
Sign up to save your podcasts
Or


In this episode, we talk with an identity expert, ex-Microsoftie and Principal Domain Architect, Mark Renoden, about creating a modern Privileged Access Management (PAM) solution for on-premises Active Directory. Discover how to build a secure "Bastion Forest" architecture using Microsoft Entra. We talk about PIM for Groups, group write-back, phish-resistant credentials, Privileged Access Workstations (PAW), securing an Entra tenant from the ground up, and navigating challenges with Cloud Solution Provider (CSP) permissions.
Watch on YouTube
PS. Can I ask a favor? If you enjoyed this episode please leave a review and rating! Thank you ๐ - Merill
About Mark
As Principal Domain Architect for Identity at Increment, Mark leads the design and delivery of secure, scalable identity architectures grounded in Microsoft Entra ID and aligned with Zero Trust principles. He specializes in helping organisations modernise their infrastructure and navigate complex identity transformations.
Previous to Increment, Mark spent over 20 years at Microsoft in support, field engineering, mission critical and customer experience roles focused on Identity across a wide spectrum of industries in Australia and New Zealand, including Finance, Healthcare, Government, Education and Retail.
LinkedIn - https://www.linkedin.com/in/markrenoden/
๐ Related Links
* DirectoryShield | Increment - https://www.increment.inc/directoryshield
* Entra Security Recommendations - https://aka.ms/EntraSecurityRecommendations
* Securing privileged access overview - https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-overview
* MIM - Bastion environment - https://learn.microsoft.com/en-us/microsoft-identity-manager/pam/planning-bastion-environment
๐ Chapters
00:46 Securing Your Entra Tenant
02:09 The Quest for a Microsoft-Only PAM Solution
04:21 What is a "Bastion Forest"?
07:50 Reimagining the Bastion Forest for the Cloud
12:53 Architecting a "Secure-by-Default" Tenant
17:41 Phish-Resistant On-Prem Admins
19:50 The Modern Privileged Access Workstation (PAW)
27:04 The Tiered Administration Model Explained
29:51 The Hidden Dangers of CSP Admin Access
34:29 How Fast is PIM for Groups?
Podcast Apps
๐๏ธ Entra.Chat - https://entra.chat
๐ง Apple Podcast โ https://entra.chat/apple
๐บ YouTube โ https://entra.chat/youtube
๐บ Spotify โ https://entra.chat/spotify
๐ง Overcast โ https://entra.chat/overcast
๐ง Pocketcast โ https://entra.chat/pocketcast
๐ง Others โ https://entra.chat/rss
Merill's socials
๐บ YouTube โ youtube.com/@merillx
๐ LinkedIn โ linkedin.com/in/merill
๐ค Twitter โ twitter.com/merill
๐บ TikTok โ tiktok.com/@merillf
๐ฆ Bluesky โ bsky.app/profile/merill.net
๐ Mastodon โ infosec.exchange/@merill
๐งต Threads โ threads.net/@merillf
๐ค GitHub โ github.com/merill
By Merill Fernando5
55 ratings
In this episode, we talk with an identity expert, ex-Microsoftie and Principal Domain Architect, Mark Renoden, about creating a modern Privileged Access Management (PAM) solution for on-premises Active Directory. Discover how to build a secure "Bastion Forest" architecture using Microsoft Entra. We talk about PIM for Groups, group write-back, phish-resistant credentials, Privileged Access Workstations (PAW), securing an Entra tenant from the ground up, and navigating challenges with Cloud Solution Provider (CSP) permissions.
Watch on YouTube
PS. Can I ask a favor? If you enjoyed this episode please leave a review and rating! Thank you ๐ - Merill
About Mark
As Principal Domain Architect for Identity at Increment, Mark leads the design and delivery of secure, scalable identity architectures grounded in Microsoft Entra ID and aligned with Zero Trust principles. He specializes in helping organisations modernise their infrastructure and navigate complex identity transformations.
Previous to Increment, Mark spent over 20 years at Microsoft in support, field engineering, mission critical and customer experience roles focused on Identity across a wide spectrum of industries in Australia and New Zealand, including Finance, Healthcare, Government, Education and Retail.
LinkedIn - https://www.linkedin.com/in/markrenoden/
๐ Related Links
* DirectoryShield | Increment - https://www.increment.inc/directoryshield
* Entra Security Recommendations - https://aka.ms/EntraSecurityRecommendations
* Securing privileged access overview - https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-overview
* MIM - Bastion environment - https://learn.microsoft.com/en-us/microsoft-identity-manager/pam/planning-bastion-environment
๐ Chapters
00:46 Securing Your Entra Tenant
02:09 The Quest for a Microsoft-Only PAM Solution
04:21 What is a "Bastion Forest"?
07:50 Reimagining the Bastion Forest for the Cloud
12:53 Architecting a "Secure-by-Default" Tenant
17:41 Phish-Resistant On-Prem Admins
19:50 The Modern Privileged Access Workstation (PAW)
27:04 The Tiered Administration Model Explained
29:51 The Hidden Dangers of CSP Admin Access
34:29 How Fast is PIM for Groups?
Podcast Apps
๐๏ธ Entra.Chat - https://entra.chat
๐ง Apple Podcast โ https://entra.chat/apple
๐บ YouTube โ https://entra.chat/youtube
๐บ Spotify โ https://entra.chat/spotify
๐ง Overcast โ https://entra.chat/overcast
๐ง Pocketcast โ https://entra.chat/pocketcast
๐ง Others โ https://entra.chat/rss
Merill's socials
๐บ YouTube โ youtube.com/@merillx
๐ LinkedIn โ linkedin.com/in/merill
๐ค Twitter โ twitter.com/merill
๐บ TikTok โ tiktok.com/@merillf
๐ฆ Bluesky โ bsky.app/profile/merill.net
๐ Mastodon โ infosec.exchange/@merill
๐งต Threads โ threads.net/@merillf
๐ค GitHub โ github.com/merill

14,346 Listeners

1,954 Listeners

1,647 Listeners

371 Listeners

99 Listeners

651 Listeners

418 Listeners

66 Listeners

8,076 Listeners

315 Listeners

61 Listeners

3 Listeners

48 Listeners

45 Listeners

55 Listeners