"description":"Placeholder-only example. Every identifier below is fictional. Real group Object IDs, attribute names, and domains belong in a protected configuration store, never in this repository."
"description":"Emergency access accounts identified by immutable Object ID (RE-009). Evaluated first so no later rule can reclassify them.",
"enabled":true,
"priority":10,
"persona":"BreakGlass-Admin",
"owner":"<TEAM-NAME>",
"match":{
"operator":"any",
"conditions":[
{
"type":"property",
"property":"AccountObjectId",
"operator":"in",
"values":[
"00000000-0000-0000-0000-000000000001",
"00000000-0000-0000-0000-000000000002"
]
}
]
}
},
{
"id":"RULE-0020-GUEST",
"name":"Guest accounts",
"description":"Any account whose directory user type is Guest.",
"enabled":true,
"priority":20,
"persona":"Guest",
"match":{
"operator":"all",
"conditions":[
{
"type":"property",
"property":"UserType",
"operator":"equals",
"value":"Guest"
}
]
}
},
{
"id":"RULE-0030-TIER0",
"name":"Tier 0 administrators",
"description":"Members of the Tier 0 administrative group, or holders of a Tier 0 directory role.",
"enabled":true,
"priority":30,
"persona":"Tier0-Admin",
"match":{
"operator":"any",
"conditions":[
{
"type":"membership",
"operator":"memberOf",
"membershipMode":"transitive",
"groupObjectIds":[
"00000000-0000-0000-0000-0000000000a0"
]
},
{
"type":"role",
"operator":"memberOf",
"roleIds":[
"<TIER0-ROLE-TEMPLATE-ID>"
]
}
]
}
},
{
"id":"RULE-0040-SERVICE",
"name":"Service accounts",
"description":"Non-human accounts identified by naming convention and the service account group. Both must hold, so a naming-convention collision alone cannot classify a person as a service account.",
"enabled":true,
"priority":40,
"persona":"Service-Account",
"match":{
"operator":"all",
"conditions":[
{
"type":"property",
"property":"UserPrincipalName",
"operator":"startsWith",
"value":"svc-"
},
{
"type":"membership",
"operator":"memberOf",
"groupObjectIds":[
"00000000-0000-0000-0000-0000000000b0"
]
}
]
}
},
{
"id":"RULE-0050-TEST",
"name":"Test accounts",
"description":"Accounts in the test account group, or matching the test naming convention while disabled.",
"enabled":true,
"priority":50,
"persona":"Test-Account",
"match":{
"operator":"any",
"conditions":[
{
"type":"membership",
"operator":"memberOf",
"groupObjectIds":[
"00000000-0000-0000-0000-0000000000c0"
]
},
{
"operator":"all",
"conditions":[
{
"type":"property",
"property":"UserPrincipalName",
"operator":"startsWith",
"value":"test-"
},
{
"type":"property",
"property":"AccountEnabled",
"operator":"equals",
"value":"False"
}
]
}
]
}
},
{
"id":"RULE-0060-CONTRACTOR",
"name":"Contractors",
"description":"Accounts whose company name marks them as external, excluding those already classified by an earlier rule.",
"enabled":true,
"priority":60,
"persona":"Contractor",
"match":{
"operator":"all",
"conditions":[
{
"type":"property",
"property":"CompanyName",
"operator":"isNotNull"
},
{
"type":"property",
"property":"CompanyName",
"operator":"notEquals",
"value":"<ORGANIZATION-NAME>"
}
]
}
},
{
"id":"RULE-0900-EMPLOYEE",
"name":"Employees",
"description":"Default classification for enabled member accounts with a department. Lowest priority so every more specific rule wins first.",