{ "configVersion": "1.0.0", "metadata": { "owner": "", "changeReference": "", "description": "Placeholder-only example. Every identifier below is fictional. Real group Object IDs, attribute names, and domains belong in a protected configuration store, never in this repository." }, "engine": { "targetAttribute": "extension__", "approvedWritableAttributes": [ "extension__" ], "maxConditionDepth": 5, "summaryInterval": 25, "defaultMembershipMode": "direct", "evaluationErrorThreshold": 50 }, "dataSources": { "groups": { "enabled": true }, "roles": { "enabled": true, "includeEligible": false } }, "logging": { "destination": "both", "path": "", "traceConditionValues": false }, "personas": [ "Guest", "BreakGlass-Admin", "Tier0-Admin", "Tier1-Admin", "Tier2-Admin", "Restricted-User", "Test-Account", "Service-Account", "Shared-Functional-Account", "Meeting-Room-Device", "Employee", "Contractor", "Student" ], "rules": [ { "id": "RULE-0010-BREAKGLASS", "name": "Emergency access accounts", "description": "Emergency access accounts identified by immutable Object ID (RE-009). Evaluated first so no later rule can reclassify them.", "enabled": true, "priority": 10, "persona": "BreakGlass-Admin", "owner": "", "match": { "operator": "any", "conditions": [ { "type": "property", "property": "AccountObjectId", "operator": "in", "values": [ "00000000-0000-0000-0000-000000000001", "00000000-0000-0000-0000-000000000002" ] } ] } }, { "id": "RULE-0020-GUEST", "name": "Guest accounts", "description": "Any account whose directory user type is Guest.", "enabled": true, "priority": 20, "persona": "Guest", "match": { "operator": "all", "conditions": [ { "type": "property", "property": "UserType", "operator": "equals", "value": "Guest" } ] } }, { "id": "RULE-0030-TIER0", "name": "Tier 0 administrators", "description": "Members of the Tier 0 administrative group, or holders of a Tier 0 directory role.", "enabled": true, "priority": 30, "persona": "Tier0-Admin", "match": { "operator": "any", "conditions": [ { "type": "membership", "operator": "memberOf", "membershipMode": "transitive", "groupObjectIds": [ "00000000-0000-0000-0000-0000000000a0" ] }, { "type": "role", "operator": "memberOf", "roleIds": [ "" ] } ] } }, { "id": "RULE-0040-SERVICE", "name": "Service accounts", "description": "Non-human accounts identified by naming convention and the service account group. Both must hold, so a naming-convention collision alone cannot classify a person as a service account.", "enabled": true, "priority": 40, "persona": "Service-Account", "match": { "operator": "all", "conditions": [ { "type": "property", "property": "UserPrincipalName", "operator": "startsWith", "value": "svc-" }, { "type": "membership", "operator": "memberOf", "groupObjectIds": [ "00000000-0000-0000-0000-0000000000b0" ] } ] } }, { "id": "RULE-0050-TEST", "name": "Test accounts", "description": "Accounts in the test account group, or matching the test naming convention while disabled.", "enabled": true, "priority": 50, "persona": "Test-Account", "match": { "operator": "any", "conditions": [ { "type": "membership", "operator": "memberOf", "groupObjectIds": [ "00000000-0000-0000-0000-0000000000c0" ] }, { "operator": "all", "conditions": [ { "type": "property", "property": "UserPrincipalName", "operator": "startsWith", "value": "test-" }, { "type": "property", "property": "AccountEnabled", "operator": "equals", "value": "False" } ] } ] } }, { "id": "RULE-0060-CONTRACTOR", "name": "Contractors", "description": "Accounts whose company name marks them as external, excluding those already classified by an earlier rule.", "enabled": true, "priority": 60, "persona": "Contractor", "match": { "operator": "all", "conditions": [ { "type": "property", "property": "CompanyName", "operator": "isNotNull" }, { "type": "property", "property": "CompanyName", "operator": "notEquals", "value": "" } ] } }, { "id": "RULE-0900-EMPLOYEE", "name": "Employees", "description": "Default classification for enabled member accounts with a department. Lowest priority so every more specific rule wins first.", "enabled": true, "priority": 900, "persona": "Employee", "match": { "operator": "all", "conditions": [ { "type": "property", "property": "UserType", "operator": "equals", "value": "Member" }, { "type": "property", "property": "Department", "operator": "isNotNull" } ] } } ] }