Memory hook: Strong login, narrow admin, visible changes.
Must remember
- Enforce strong authentication and recovery policies; prefer phishing-resistant methods such as security keys/passkeys where supported. Plan enrollment and emergency administrator recovery before enforcement.
- Context-aware access evaluates signals such as device posture and access context. A correct password can still be insufficient when a policy condition is unmet.
- Assign prebuilt or custom admin roles to specific duties. Reserve Super Admin for necessary work and keep emergency access monitored and protected.
- Use audit/investigation tools, security center views, health recommendations and activity rules to identify suspicious logins, sharing and administrative changes. Correlate timestamps and users before acting.
- SSO integration, Marketplace allowlisting and OAuth app access are separate controls. Review requested scopes, restrict high-risk applications and revoke obsolete connected-app access.
- Session controls and forced sign-out can reduce continuing access, but incident response may also require token revocation, password changes and device actions.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A help desk only resets passwords | A delegated user-management role scoped to its responsibility. |
| A third-party app requests broad Drive access | Review OAuth scopes and application controls before approval. |
Traps
- Two-step verification is not identical to phishing resistance.
- Disabling an app in one catalogue may not revoke every existing token.
Active recall
1. Why maintain emergency admin access?
To recover when normal identity or access policies fail.
2. What can context-aware access inspect?
Supported contextual signals such as device and network conditions.
3. Which evidence helps investigate an unexpected policy change?
Administrative audit events with actor, time and changed setting.
4. Why avoid routine Super Admin use?
It greatly increases the impact of mistakes or compromised credentials.
5. What follows a stolen refresh token?
Revoke affected sessions/tokens and investigate the identity and device, not only the password.