strong>All roles</strong>&#8221; and then &#8220;<strong>New custom role</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F_Cf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F_Cf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png 424w, https://substackcdn.com/image/fetch/$s_!F_Cf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png 848w, https://substackcdn.com/image/fetch/$s_!F_Cf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png 1272w, https://substackcdn.com/image/fetch/$s_!F_Cf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F_Cf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png" width="1405" height="364" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:364,&quot;width&quot;:1405,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42047,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F_Cf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png 424w, https://substackcdn.com/image/fetch/$s_!F_Cf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png 848w, https://substackcdn.com/image/fetch/$s_!F_Cf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png 1272w, https://substackcdn.com/image/fetch/$s_!F_Cf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a596fe1-8755-43fd-8c09-26d734b3a065_1405x364.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Give your new custom role a name and description that makes sense and choose to &#8220;<strong>Start from scratch</strong>&#8221; for the permissions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O3aB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O3aB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png 424w, https://substackcdn.com/image/fetch/$s_!O3aB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png 848w, https://substackcdn.com/image/fetch/$s_!O3aB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png 1272w, https://substackcdn.com/image/fetch/$s_!O3aB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O3aB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png" width="996" height="404" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:404,&quot;width&quot;:996,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:15058,&quot;alt&quot;:&quot;Creating a custom role&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Creating a custom role" title="Creating a custom role" srcset="https://substackcdn.com/image/fetch/$s_!O3aB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png 424w, https://substackcdn.com/image/fetch/$s_!O3aB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png 848w, https://substackcdn.com/image/fetch/$s_!O3aB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png 1272w, https://substackcdn.com/image/fetch/$s_!O3aB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce894af-7fe1-44f8-903e-3a00a69f201d_996x404.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On the permissions section, add the following permission, then you can &#8220;<strong>Review and create</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5kIb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5kIb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png 424w, https://substackcdn.com/image/fetch/$s_!5kIb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png 848w, https://substackcdn.com/image/fetch/$s_!5kIb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png 1272w, https://substackcdn.com/image/fetch/$s_!5kIb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5kIb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png" width="1426" height="366" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:366,&quot;width&quot;:1426,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19200,&quot;alt&quot;:&quot;Adding privileges to the role&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Adding privileges to the role" title="Adding privileges to the role" srcset="https://substackcdn.com/image/fetch/$s_!5kIb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png 424w, https://substackcdn.com/image/fetch/$s_!5kIb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png 848w, https://substackcdn.com/image/fetch/$s_!5kIb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png 1272w, https://substackcdn.com/image/fetch/$s_!5kIb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40cc2f21-8453-4f8c-80f4-0d464a4a3969_1426x366.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 2. </strong>Now we are going to create a Restricted Admin Unit. You'd be surprised how many people have never heard of or noticed this Entra feature before, and if I'm being completely honest, I didn't pay that much attention to them for a while either. Whenever I'd read about them they were described in the same vein as delegated OUs in Active Directory with the old "regional IT support" model use case which does make sense I suppose.</p><p>Go to the Entra portal, &#8220;<strong>Roles and admins</strong>&#8221;, &#8220;<strong>Admin units</strong>&#8221; and then &#8220;<strong>Add</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8e9P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8e9P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png 424w, https://substackcdn.com/image/fetch/$s_!8e9P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png 848w, https://substackcdn.com/image/fetch/$s_!8e9P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png 1272w, https://substackcdn.com/image/fetch/$s_!8e9P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8e9P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png" width="1446" height="456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:456,&quot;width&quot;:1446,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35580,&quot;alt&quot;:&quot;Entra; Add an Admin Unit&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Entra; Add an Admin Unit" title="Entra; Add an Admin Unit" srcset="https://substackcdn.com/image/fetch/$s_!8e9P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png 424w, https://substackcdn.com/image/fetch/$s_!8e9P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png 848w, https://substackcdn.com/image/fetch/$s_!8e9P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png 1272w, https://substackcdn.com/image/fetch/$s_!8e9P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F894609dd-f66c-4ec1-91aa-fd0810098766_1446x456.