Skip to content
BeaconiXBlueprint

Identity & Access

Organisational RBAC Framework

A tiered, dual-layer role-based access model — privileged application access kept structurally separate from operational support access — aligned to modern IDAM and PAM platforms rather than any single vendor.

Model

A dual-layer RBAC model

Privileged application access and operational support access are deliberately kept as two separate group hierarchies. Blending them is one of the most common ways a support-desk compromise turns into a domain-wide incident.

App Priv Access Group — privileged application access

0

Priv Tier 0

Global Admins

Domain- and directory-wide access; highest-privilege application administrators.

Membership: Direct user assignment via a controlled, time-bound process. No nested group membership permitted.

1

Priv Tier 1

Server & workstation admins (global)

Administrative rights over servers and workstations at global scope.

Membership: Only access-assign groups permitted as members — no direct user assignment.

2

Priv Tier 2

Delegated admins (regional)

Delegated server and workstation administration at regional scope, plus global reader access.

Membership: AD/Entra role groups allowed as members. No direct user access.

3

Std Tier 3

Standard users

No privileged access by default — standard application and productivity access only.

Membership: Direct user access is permitted; group membership requires a documented exemption.

AccessAssign — support group

1

Support L1

Service desk

Support team, designated IT teams and service desk — first-line resolution.

Membership: No AD/Entra groups as members permitted; users-only group.

2

Support L2

IT project partner

IT project partners and support team members handling escalated issues.

Membership: No AD/Entra groups as members permitted; users-only group.

3

Support L3

Designated IT

IT project partners, support team and designated IT for the most sensitive escalations.

Membership: No AD/Entra groups as members permitted; users-only group.

Both hierarchies share the same rules: higher tiers forbid direct user assignment and accept only controlled group membership, while the lowest tier permits direct assignment precisely because it carries the least risk.

Governance flow

How access is requested, approved and reviewed

Every tier — privileged or support — moves through the same governed path, whether the request originates from a service owner, an access manager, security, or a service partner.

Request for access

Service owner, GAM or service partner raises a request

Change / service management

IT change management or service request fulfilment intake

Approval

Business and security approval recorded against the request

Provisioning

Access-assign or app-privileged group membership updated

Time-bound activation

Manual or PIM-based activation for a fixed duration

Periodic access review

Certification confirms access is still required

Platform alignment

Aligning to modern IDAM & PAM platforms

This framework is deliberately vendor-agnostic — Entra ID provides the native directory and Conditional Access layer, and each capability below maps to where a specialist IDAM or PAM platform typically extends it.

Identity governance & lifecycle

SailPoint
Principle
Joiner-mover-leaver is a governed process, not a helpdesk ticket queue.
Decision
SailPoint IdentityIQ/IdentityNow is the system of record for identity lifecycle and entitlement certification, feeding Entra ID as the authentication directory.
Implementation
HR-triggered joiner/mover/leaver workflows provision and deprovision Entra ID and application entitlements automatically.
Guardrail
Leaver events revoke access within a defined SLA; certification campaigns run on a fixed quarterly cadence.
Example
A Contoso role change from Finance to Engineering triggers automatic removal of Priv Tier 2 finance-system access.

Workforce SSO & adaptive access

Okta / Entra ID
Principle
One identity, one strong authentication event, enforced consistently.
Decision
Entra ID (or Okta, where a multi-IdP estate applies) is the single sign-on and adaptive MFA layer for every application tier.
Implementation
Conditional Access / adaptive policies scale authentication strength to the sensitivity of the tier being accessed.
Guardrail
Priv Tier 0 and 1 access always requires phishing-resistant MFA; standard tier access follows risk-based policy.
Example
A Priv Tier 0 sign-in from an unmanaged device is blocked outright rather than stepped up.

Access request & certification

SailPoint / Entra Access Reviews
Principle
Every grant of access has a visible requester, approver and expiry.
Decision
Access requests flow through a single request-for-access process regardless of which tier is being requested.
Implementation
IT Service Request Fulfilment and IT Change Management intake feed the same approval and audit trail.
Guardrail
Access without a corresponding approved request is treated as a compliance finding, not a convenience.
Example
A Service Partner's request for AccessAssign Level 2 access is approved by Global Security before provisioning.

Privileged session management & vaulting

CyberArk
Principle
Privileged credentials are never known to, or held by, the human using them.
Decision
CyberArk vaults and rotates credentials for Priv Tier 0 and Tier 1 accounts and brokers all privileged sessions.
Implementation
Session recording and isolation for every Priv Tier 0/1 connection, routed through the CyberArk PSM layer.
Guardrail
Direct RDP/SSH to Tier 0/1 systems outside the vaulted session path is blocked at the network layer.
Example
A Global Admin action against Contoso's domain controllers is recorded end-to-end via a CyberArk session.

Just-in-time privileged elevation

Delinea
Principle
Privilege exists only for the duration it's needed, not by default.
Decision
Delinea (or Entra PIM for cloud-native roles) grants time-bound elevation for Tier 1 and Tier 2 access.
Implementation
Requesters activate a role for a fixed window (typically up to 4 hours); activation requires approval and justification.
Guardrail
Standing privileged role assignment is disallowed by policy outside documented break-glass accounts.
Example
A Priv Tier 1 server admin activates elevated access via Delinea for a scheduled 2-hour maintenance window.

Break-glass & emergency access

CyberArk / Delinea + Entra PIM
Principle
Emergency access exists, is tightly controlled, and is never invisible.
Decision
A small number of break-glass accounts are excluded from standard Conditional Access and vaulted separately.
Implementation
Break-glass credential checkout triggers immediate alerting to Global Security and a mandatory post-use review.
Guardrail
Break-glass accounts are monitored continuously; any use outside a declared incident triggers an audit.
Example
A break-glass account used during a Contoso Entra ID outage is reviewed by Global Security within 24 hours.