DiscoverEntra.ChatPushing Microsoft Entra to its Limits to Secure On-Prem AD
Pushing Microsoft Entra to its Limits to Secure On-Prem AD

Pushing Microsoft Entra to its Limits to Secure On-Prem AD

Update: 2025-06-20
Share

Description

In this episode, we talk with an identity expert, ex-Microsoftie and Principal Domain Architect, Mark Renoden, about creating a modern Privileged Access Management (PAM) solution for on-premises Active Directory. Discover how to build a secure "Bastion Forest" architecture using Microsoft Entra. We talk about PIM for Groups, group write-back, phish-resistant credentials, Privileged Access Workstations (PAW), securing an Entra tenant from the ground up, and navigating challenges with Cloud Solution Provider (CSP) permissions.

Watch on YouTube

PS. Can I ask a favor? If you enjoyed this episode please leave a review and rating! Thank you πŸ™ - Merill

About Mark

As Principal Domain Architect for Identity at Increment, Mark leads the design and delivery of secure, scalable identity architectures grounded in Microsoft Entra ID and aligned with Zero Trust principles. He specializes in helping organisations modernise their infrastructure and navigate complex identity transformations.

Previous to Increment, Mark spent over 20 years at Microsoft in support, field engineering, mission critical and customer experience roles focused on Identity across a wide spectrum of industries in Australia and New Zealand, including Finance, Healthcare, Government, Education and Retail.

LinkedIn - https://www.linkedin.com/in/markrenoden/

πŸ”— Related Links

* DirectoryShield | Increment - https://www.increment.inc/directoryshield

* Entra Security Recommendations - https://aka.ms/EntraSecurityRecommendations

* Securing privileged access overview - https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-overview

* MIM - Bastion environment - https://learn.microsoft.com/en-us/microsoft-identity-manager/pam/planning-bastion-environment

πŸ“— Chapters

00:46 Securing Your Entra Tenant

02:09 The Quest for a Microsoft-Only PAM Solution

04:21 What is a "Bastion Forest"?

07:50 Reimagining the Bastion Forest for the Cloud

12:53 Architecting a "Secure-by-Default" Tenant

17:41 Phish-Resistant On-Prem Admins

19:50 The Modern Privileged Access Workstation (PAW)

27:04 The Tiered Administration Model Explained

29:51 The Hidden Dangers of CSP Admin Access

34:29 How Fast is PIM for Groups?

Podcast Apps

πŸŽ™οΈ Entra.Chat - https://entra.chat

🎧 Apple Podcast β†’ https://entra.chat/apple

πŸ“Ί YouTube β†’ https://entra.chat/youtube

πŸ“Ί Spotify β†’ https://entra.chat/spotify

🎧 Overcast β†’ https://entra.chat/overcast

🎧 Pocketcast β†’ https://entra.chat/pocketcast

🎧 Others β†’ https://entra.chat/rss

Merill's socials

πŸ“Ί YouTube β†’ youtube.com/@merillx

πŸ‘” LinkedIn β†’ linkedin.com/in/merill

🐀 Twitter β†’ twitter.com/merill

πŸ•Ί TikTok β†’ tiktok.com/@merillf

πŸ¦‹ Bluesky β†’ bsky.app/profile/merill.net

🐘 Mastodon β†’ infosec.exchange/@merill

🧡 Threads β†’ threads.net/@merillf

πŸ€– GitHub β†’ github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
CommentsΒ 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Pushing Microsoft Entra to its Limits to Secure On-Prem AD

Pushing Microsoft Entra to its Limits to Secure On-Prem AD

Merill Fernando