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Give the admin unit a useful name and description and DON&#8217;T FORGET to select &#8220;<strong>Yes</strong>&#8221; for Restricted management administrative unit. Once you create an AU, you cannot go back and change this setting either way.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZefP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZefP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png 424w, https://substackcdn.com/image/fetch/$s_!ZefP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png 848w, https://substackcdn.com/image/fetch/$s_!ZefP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png 1272w, https://substackcdn.com/image/fetch/$s_!ZefP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZefP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png" width="737" height="498" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:498,&quot;width&quot;:737,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14232,&quot;alt&quot;:&quot;Adding an administrative unit&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Adding an administrative unit" title="Adding an administrative unit" srcset="https://substackcdn.com/image/fetch/$s_!ZefP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png 424w, https://substackcdn.com/image/fetch/$s_!ZefP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png 848w, https://substackcdn.com/image/fetch/$s_!ZefP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png 1272w, https://substackcdn.com/image/fetch/$s_!ZefP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9489d19-4e70-4c92-b805-a0a06193c3ae_737x498.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Click &#8220;<strong>Review+ create</strong>&#8221; and finish the creation now.  If you go &#8220;<strong>Next; Assign roles</strong>&#8221; and try to assign any privileges during creation, the GUI will only allow us to select users at that point for some reason and we need to be able to see service principals.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!clY0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!clY0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png 424w, https://substackcdn.com/image/fetch/$s_!clY0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png 848w, https://substackcdn.com/image/fetch/$s_!clY0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png 1272w, https://substackcdn.com/image/fetch/$s_!clY0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!clY0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png" width="367" height="65" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:65,&quot;width&quot;:367,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2909,&quot;alt&quot;:&quot;Review and create&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Review and create" title="Review and create" srcset="https://substackcdn.com/image/fetch/$s_!clY0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png 424w, https://substackcdn.com/image/fetch/$s_!clY0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png 848w, https://substackcdn.com/image/fetch/$s_!clY0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png 1272w, https://substackcdn.com/image/fetch/$s_!clY0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab026d4a-a044-4fb0-b84f-9ca46959d311_367x65.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Step 3.  Now let&#8217;s permanently assign our new custom role to Entitlement Management with the scope of this new Admin Unit.</p><p>Go to your new Admin unit.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f-75!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f-75!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png 424w, https://substackcdn.com/image/fetch/$s_!f-75!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png 848w, https://substackcdn.com/image/fetch/$s_!f-75!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png 1272w, https://substackcdn.com/image/fetch/$s_!f-75!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f-75!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png" width="1456" height="215" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:215,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19758,&quot;alt&quot;:&quot;Your new admin unit&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Your new admin unit" title="Your new admin unit" srcset="https://substackcdn.com/image/fetch/$s_!f-75!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png 424w, https://substackcdn.com/image/fetch/$s_!f-75!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png 848w, https://substackcdn.com/image/fetch/$s_!f-75!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png 1272w, https://substackcdn.com/image/fetch/$s_!f-75!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8024bc8-7751-44dd-ad3b-48c66a4a4586_1785x263.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Click on &#8220;<strong>Roles and administrators</strong>&#8221; and choose the new custom role from the list.