← Other Athentra features

Module: Control · Execution

Delegated Execution

Where Microsoft only exposes an action to a delegated identity, an administrator can authorise a control to run as them. The grant is held per person rather than shared tenant-wide, so the action is attributable to an individual. Automation reaches those actions without anyone creating a standing privileged account.

  1. 01

    Pain Point

    What's the problem?

    Some Microsoft actions are only exposed to a signed-in person, and no application credential can perform them.

  2. 02

    Remedy

    How do we attack it?

    Authorise a control to run as you, using a grant held per person rather than tenant-wide

  3. 03

    Your Value

    What do you get out of it?

    Reaches the actions application permissions cannot, without a shared privileged account