Managing access
Access is the explicit bond: this person may sign in to this resource — optionally narrowed to a specific Windows account, a protocol, and an end date.
What an access defines
Section titled “What an access defines”| Dimension | Options |
|---|---|
| Person | Who it belongs to (email identity) |
| Resource | Which machine |
| Account | Which Windows login account (or account-wide) |
| Decision | Allow or Deny |
| Protocol | Console, RDP — or all the resource allows |
| Expiry | Permanent, or an end date (time-boxed / just-in-time) |
One person can hold access to several accounts on the same machine, and to many machines — always with the same single authenticator.
Granting
Section titled “Granting”Access is created when you invite a person to a resource account, or from the person’s page. Granting access to an already-enrolled person takes effect immediately (they just get a notification email).
Denying and removing
Section titled “Denying and removing”- Deny keeps the record but blocks sign-in — useful to suspend one access without deleting history.
- Remove deletes the access. The person receives a passive security notice (“your access was removed”) with no instructions — informative, not actionable.
- Either way, the person’s other accesses and their authenticator are untouched.
Time-boxed access
Section titled “Time-boxed access”Set an expiry when the need is temporary (a contractor, an incident, a migration). When the date passes, sign-in is refused with the access expired reason — nothing to remember to clean up.
Zero-trust option
Section titled “Zero-trust option”By default, a person with no access is simply denied when the resource enforces grants — and you can make this strict per resource with the enforce grants policy: no access record ⇒ no sign-in, full stop. See sign-in policies.
Where to see it all
Section titled “Where to see it all”A person’s page lists every access they hold across resources — one place to review and revoke. The audit log records each grant, change, and removal with who did it.