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GPdn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GPdn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png 424w, https://substackcdn.com/image/fetch/$s_!GPdn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png 848w, https://substackcdn.com/image/fetch/$s_!GPdn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png 1272w, https://substackcdn.com/image/fetch/$s_!GPdn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GPdn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png" width="1456" height="560" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:560,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72566,&quot;alt&quot;:&quot;The Admin Units role and administrators&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The Admin Units role and administrators" title="The Admin Units role and administrators" srcset="https://substackcdn.com/image/fetch/$s_!GPdn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png 424w, https://substackcdn.com/image/fetch/$s_!GPdn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png 848w, https://substackcdn.com/image/fetch/$s_!GPdn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png 1272w, https://substackcdn.com/image/fetch/$s_!GPdn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3ee2297-f8f5-43b1-a112-b750e3cfee2a_1775x683.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In Assignments, click &#8220;<strong>Add assignments</strong>&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rnt7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rnt7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png 424w, https://substackcdn.com/image/fetch/$s_!rnt7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png 848w, https://substackcdn.com/image/fetch/$s_!rnt7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png 1272w, https://substackcdn.com/image/fetch/$s_!rnt7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rnt7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png" width="892" height="289" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:289,&quot;width&quot;:892,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20739,&quot;alt&quot;:&quot;Add assignments&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Add assignments" title="Add assignments" srcset="https://substackcdn.com/image/fetch/$s_!rnt7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png 424w, https://substackcdn.com/image/fetch/$s_!rnt7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png 848w, https://substackcdn.com/image/fetch/$s_!rnt7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png 1272w, https://substackcdn.com/image/fetch/$s_!rnt7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd241c703-3260-4f7e-8d58-bd9cb933c6ce_892x289.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You can see on the next screen, we are assigning the &#8220;Restricted AU Groups Administrator&#8221; role with the &#8220;Scope Type&#8221; of Administrative Unit and the selected scope is our new Entitlement Management AU. If that lines up, click on &#8220;<strong>No member selected</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cRcr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cRcr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png 424w, https://substackcdn.com/image/fetch/$s_!cRcr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png 848w, https://substackcdn.com/image/fetch/$s_!cRcr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png 1272w, https://substackcdn.com/image/fetch/$s_!cRcr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cRcr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png" width="562" height="646" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:646,&quot;width&quot;:562,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23388,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cRcr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png 424w, https://substackcdn.com/image/fetch/$s_!cRcr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png 848w, https://substackcdn.com/image/fetch/$s_!cRcr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png 1272w, https://substackcdn.com/image/fetch/$s_!cRcr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b09e6e-7ed4-42ea-a6a0-eeeed18785d8_562x646.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>In the search box enter &#8220;<strong>ec245c98-4a90-40c2-955a-88b727d97151</strong>&#8220;, you can see this will add a new column, Enterprise Applications (Service Principals) and you should see the Service Principal for Identity Governance, select this service principal.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_DcP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_DcP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png 424w, https://substackcdn.com/image/fetch/$s_!_DcP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png 848w, https://substackcdn.com/image/fetch/$s_!_DcP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png 1272w, https://substackcdn.com/image/fetch/$s_!_DcP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_DcP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png" width="1076" height="432" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:432,&quot;width&quot;:1076,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:27292,&quot;alt&quot;:&quot;Selecting a service principal&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Selecting a service principal" title="Selecting a service principal" srcset="https://substackcdn.com/image/fetch/$s_!_DcP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png 424w, https://substackcdn.com/image/fetch/$s_!_DcP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png 848w, https://substackcdn.com/image/fetch/$s_!_DcP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png 1272w, https://substackcdn.com/image/fetch/$s_!_DcP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d0395de-1dd4-478c-88e6-353acb342bb2_1076x432.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Note the warning that applications are only allowed for active assignments, this is great as we always want Identity Governance to have these permissions.  Click &#8220;<strong>Next</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_aJv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_aJv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png 424w, https://substackcdn.com/image/fetch/$s_!