Introduction
You set up a safeguard for one of Relecloud's most sensitive admin roles: activation now requires approval before anyone can start using it. You leave the approver list empty for the moment, planning to fill it in once you decide who should hold that responsibility—confident that until you do, no one can activate the role.
The first activation request comes in the next morning. It's approved within the hour, by someone you never added to any list.
So who signed off, why did they have the authority to, and what does that mean for every other privileged role in Relecloud's tenant?
Relecloud is scaling fast enough that this kind of question keeps surfacing. A new engineering office overseas needs dozens of new hires provisioned at once. Woodgrove Bank's fraud analysts need guest access to a joint investigation project—but only to that project, nothing else. And too many people at Relecloud still hold standing Global Administrator access, for no better reason than "it was easier to set up that way."
What you'll learn
- Manage the full user and contact lifecycle across the Microsoft 365 and Microsoft Entra admin centers.
- Bulk-provision new hires with Microsoft Graph PowerShell, requesting the least-privileged scope for the task.
- Invite external partners as guests, govern their access, and delegate invitations through the Guest Inviter role.
- Create Microsoft 365 groups and security groups with naming and expiration policies, and recognize how nesting resolves membership.
- Scope a delegated administrator role to one slice of the directory using administrative units.
- Move privileged roles to just-in-time access with Privileged Identity Management, including approvals and eligible assignments.
By the end of this module, you can populate and govern a Microsoft Entra directory under least privilege at scale: managing users, contacts, and groups; delegating guest and administrative unit access without over-granting; and moving privileged roles to just-in-time access with Privileged Identity Management.