Pre-Built Azure AD Groups based on the SPA Roadmap

Brass Contributor

Since new GCC High deployments begin with no production users or data: is there some way we could receive guidance from MFST on a preferred Azure AD structure that maps to the Securing Privileged Access roadmap phases?

2 Replies

@rybo3000 can you clarify what you are looking for?  Are you looking for recommendations on separating accounts (User vs. Admin), ways to organize accounts in various security groups, or something else?

@dmcweeboth of those clarifications would be great. Many orgs are looking for suggestions on how to name their accounts, how to construct the security groups behind those accounts (dynamic vs assigned, etc.), and a "starter set" of admin role assignments and permissions to layer over top of the recommendations in the Securing Privileged Access roadmap.