_aJv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png 848w, https://substackcdn.com/image/fetch/$s_!_aJv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png 1272w, https://substackcdn.com/image/fetch/$s_!_aJv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_aJv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png" width="614" height="583" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:583,&quot;width&quot;:614,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:13723,&quot;alt&quot;:&quot;Permanently assigned&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Permanently assigned" title="Permanently assigned" srcset="https://substackcdn.com/image/fetch/$s_!_aJv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png 424w, https://substackcdn.com/image/fetch/$s_!_aJv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png 848w, https://substackcdn.com/image/fetch/$s_!_aJv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png 1272w, https://substackcdn.com/image/fetch/$s_!_aJv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ef2e336-04af-4833-9087-1b78eac1ef42_614x583.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Make the assignment permeant and Input something useful for other administrators to understand why this role assignment exists and then click &#8220;<strong>Assign</strong>&#8221;.</p><p>At this point I should mention that you could also assign this role to PIM using the same method but using the service principal Id of &#8220;01fc33a7-78ba-4d2f-a4b7-768e336e890e&#8221; (MS-PIM).  You could then create an AU for PIM controlled groups although managing &#8220;role assignable&#8221; groups in this way is not possible.</p><p><strong>Step 3</strong>.  All that&#8217;s left is to add groups to the admin unit.  You can create new groups within the AU or you can add existing groups. (Just make sure you are happy with the current group membership when you do that - See Part 3 coming soon)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WYfW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WYfW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png 424w, https://substackcdn.com/image/fetch/$s_!WYfW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png 848w, https://substackcdn.com/image/fetch/$s_!WYfW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png 1272w, https://substackcdn.com/image/fetch/$s_!WYfW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WYfW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png" width="1030" height="322" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:322,&quot;width&quot;:1030,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22967,&quot;alt&quot;:&quot;Adding groups to the new AU&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Adding groups to the new AU" title="Adding groups to the new AU" srcset="https://substackcdn.com/image/fetch/$s_!WYfW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png 424w, https://substackcdn.com/image/fetch/$s_!WYfW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png 848w, https://substackcdn.com/image/fetch/$s_!WYfW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png 1272w, https://substackcdn.com/image/fetch/$s_!WYfW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a3ca3f-cf12-44b6-b70a-49a137d3b4f9_1030x322.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And that&#8217;s it, the only thing that can add users to a group in our AU is Entitlement Management. If another admin tries to sneak someone in because of the old classic the classic &#8220;boss says add them now&#8221;, this is what they&#8217;ll see.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9d6c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9d6c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png 424w, https://substackcdn.com/image/fetch/$s_!9d6c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png 848w, https://substackcdn.com/image/fetch/$s_!9d6c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png 1272w, https://substackcdn.com/image/fetch/$s_!9d6c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9d6c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png" width="1191" height="456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:456,&quot;width&quot;:1191,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35711,&quot;alt&quot;:&quot;Warning for groups controlled contained within an AU.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.identitycrisis.net/i/172340202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Warning for groups controlled contained within an AU." title="Warning for groups controlled contained within an AU." srcset="https://substackcdn.com/image/fetch/$s_!9d6c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png 424w, https://substackcdn.com/image/fetch/$s_!9d6c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png 848w, https://substackcdn.com/image/fetch/$s_!9d6c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png 1272w, https://substackcdn.com/image/fetch/$s_!9d6c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65cbb45-7ad6-4109-958c-9510105b074e_1191x456.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Sorry mate, this request needs to go via an access package.</p><p>Technically, someone could PIM into the Restricted AU Groups Admin role in an emergency and add users. But (1) it&#8217;s audited, and (2) honestly, why? Assigning the access package is just as quick.</p><p><strong>Coming Up Next: Part 3 - The Migration</strong></p><p>In this post, we focused on the implementation: creating a restricted Administrative Unit, wiring up a custom role for Entitlement Management, and moving your groups inside so every membership flows through proper governance.</p><p>In Part 3, I&#8217;ll take it a step further and show you my process for onboarding existing group members into access packages - because setting up the velvet rope is one thing, but getting everyone already inside the club to leave, line up and come through the front door again, is another.