Back to featured projects

A little more of the work

Modernizing Microsoft Graph Permissions Governance

Enterprise API governance needed consistent authorization decisions across permission risk, access types, applications, workloads, and cloud environments.

Liz's Library
Back to platform governance

Platform initiative

Inside the folder

Technical Product Manager

GovernancePermissionsSecurity

Description

Enterprise API governance needed consistent authorization decisions across permission risk, access types, applications, workloads, and cloud environments.

My contribution

  • Architected authorization and identity policy models for enterprise API governance
  • Coauthored a contextual authorization architecture across workload, permission risk, access type, application type, and cloud environment
  • Defined fail-closed treatment for unclassified permissions, new APIs, missing ownership, and unexpected states
  • Designed governance-bypass detection for application and permission changes with staged rollout and telemetry gates

Outcomes & evidence

  • 1,200+ permission records modernized
  • 12+ workload teams involved
  • Rollout checkpoints at 10%, 40%, 70%, and 100% with 24-hour telemetry gates
  • Automatic governance tickets when checks fail

Sources & project links

Folder openPlatform initiative