Skip to content
EntraOps Privileged EAM Automate Tiered Access Model for Conditional Access and Administrative Units

EntraOps Privileged EAM Automate Tiered Access Model for Conditional Access and Administrative Units

Written By Anoop C Nair
Last Updated August 16, 2024
Posted In Entra
SHARE

EntraOps Privileged EAM Automate Tiered Access Model for Conditional Access and Administrative Units! Microsoft developed new features aimed at automating the tiered administration of the Enterprise Access Model in Microsoft Entra.

These features are designed to simplify the management of privileged access and security within your organization. After updating to the latest version, you can enable these new capabilities, including automation for managing assignments, maintaining privileged assets, etc.

These enhancements will help you better manage and secure your enterprise access model. This post covers all the details about EntraOps Privileged EAM V0.2. It is now available with new automation features. EntraOps is a free community tool designed to manage and automate privileged access and security within Microsoft Entra.

On May 2nd, 2024, Microsoft announced that its consumer accounts now support Passkey. A passkey is a highly secure way to log in to websites and apps, using the latest technology known as W3C WebAuthN. It replaces traditional passwords with a more advanced method of authentication.

Patch My PC

EntraOps Privileged EAM V0.2 Now Available with New Automation Features

Let’s discuss the new capabilities to automate the tiered access model. The table below helps you to show more details. All credit to Thomas Naunheim.

Upload Data to WatchList – Managing classified privileged assets in Microsoft Sentinel WatchList templates, Ingestion of security posture data of Workload ID to WatchLists.

Apply Assignment for Privileged Users and Groups to (Restricted) Administrative Units: Delegating and managing objects on specific tiered level.

EntraOps Privileged EAM V0.2 Now Available with New Automation Features
Uploading data to WatchList
Assigning privileges for users and groups to restricted administrative units
Assigning unprotected assets to restricted administrative units
Applying group assignments for conditional access policies
EntraOps Privileged EAM Automate Tiered Access Model for Conditional Access and Administrative Units – Table 1

Apply Assignment for unprotected assets to (Restricted) Administrative Unit – Identifying users and groups without existing restricted management (RMAU, role-assignable group or Entra ID role) to protected them by assignment of RMAU.

Apply Group Assignment for Conditional Access Policies Assigning membership to security groups based on
classification level for Conditional Access policies.

EntraOps Privileged EAM Automate Tiered Access Model for Conditional Access and Administrative Units- Fig.1
EntraOps Privileged EAM Automate Tiered Access Model for Conditional Access and Administrative Units – Fig.1 – Credit to MS

Automated Management of Conditional Access Target Groups and Administrative Units

The latest update introduces automation for managing assignments related to Conditional Access target groups and Restricted Management Administrative Units. This automation shows classified privileged objects to simplify the assignment process. It ensures that the correct policies and management rules are applied based on classifying privileged assets.

  • This feature enhances efficiency and accuracy in managing access and permissions across your organization.

Automatic Maintenance for Privileged Assets in Microsoft Sentinel Watchlists

The new update includes automatic maintenance for privileged assets classified by EntraOps within Microsoft Sentinel watchlists. This feature ensures that VIP users, identity correlations, and high-value assets are consistently monitored and maintained.

By automating this process, you can keep your watchlists up-to-date with the latest classifications, improving the visibility and security of critical assets in your environment.

Deployment of Advanced Watchlists for Tracking Workload Identity Security Posture

Microsoft is rolling out advanced watchlists designed to monitor the security posture of Workload Identities. These watchlists will provide enhanced tracking and insights, helping to ensure that the security of your workload identities is maintained and any potential risks are promptly identified.

Updating EntraOps

It is essential to ensure you are using the latest version of EntraOps. Follow the below steps for more details. There are 3 steps: the first is to Update EntraOps, the second is to Configure New Features, and the third is to Assign New Permissions.

  1. Use the Update – EntraOps cmdlet in the PowerShell Module or follow the GitHub workflow to update EntraOps to its newest version. This ensures you have access to the latest features and improvements.
  2. Configure New Features – After updating, you must configure any new features in the EntraOps.config file. This file holds the configuration settings required for the latest features to function correctly.
  3. Assign New Permissions – Verify and assign any new permissions needed for EntraOps service principals. These permissions are crucial for the updated features to operate correctly and securely.
EntraOps Privileged EAM Automate Tiered Access Model for Conditional Access and Administrative Units - Fig.2 - Credit to MS
EntraOps Privileged EAM Automate Tiered Access Model for Conditional Access and Administrative Units – Fig.2 – Credit to MS

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP from 2015 onwards for consecutive 10 years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His main focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career etc…

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read