</p><p>Locking it down in practice is good, migrating cleanly is even better.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.identitycrisis.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity Crisis - &#8220;An Impostor&#8217;s Guide to IAM"! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Entitlement Management isn't enough! - Lock down your Entra groups.]]></title><description><![CDATA[&#8220;How to prevent rogue admins and group owners from undermining your access package strategy.&#8221;]]></description><link>https://www.identitycrisis.net/p/entitlement-management-isnt-enough</link><guid isPermaLink="false">https://www.identitycrisis.net/p/entitlement-management-isnt-enough</guid><dc:creator><![CDATA[Patrick Horne]]></dc:creator><pubDate>Fri, 22 Aug 2025 09:56:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Bxz5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Part 1: Rogue Admins and Group Owners vs. Your Access Packages</strong></p><p>Administrators have used groups to control access to resources since God was a boy. The old AGDLP (or AGUDLP, depending on how you learned it) model worked well for years and should still be second nature for managing access in on-premises Active Directory.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bxz5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bxz5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Bxz5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Bxz5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Bxz5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bxz5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1989929,&quot;alt&quot;:&quot;God dictating AGDLP&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://hornep.substack.com/i/171629357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="God dictating AGDLP" title="God dictating AGDLP" srcset="https://substackcdn.com/image/fetch/$s_!Bxz5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Bxz5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Bxz5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Bxz5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720e128c-4c54-4750-9d09-95f2e922d648_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>But the world has moved on. With the advent and evolution of Entra ID, we now have more powerful ways of managing access in the cloud. Features such as Entitlement Management, Access Packages, and Access Reviews provide capabilities that traditional AD groups never could.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!18Mj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!18Mj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png 424w, https://substackcdn.com/image/fetch/$s_!18Mj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png 848w, https://substackcdn.com/image/fetch/$s_!18Mj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png 1272w, https://substackcdn.com/image/fetch/$s_!18Mj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!18Mj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png" width="728" height="162.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:325,&quot;width&quot;:1456,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:46107,&quot;alt&quot;:&quot;The benefits of Access Packages&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://hornep.substack.com/i/171629357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="The benefits of Access Packages" title="The benefits of Access Packages" srcset="https://substackcdn.com/image/fetch/$s_!18Mj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png 424w, https://substackcdn.com/image/fetch/$s_!18Mj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png 848w, https://substackcdn.com/image/fetch/$s_!18Mj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png 1272w, https://substackcdn.com/image/fetch/$s_!18Mj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34198820-2b68-42ad-b5bc-2effbb8e3b11_1576x352.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>There is a problem though.</p><p>When you add a group as a resource in an Access Package, there is nothing stopping a group owner or an admin with no respect for process from bypassing governance and adding users directly to that group.</p><p>And just like that, your carefully designed access package strategy is toast.</p><p>In this post, I will explain the issue; why group owners and rogue admins are a risk, and the approach I use to stop it.</p><p>In Part 2, I will walk through the technical steps to implement the solution in Entra ID.</p><div><hr></div><p><strong>The Problem: Backdoors to Your Process</strong></p><p>Think about it. You have built a clean entitlement management process: requests, approvals, reviews, lifecycle management. Everything flows through clear governance controls.</p><p>But if a group owner adds a user directly, all of that work is bypassed. The access exists, and while you might catch it eventually with an access review, how long might that be?</p><p>You could also set up monitoring and alerts for changes in group membership, and if the access is particularly sensitive, you probably should. But alerts are still after the fact. By the time you are investigating, the access has already been granted, and the horse has bolted from the stable.