Security Domains

Identity & Access

Identity and access management provides the foundation of the enterprise security architecture. It ensures that users, administrators and devices can securely access enterprise resources according to their assigned responsibilities.

Overview

Identity is the primary security boundary within Brunner Security Labs. Every user, administrator and managed device must establish a trusted identity before accessing enterprise resources.

Microsoft Entra ID provides the central identity platform for the lab. It supports authentication, authorization, administrative role management, device identities and integration with Microsoft 365, Microsoft Intune, Defender for Endpoint and Microsoft Sentinel.

Business Need

Cloud services and remote access have reduced the effectiveness of the traditional network perimeter. Access decisions can no longer rely only on whether a device is located inside a corporate network.

Enterprise resources therefore require a central identity system capable of verifying who is requesting access, what privileges the identity possesses and whether additional authentication controls are required.

Security objective

Ensure that access to enterprise resources is authenticated, authorized, traceable and limited according to business need.

Architecture

Microsoft Entra ID acts as the central identity provider. Users authenticate through Entra ID before accessing Microsoft 365 and the security services connected to the lab.

Users and Administrators
Microsoft Entra ID
Microsoft 365
Microsoft Intune
Security Services

Device identities are also registered in Entra ID. This establishes the connection between users, managed Windows devices and the security controls applied through Microsoft Intune and Defender for Endpoint.

Implementation

Microsoft Entra tenant

A dedicated Microsoft tenant provides the identity and service foundation for Brunner Security Labs. The tenant is connected to Microsoft 365, Microsoft Intune, Defender for Endpoint and Microsoft Sentinel.

Microsoft Entra tenant overview for Brunner Security Labs
Figure 1. Microsoft Entra ID tenant overview. The tenant provides the central identity platform for Brunner Security Labs and supports the connected Microsoft security services.

🔍 Key Observations

  • Microsoft Entra ID provides the central identity platform for the environment.
  • The dedicated tenant separates the lab from unrelated personal environments.
  • Microsoft Entra ID P1 capabilities are available within the tenant.
  • The tenant provides the identity foundation for Microsoft 365 and Microsoft Intune.
  • Tenant identifiers and temporary domain information are redacted from the published evidence.

Users, groups and administrative roles

Security and Microsoft 365 groups organize identities and devices according to their operational purpose. Dedicated groups support role-based administration, policy assignment and device targeting.

Security and Microsoft 365 groups configured in Microsoft Entra ID
Figure 2. Microsoft Entra ID groups. Dedicated groups organize administrators, security personnel, users and managed Windows devices.

🔍 Key Observations

  • Dedicated security groups separate administrative, security and standard-user responsibilities.
  • The DG-Windows-Clients group is used to organize managed Windows endpoints.
  • The SG-IT-Administrators group represents privileged administrative identities.
  • The SG-Security-Team group supports separation of security responsibilities.
  • Dynamic and assigned membership models are used according to the purpose of each group.

Authentication methods

Tenant-wide authentication method policies define which mechanisms users may register and use. Strong authentication methods reduce the risk that a compromised password alone can provide access to enterprise resources.

Microsoft Entra ID authentication methods policy
Figure 3. Authentication Methods Policy. Microsoft Entra ID defines which strong authentication mechanisms are available to users across the tenant.

🔍 Key Observations

  • Microsoft Authenticator is enabled for tenant users.
  • FIDO2 security keys are supported as a phishing-resistant authentication method.
  • Temporary Access Pass is enabled to support controlled onboarding and recovery scenarios.
  • Software OATH tokens are available as an additional authentication option.
  • SMS and voice-call authentication remain disabled because they provide weaker protection.

Device identity

The Windows lab endpoint is joined to Microsoft Entra ID and enrolled in Microsoft Intune. This creates a trusted device identity that can be evaluated by management, compliance and endpoint security services.

Windows endpoint joined to Microsoft Entra ID and managed by Microsoft Intune
Figure 4. Microsoft Entra joined Windows endpoint. The device is managed through Microsoft Intune and evaluated against organizational compliance requirements.

🔍 Key Observations

  • The Windows endpoint is Microsoft Entra joined.
  • Microsoft Intune provides mobile device management for the endpoint.
  • Security settings are also managed through Microsoft Intune.
  • The device is reported as compliant with the configured requirements.
  • The endpoint belongs to the DG-Windows-Clients device group.

Validation

Identity controls are validated through administrative records, device state and authentication telemetry.

  • User authentication succeeds with the expected identity.
  • Strong authentication methods are enabled through tenant-wide policies.
  • The Windows endpoint appears as a Microsoft Entra joined device.
  • Microsoft Intune reports the endpoint as managed and compliant.
  • Authentication events are recorded in Microsoft Entra sign-in logs.
Microsoft Entra sign-in logs showing successful authentication events
Figure 5. Microsoft Entra sign-in logs. Interactive authentication events are recorded centrally and provide evidence for auditing, troubleshooting and security monitoring.

🔍 Key Observations

  • Interactive user sign-ins are centrally logged by Microsoft Entra ID.
  • Each event can be associated with the application and resource that were accessed.
  • The event status provides evidence of successful or failed authentication attempts.
  • Sign-in telemetry supports auditing, troubleshooting and incident investigation.
  • Microsoft Entra sign-in data can be integrated with Microsoft Sentinel for centralized monitoring and detection.

Future Work

The next stage will strengthen identity protection by introducing more contextual, risk-based and privileged-access controls.

  • Conditional Access policies
  • Separate emergency access accounts
  • Passwordless authentication
  • Privileged Identity Management
  • Periodic access reviews
  • Identity risk monitoring