Skip to content
const portfolio = { loading: true, status: 'initializing...'};
0%
back to home.tsx

~/case-studies/identity-security-posture

Identity Security Posture

Turning scattered identity signals into one prioritized recommendation — so admins can assess, understand and strengthen their security at a glance.

From a weekend hackathon to Microsoft Entra Public Preview.

Lead Product DesignerMicrosoft Entra · ISPMIdentity

3

PMs I led design across

20+

customer & partner previews

3

private-preview phases cleared

Public Preview

shipping next

The demo tenant “Zava” and every figure in the walkthrough are mocked prototype data — no real customer, tenant, or employee data.

Posture overview / tenant analysis
Identity posture overview for the Zava tenant: 1,818 identities, 92% requirements met, an agent recommendation card, and the Administrators segment.
AI-scored posture with one prioritized recommendation (“no standing privilege”).

01~/renan-rios$cat ./origin/how-it-started.md

How it started

Not a roadmap item — a hackathon. And a Product Manager looking for someone who could design and build at the same time.

The spark

A hackathon, and an unusual ask

It began as a hackathon. A Product Manager on the Entra Conditional Access team came looking for someone who could do two things at once — design the experience and build it in code — and bring a rough idea to life. In a weekend that became a working prototype, with identity posture living directly inside the Conditional Access agent.

The bet

The bet

The build drew real attention from leadership, who asked us to keep going and shape it into something solid enough to put in front of customers. That greenlight turned a weekend prototype into a staffed effort on a path to Private Preview — and, eventually, Public Preview.

02~/renan-rios$git shortlog -sn --all

How I worked

Lead designer and the connective tissue across three PMs, engineering, and the wider Entra design org.

As lead designer I was the connective tissue across three PMs, engineering, and the wider Entra design org. My high-fidelity prototypes weren't throwaway mockups — they were what engineering converted into the production codebase.

Three Product Managers

Each owned a slice: risky users and the posture dashboard; non-CA-policy phased rollouts and the customer-facing AI analysis; and agentic tenant analysis, the first-run experience, and break-glass. I designed across all three.

Engineering

Embedded throughout for technical input and feasibility — and they took my high-fidelity prototypes and shipped them as production code.

IDNA design org

Weekly syncs with other IDNA designers to keep the work consistent with the broader Entra design language.

Operating rhythm

  • Daily syncs with PMs on open items
  • Bi-weekly feasibility syncs with engineering
  • Weekly demos
  • Leadership reviews roughly every three weeks
  • Weekly design-consistency syncs with other IDNA designers

The sync that changed everything

In one leadership review the feedback landed hard: the design was perfectly consistent with the rest of Entra — and dull. Leadership wanted the experience to feel unmistakably AI-driven, not just another settings page. That single moment pushed me to level up my craft dramatically, and it kicked off the redesigns of the phased rollout and the posture page that leadership and customers ended up loving.

03~/renan-rios$git log --oneline hackathon..public-preview

The evolution

Every major redesign traces back to a signal — a customer blocker, a leadership push, or the product outgrowing its first shape.

  1. 01

    Posture born inside the agent

    Hackathon

    The first build lived entirely inside the Conditional Access agent — enough to prove the concept had legs.

    Why: Hackathon prototype

  2. 02

    A first-run experience to orient admins

    Early build

    Added a first-run experience so admins understood what the agent does and how to begin, before dropping them into posture.

    Why: Customers couldn't tell how to start — discoverability was an early blocker

  3. 03

    Posture steps out of the agent

    Early build

    Pulled identity posture out of the agent and onto the overview — room to become a first-class surface, while still scoped to the agent.

    Why: The idea outgrew a panel buried inside the agent

  4. 04

    AI review on the phased rollout

    Private Preview

    Introduced an AI review step on the phased rollout. The team liked the direction — but this first pass was still basic.