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8dZR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8dZR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png 424w, https://substackcdn.com/image/fetch/$s_!8dZR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png 848w, https://substackcdn.com/image/fetch/$s_!8dZR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png 1272w, https://substackcdn.com/image/fetch/$s_!8dZR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8dZR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png" width="1456" height="334" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:334,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Azure monitor alerts&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Azure monitor alerts" title="Azure monitor alerts" srcset="https://substackcdn.com/image/fetch/$s_!8dZR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png 424w, https://substackcdn.com/image/fetch/$s_!8dZR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png 848w, https://substackcdn.com/image/fetch/$s_!8dZR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png 1272w, https://substackcdn.com/image/fetch/$s_!8dZR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1737e58c-7f71-4de5-b7a3-464401ff4202_1920x440.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>What we are really after is a way to stop it from happening in the first place. Prevention beats detection every time.</p><div><hr></div><p><strong>The Solution: Restricted Administrative Units</strong></p><p>Here is the approach I use:</p><ol><li><p><strong>Create a restricted Administrative Unit (AU)</strong> in Entra ID.</p></li><li><p><strong>Move the groups</strong> used in Access Packages into that AU.</p></li><li><p><strong>Grant Entitlement Management </strong>the rights it needs within the AU.</p></li></ol><p>What this achieves:</p><ul><li><p>Group owners and admins cannot add members behind the scenes.</p></li><li><p>All membership changes flow through Entitlement Management.</p></li><li><p>PIM still provides just-in-time access to manage the AU when needed.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FrF-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FrF-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png 424w, https://substackcdn.com/image/fetch/$s_!FrF-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png 848w, https://substackcdn.com/image/fetch/$s_!FrF-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png 1272w, https://substackcdn.com/image/fetch/$s_!FrF-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FrF-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png" width="1456" height="199" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:199,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:38276,&quot;alt&quot;:&quot;Restricted administrative unit&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://hornep.substack.com/i/171629357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Restricted administrative unit" title="Restricted administrative unit" srcset="https://substackcdn.com/image/fetch/$s_!FrF-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png 424w, https://substackcdn.com/image/fetch/$s_!FrF-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png 848w, https://substackcdn.com/image/fetch/$s_!FrF-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png 1272w, https://substackcdn.com/image/fetch/$s_!FrF-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc27b51b0-6dd8-4dff-b55b-9b2bb56b02d9_1521x208.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div><hr></div><p><strong>What About Group Owners?</strong></p><p>"Can&#8217;t group owners just add users?"</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LKhG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LKhG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png 424w, https://substackcdn.com/image/fetch/$s_!LKhG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png 848w, https://substackcdn.com/image/fetch/$s_!LKhG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png 1272w, https://substackcdn.com/image/fetch/$s_!LKhG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LKhG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png" width="977" height="298" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:298,&quot;width&quot;:977,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35536,&quot;alt&quot;:&quot;Entra ID group owners&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://hornep.substack.com/i/171629357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Entra ID group owners" title="Entra ID group owners" srcset="https://substackcdn.com/image/fetch/$s_!LKhG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png 424w, https://substackcdn.com/image/fetch/$s_!LKhG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png 848w, https://substackcdn.com/image/fetch/$s_!LKhG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png 1272w, https://substackcdn.com/image/fetch/$s_!LKhG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbce7e1b-a573-4dee-bcd7-85e3531cee29_977x298.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Yes, and that is part of the problem. By default, group owners can add or remove members. That bypasses your processes and makes governance meaningless.</p><p>The trick is to separate business accountability from technical control. Groups should still have owners. They are the ones who understand what the group is for, why it exists, what type of access it represents, and whether it is still needed as part of its lifecycle. They are essential for approvals, reviews, audits, and deciding when a group has outlived its purpose.</p><p>But once the groups move into a restricted AU, owners lose the ability to change membership directly. They still own the group in a business sense, but every change to membership goes through Entitlement Management. That way changes can be reviewed, tracked, audited and revoked when no longer appropriate.</p><p>That way you get the best of both worlds:</p><ul><li><p>Business accountability from owners.</p></li><li><p>Governance and enforcement from Entitlement Management.</p></li></ul><p><strong>Bonus tip: </strong>Make the group owner the approver of the access package? That way we are still giving control to the resource owners while ensuring the governance is handled by Entra.