Skip to content
Entra ID Lab

Phase 5 of 11

Tenant Properties and Roles

Overview

What was built

Phil Coulson, the IT Manager, needs to manage user accounts and groups, nothing more, so he was assigned User Administrator rather than Global Administrator, which would also hand him control over billing, security policies, and app registrations that his role never requires. Nick Fury, the Security Manager, needs visibility into security events, so he was assigned Security Reader, a read-only role, rather than Security Administrator, which would let him modify security policies he only needs to observe.

How it works

The walkthrough

Step 1 of 1

Assigning roles by job function, not convenience

Set the tenant display name to Stark Enterprise Lab and configured the technical and privacy contact fields under tenant properties.

Assigned both roles as Active rather than Eligible, to demonstrate straightforward least-privilege role assignment in this phase. Eligible assignments with PIM's just-in-time activation are covered separately and fully in Phase 9, once the eligible-versus-active distinction actually matters for a privileged role like Global Administrator.

Phil Coulson's assigned roles showing User Administrator
Phil Coulson assigned User Administrator, scoped to exactly what his role needs.