Identity & Access
Organisational RBAC Framework
A tiered, dual-layer role-based access model — privileged application access kept structurally separate from operational support access — aligned to modern IDAM and PAM platforms rather than any single vendor.
Model
A dual-layer RBAC model
Privileged application access and operational support access are deliberately kept as two separate group hierarchies. Blending them is one of the most common ways a support-desk compromise turns into a domain-wide incident.
App Priv Access Group — privileged application access
Priv Tier 0
Global Admins
Domain- and directory-wide access; highest-privilege application administrators.
Membership: Direct user assignment via a controlled, time-bound process. No nested group membership permitted.
Priv Tier 1
Server & workstation admins (global)
Administrative rights over servers and workstations at global scope.
Membership: Only access-assign groups permitted as members — no direct user assignment.
Priv Tier 2
Delegated admins (regional)
Delegated server and workstation administration at regional scope, plus global reader access.
Membership: AD/Entra role groups allowed as members. No direct user access.
Std Tier 3
Standard users
No privileged access by default — standard application and productivity access only.
Membership: Direct user access is permitted; group membership requires a documented exemption.
AccessAssign — support group
Support L1
Service desk
Support team, designated IT teams and service desk — first-line resolution.
Membership: No AD/Entra groups as members permitted; users-only group.
Support L2
IT project partner
IT project partners and support team members handling escalated issues.
Membership: No AD/Entra groups as members permitted; users-only group.
Support L3
Designated IT
IT project partners, support team and designated IT for the most sensitive escalations.
Membership: No AD/Entra groups as members permitted; users-only group.
Governance flow
How access is requested, approved and reviewed
Every tier — privileged or support — moves through the same governed path, whether the request originates from a service owner, an access manager, security, or a service partner.
Request for access
Service owner, GAM or service partner raises a request
Change / service management
IT change management or service request fulfilment intake
Approval
Business and security approval recorded against the request
Provisioning
Access-assign or app-privileged group membership updated
Time-bound activation
Manual or PIM-based activation for a fixed duration
Periodic access review
Certification confirms access is still required
Platform alignment
Aligning to modern IDAM & PAM platforms
This framework is deliberately vendor-agnostic — Entra ID provides the native directory and Conditional Access layer, and each capability below maps to where a specialist IDAM or PAM platform typically extends it.
Identity governance & lifecycle
SailPoint- Principle
- Joiner-mover-leaver is a governed process, not a helpdesk ticket queue.
- Decision
- SailPoint IdentityIQ/IdentityNow is the system of record for identity lifecycle and entitlement certification, feeding Entra ID as the authentication directory.
- Implementation
- HR-triggered joiner/mover/leaver workflows provision and deprovision Entra ID and application entitlements automatically.
- Guardrail
- Leaver events revoke access within a defined SLA; certification campaigns run on a fixed quarterly cadence.
- Example
- A Contoso role change from Finance to Engineering triggers automatic removal of Priv Tier 2 finance-system access.
Workforce SSO & adaptive access
Okta / Entra ID- Principle
- One identity, one strong authentication event, enforced consistently.
- Decision
- Entra ID (or Okta, where a multi-IdP estate applies) is the single sign-on and adaptive MFA layer for every application tier.
- Implementation
- Conditional Access / adaptive policies scale authentication strength to the sensitivity of the tier being accessed.
- Guardrail
- Priv Tier 0 and 1 access always requires phishing-resistant MFA; standard tier access follows risk-based policy.
- Example
- A Priv Tier 0 sign-in from an unmanaged device is blocked outright rather than stepped up.
Access request & certification
SailPoint / Entra Access Reviews- Principle
- Every grant of access has a visible requester, approver and expiry.
- Decision
- Access requests flow through a single request-for-access process regardless of which tier is being requested.
- Implementation
- IT Service Request Fulfilment and IT Change Management intake feed the same approval and audit trail.
- Guardrail
- Access without a corresponding approved request is treated as a compliance finding, not a convenience.
- Example
- A Service Partner's request for AccessAssign Level 2 access is approved by Global Security before provisioning.
Privileged session management & vaulting
CyberArk- Principle
- Privileged credentials are never known to, or held by, the human using them.
- Decision
- CyberArk vaults and rotates credentials for Priv Tier 0 and Tier 1 accounts and brokers all privileged sessions.
- Implementation
- Session recording and isolation for every Priv Tier 0/1 connection, routed through the CyberArk PSM layer.
- Guardrail
- Direct RDP/SSH to Tier 0/1 systems outside the vaulted session path is blocked at the network layer.
- Example
- A Global Admin action against Contoso's domain controllers is recorded end-to-end via a CyberArk session.
Just-in-time privileged elevation
Delinea- Principle
- Privilege exists only for the duration it's needed, not by default.
- Decision
- Delinea (or Entra PIM for cloud-native roles) grants time-bound elevation for Tier 1 and Tier 2 access.
- Implementation
- Requesters activate a role for a fixed window (typically up to 4 hours); activation requires approval and justification.
- Guardrail
- Standing privileged role assignment is disallowed by policy outside documented break-glass accounts.
- Example
- A Priv Tier 1 server admin activates elevated access via Delinea for a scheduled 2-hour maintenance window.
Break-glass & emergency access
CyberArk / Delinea + Entra PIM- Principle
- Emergency access exists, is tightly controlled, and is never invisible.
- Decision
- A small number of break-glass accounts are excluded from standard Conditional Access and vaulted separately.
- Implementation
- Break-glass credential checkout triggers immediate alerting to Global Security and a mandatory post-use review.
- Guardrail
- Break-glass accounts are monitored continuously; any use outside a declared incident triggers an audit.
- Example
- A break-glass account used during a Contoso Entra ID outage is reviewed by Global Security within 24 hours.