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n92E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n92E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png 424w, https://substackcdn.com/image/fetch/$s_!n92E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png 848w, https://substackcdn.com/image/fetch/$s_!n92E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png 1272w, https://substackcdn.com/image/fetch/$s_!n92E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n92E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png" width="855" height="320" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:320,&quot;width&quot;:855,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22696,&quot;alt&quot;:&quot;Access package approvers&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://hornep.substack.com/i/171629357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Access package approvers" title="Access package approvers" srcset="https://substackcdn.com/image/fetch/$s_!n92E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png 424w, https://substackcdn.com/image/fetch/$s_!n92E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png 848w, https://substackcdn.com/image/fetch/$s_!n92E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png 1272w, https://substackcdn.com/image/fetch/$s_!n92E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d619032-7bea-421d-a083-435e32a2e0a7_855x320.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><strong>What About Rogue Admins?</strong></p><p>It is not just group owners you need to worry about. In many environments, administrators have broad rights over groups by default. That means another admin could still add or remove members directly, bypassing your carefully designed access package strategy.</p><p>Restricted Administrative Units stop this as well. By moving groups into a Restricted AU and limiting who can manage them, you close off this backdoor. Regular admins lose direct control. If someone needs to make changes, they must go through PIM.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FPyt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FPyt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png 424w, https://substackcdn.com/image/fetch/$s_!FPyt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png 848w, https://substackcdn.com/image/fetch/$s_!FPyt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png 1272w, https://substackcdn.com/image/fetch/$s_!FPyt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FPyt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png" width="1148" height="251" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:251,&quot;width&quot;:1148,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:39030,&quot;alt&quot;:&quot;Can't add users to this group&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://hornep.substack.com/i/171629357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Can't add users to this group" title="Can't add users to this group" srcset="https://substackcdn.com/image/fetch/$s_!FPyt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png 424w, https://substackcdn.com/image/fetch/$s_!FPyt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png 848w, https://substackcdn.com/image/fetch/$s_!FPyt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png 1272w, https://substackcdn.com/image/fetch/$s_!FPyt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4327528e-83a1-41d6-8cd5-2c7d6c2cd6d3_1148x251.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">caption...</figcaption></figure></div><p><strong>In other words:</strong></p><ul><li><p>Day-to-day admins cannot tamper with membership.</p></li><li><p>Elevated access must go through PIM, which adds approval, time limits, and auditing.</p></li><li><p>Entitlement Management remains the single source of truth for access.</p></li></ul><div><hr></div><p><strong>Why This Works</strong></p><p>By moving those groups into a restricted AU, you are effectively putting them behind a velvet rope:</p><ul><li><p>Governance is preserved.</p></li><li><p>Business owners are still accountable.</p></li><li><p>Reviews stay accurate.</p></li><li><p>And your auditors do not chase you down asking why Bob from Finance magically appeared in the "Global Admin Test" group.</p></li></ul><p>It is not glamorous, but it is clean, effective, and makes sure your Access Package strategy actually works as designed.</p><p><strong>Coming Up Next: Part 2 - The Implementation</strong></p><p>In this post, we focused on the issue: how group owners and admins can bypass your carefully crafted access package strategy, and how restricted Administrative Units can close that backdoor.</p><p>In <a href="https://www.identitycrisis.net/p/entitlement-management-isnt-enough-part2">Part 2</a>, I will show you the step-by-step implementation:</p><ul><li><p>How to create a restricted Administrative Unit and move your groups into it.</p></li><li><p>How to configure PIM and Entitlement Management so you keep governance without losing flexibility.</p></li></ul><p>Locking it down in theory is good, but locking it down in practice is even better.</p>]]></content:encoded></item><item><title><![CDATA[Coming soon]]></title><description><![CDATA[This is Identity Crisis - &#8220;An Impostor&#8217;s Guide to IAM&#34;.]]></description><link>https://www.identitycrisis.net/p/coming-soon</link><guid isPermaLink="false">https://www.identitycrisis.net/p/coming-soon</guid><dc:creator><![CDATA[Patrick Horne]]></dc:creator><pubDate>Tue, 24 Jun 2025 19:54:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VIs5!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f72147f-839b-4f7e-b7ed-ab01f164ffa7_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is Identity Crisis - &#8220;An Impostor&#8217;s Guide to IAM&#34;.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.identitycrisis.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.identitycrisis.net/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item></channel></rss>