    Why: Trust has to be earned before anything is automated

  5. 05

    The phased rollout, fully redesigned

    Private Preview

    Rebuilt the rollout with a new, AI-forward interface: human-initiated waves, an impact preview, and visible safeguards.

    Why: Auto-enforcement is a non-starter in change-controlled orgs — and it had to feel AI-driven

  6. 06

    The posture page, fully redesigned

    Private Preview

    Rebuilt the posture page around real jobs-to-be-done and aligned it with the new rollout interface, so the whole experience felt intentional and cohesive.

    Why: The original page was basic, had no JTBD input, and no longer matched the scale of the product

  7. 07

    Break-glass, made real-world

    Private Preview

    Reworked break-glass handling to match how tenants actually operate — not every org uses Global Admin — and removed the silent dead-ends.

    Why: Rigid Global-Admin assumptions broke real customer configurations

04~/renan-rios$cat ./research/customer-signals.md

What customers told us

Private Preview put the work in front of real enterprises. Their feedback didn't just validate the direction — it drove the redesigns.

Through Private Preview the direction validated across roughly two dozen engagements — enterprises in finance, energy, tech, government, and education, plus partners, MVPs, and analysts. Three themes shaped nearly every decision.

20+

customer & partner engagements

6

industries represented

3

private-preview phases cleared

Customization is non-negotiable

One tenant's good state is never another's. Customers needed cohorts, definitions, and enforcement they could shape to their own environment.

Trust is earned incrementally

Admins move along a ladder — insights, then manual action, then approved automation, then autonomy. In practice, few click accept directly in the agent, but they act on its insights.

Posture is cross-functional

Identity posture can't live in an Entra-only silo; it has to connect to the signals and teams around it.

The trust ladder — earn it before you automate

Insights
Manual action
Approved automation
Agent autonomy

Customer feedback synthesized and anonymized — no customer names, individuals, or verbatim quotes.

05~/renan-rios$cat ./tenant/context.md

The demo tenant

A fictional tenant I used to design and demo the experience — a real-world shape: high-stakes, compliance-bound, hybrid identity. Everything shown from here on is mocked demo data.

tenant.md

A fictional Defense Industrial Base / government contractor — CMMC Level 2 and Zero Trust in scope, handling CUI + ITAR workloads on hybrid identity (Entra ID + on-prem AD), Microsoft 365 E5 · Entra ID P2.

The experience — An AI “Conditional Access Optimization Agent” analyzes the tenant, scores identity posture, and turns the single highest-impact gap into a safe, phased, human-approved rollout — a “Good State” campaign.

Tenant facts

Identities
1,818
Segments
6 cohorts
Admins
48
Compliance
CMMC L2 · ZTA
Licensing
M365 E5 · Entra ID P2
Identity
Hybrid (Entra + AD)

06~/renan-rios$node rollout.ts --recommendation=remove-standing-access

The prioritized move, executed safely

The single ranked recommendation becomes a phased, reversible, human-approved rollout — 13 admins across 3 waves, break-glass preserved.

13

admins in scope

3

phased waves

2

break-glass excluded

  1. 1

    Pilot

    3 admins

    PIM-familiar admins with lowest predicted disruption

  2. 2

    Early adoption

    6 admins

    Broader admin cohort with strong sign-in cadence

  3. 3

    Full enforcement

    4 admins

    Remaining permanent-role assignments with closer monitoring

Safeguards

  • Excludes break-glass and emergency access accounts
  • Each phase starts only when an admin clicks Start
  • Monitors notification delivery, sign-in issues, PIM activation, and support tickets
  • Admin can pause the rollout and restore access while investigating
Remove standing admin access — phased rollout
Phased PIM rollout: 13 identities in scope, 3 phases, 2 excluded, with Phase 1 pilot and an AI summary.
Standing access removed in safe, approval-gated waves (13 in scope, 3 phases).
Impact preview drawer (Phase 1)
Impact preview drawer: 3 admins affected, a sample Teams notification, and safeguards including break-glass exclusion and one-click pause-and-restore.
Human-in-the-loop: who's affected, the user's Teams message, and built-in safeguards.

