← Other Athentra features
Module: Control · Execution
Delegated Execution
Where Microsoft only exposes an action to a delegated identity, an administrator can authorise a control to run as them. The grant is held per person rather than shared tenant-wide, so the action is attributable to an individual. Automation reaches those actions without anyone creating a standing privileged account.
- 01
Pain Point
What's the problem?
Some Microsoft actions are only exposed to a signed-in person, and no application credential can perform them.
- 02
Remedy
How do we attack it?
Authorise a control to run as you, using a grant held per person rather than tenant-wide
- 03
Your Value
What do you get out of it?
Reaches the actions application permissions cannot, without a shared privileged account
