Chapter 4
Management groups are a great way of granting roles to users in a hierarchical manner that fits a company's geographical or divisional structure. In this scenario, the Global Administrator role would be set at the root tenant-level; however, for each region, a nominated administrator account could be set as Owner that only applied to a geographic management group.
Further service line groups could then be set within each country where the Owner Azure Role could be set on nominated IT Champions. The structure would look as follows:
Example RBAC hierarchy
To apply the least privileged principle, AD Manager roles (such as User Administrator) would be assigned to users as an eligible role, with the IT Champion set as the approver. Yearly access reviews would also be applied to these roles.
Create risk policies that deny access should a score of high be met, and a separate policy to force a password change on medium and above.
Finally, to support these actions...