07~/renan-rios$cat ./design/decisions.md

Design decisions

The judgment calls behind the experience — what to prioritize, when to automate, and how to earn trust with privileged change.

Identity risk hides across Secure Score, Conditional Access, PIM, and sign-in logs. The overview replaces that noise with a single AI-scored posture read and one ranked recommendation, so an admin knows the highest-leverage action at a glance.

  • Weighted critical-exposure-by-segment — 64% mapped to Administrators (2.6% of identities)
  • One primary recommendation instead of a backlog of 143 tasks
  • A “biggest wins” list ranks the five moves that add the most Secure Score points

Prioritization is the product — surfacing the one move that matters beats a longer list.

Changes to privileged accounts are risky, so the rollout is staged in waves that expand only when activation, sign-in, and support signals stay healthy — and it protects emergency access by design.

  • Phased waves (3 → 6 → 4 admins) that each start only when an admin clicks Start
  • Break-glass accounts auto-detected from CA-policy exclusions and preserved (2 out of scope)
  • One-click pause-and-restore if unexpected access issues appear

Trust comes from visible guardrails — staging, exclusions, and reversibility — not just automation.

The agent fixes low-risk drift automatically but routes anything consequential to an approval step, keeping humans in control of privileged change.

  • Low-risk drift is auto-remediated; high-impact actions require admin approval
  • An impact preview spells out who's affected and the exact Teams message users receive
  • Evidence loop: campaign telemetry reports back to Identity Secure Score (+8.4 pts)

Automation earns trust by knowing what not to do on its own.

The single biggest risk — permanent admin rights — is converted to just-in-time PIM access without disrupting admins, using earlier phases to de-risk the final cohort.

  • 13 admins scoped across 3 waves; permanent roles become eligible, just-in-time access
  • 100% PIM activation among sign-ins, zero support escalations in the pilot
  • Framework-aligned: CMMC L2 AC.L2-3.1.5 and NIST 800-171 3.1.5 (least privilege)

The highest-impact security win can ship with near-zero user friction when it's sequenced well.

What I owned — craft and UX patterns

Outcome-framed information architecture — controls read as end-states (“No standing privilege,” “Phishing-resistant MFA only,” “No open risk”), kept consistent from hero to drawer.

“Assess at a glance” hero — a single posture read, weighted critical-exposure-by-segment, and one ranked recommendation instead of an alert list.

Human-in-the-loop trust model — chain-of-thought agent reasoning, an impact preview, admin-initiated phases, and reversible/pausable rollouts.

Break-glass safety patterns — auto-detection, exclusion, and guidance for group-based emergency access so campaigns never lock out emergency admins.

Secure Score ↔ Good State evidence loop — connecting a recommendation to execution and back to a measurable score, with a ranked “biggest wins” surface.

Cohort model surface — every identity classified across tenant signals, with confidence-gap handling that refines without blocking evaluation.

Regulation co-branding contract — only show an Entra Recommendation chip where a real 1:1 mapping exists; extensions and deep-links don't fake it.

Design decisions embodied in the shipped prototype and the production experience.

09~/renan-rios$cat ./retro/reflection.md

Reflection

What this project says about how I work — and where it goes next.

The takeaway

A design-and-code force multiplier who turns AI ambiguity into trustworthy, shipped product.

  • Prioritization is the product — the highest-value move was collapsing scattered signals into one recommendation an admin could trust.
  • Trust is a design material — guardrails, impact previews, and human-initiated action earn the right to automate.
  • Designing in code closed the gap between intent and production; engineering shipped what I prototyped.
  • The "make it feel AI-driven" challenge pushed my craft further than any written brief could.

What's next

Public Preview is next — with scope reaching toward non-human and agentic identities, deeper compliance mapping, and posture that spans platforms.

// end of case study

Want the rest of the story?

See more Microsoft Entra work and the full delivery record, or head back home.