Admin Work and Everyday Work on One Machine? Game Over.

Why one tenant is not enough for CIOs, and why the second one is rarely part of the plan. The Managed Red Tenant separates administrative work from the office environment architecturally, the Managed Dark Tenant keeps the business able to act when the defenses fall anyway. What that means for the operating model, the SOC signal and the evidence obligations under NISG 2026.

Admin Work and Everyday Work on One Machine? Game Over.

One machine, two tabs, one click

The scenario is unspectacular, and that is exactly what makes it dangerous: an administrator is sitting at their usual office laptop. In the left browser tab the Microsoft 365 admin center is open, Global Admin and Intune Admin rights included. In the right tab they download a "free tool", Invoice_2026.pdf.exe. One click, a PowerShell payload, persistence established, privilege escalation under way. The path to Tier 0, to the heart of the company's IT, is open.

Game Over.

MITRE ATT&CK currently documents 222 techniques for enterprise environments, plus 475 sub-techniques, together close to 700 known ways to escalate privileges, move laterally and reach a company's most sensitive assets. Attackers need exactly one of them. And in most of the incident response engagements we work on, the same pattern shows up: administration happened on the same device that was used to read email, browse the web and chat in Teams.

Anyone who takes "assume breach" seriously, and under NIS2 there is little alternative, has to accept one uncomfortable consequence: some things simply do not belong on the same machine. Half a separation is no separation.

Why the obvious answers fall short

We all know the standard reflexes. Jump servers? A reverse proxy tunnel from the compromised client, and the attacker rides straight through the jump box: same machine, same browser, same risk. Building classic privileged access management (PAM) inside your own tenant? Then the question comes up immediately: who manages the management environment? If the protected admin workstations live in the same tenant they are meant to protect, you have built a circle, not a wall. And the virtual desktop launched from the office laptop? It inherits that laptop's keylogger. The screen is virtual, the keystrokes are real. Zero Trust ends precisely where admin work and everyday work share a device.

The Managed Red Tenant: separation as architecture

This is where the Managed Red Tenant (MRT) comes in: a dedicated, fully code-managed and heavily hardened tenant environment used exclusively for administrative work. For Tier 0 tasks, Privileged Access Workstations (PAW) are available as a managed service, hardened hardware PAWs as separate physical devices. For Tier 1 work there are VAWs, virtual access workstations based on Azure Virtual Desktop, reachable only from compliant devices, only with FIDO2, only under Conditional Access. Added to that are iPads configured to a maximally restrictive security baseline, for the situations where convenience matters.

Schematic comparison of two tenants: on the left the Managed Red Tenant as a shielded room holding the admin workstations PAW, VAW and iPAW, on the right the production tenant with internet, mail, Teams and SharePoint drawn as a floor plan with open passages, separated by a continuous red wall

The decisive point for CIOs, though, is not the technology but the operating model. Every change to the Red Tenant runs as configuration as code through a CI/CD pipeline and is only deployed after explicit approval by the customer. This shared responsibility principle answers the question every buyer of managed services should ask: what happens if the service provider itself is compromised? The answer: nothing. Without customer approval, not a single line of configuration changes in the Red Tenant. The management layer sits outside the customer's risk zone, and the right of veto stays with the customer.

The operational gain is twofold. First, it creates a clarity that is rarely available: every legitimate administrative access to the production environment comes, by definition, from an MRT machine. Everything else is an attack. That gives the SOC a signal without noise, one it can act on immediately instead of sorting through false positives. Second, if an attack on the office environment succeeds, there is a wall in the way rather than a speed bump: jumping from a compromised office laptop onto a hardware PAW that sits next to it on the desk as a device of its own is extremely difficult to impossible for an attacker.

And if it happens anyway? The extra life.

Every experienced CIO knows there is no such thing as one hundred percent security. Assume breach also means planning for your own defenses to fail. The Stryker incident in March 2026 showed how narrow the margin is: one compromised Intune admin account was enough to wipe devices in 79 countries. Ransomware groups today deliberately target backups, Active Directory, exactly the systems you would need for a rebuild. Whoever then starts improvising, with encrypted file servers, without working identities, with a phone tree instead of a communication infrastructure, loses days and weeks in which the business stands still.

If the Red Tenant keeps it from ever saying "Game Over", then the Managed Dark Tenant is the extra life: a prepared recovery environment that lies dormant in normal operation and is activated when the worst happens. One call to the 24/7 emergency number starts the disaster recovery process. A virtual war room immediately establishes secure communication with all key stakeholders, independently of the possibly compromised production environment. Because the Dark Tenant is built as infrastructure as code, all critical recovery processes are predefined and automated: system-critical components such as Active Directory and identities are restored cleanly instead of being assembled ad hoc under pressure. The result is a recovery time objective (RTO) of a few hours to a few days and a defined recovery point objective (RPO), instead of the weeks that improvised recoveries regularly cost in practice.

Resilience, doubled

Red Tenant and Dark Tenant answer two different questions that only together produce a complete picture. The Red Tenant answers: how do I prevent a compromised client from ever becoming a compromised domain? The Dark Tenant answers: how do I stay able to act when it happens anyway? One is the wall, the other is the safety net.

For Austrian companies there is a regulatory dimension on top of that, and it is about to become very concrete. With NISG 2026, which takes effect on 1 October 2026, around 4,000 Austrian companies fall under cybersecurity obligations they have to be able to evidence, explicitly including risk management, business continuity, emergency planning and crisis management. Anyone who can explain to their supervisory board that administrative access is isolated architecturally and that a tested, automated recovery environment stands ready for an emergency is having a different conversation than someone pointing to awareness training and hope.

Table of the NIS2 risk measures under Article 21.2 with the rows Incident Handling, Business Continuity, Supply Chain Security, Security in Network and Information Systems, Effectiveness of Cybersecurity Risk Management Measures, Human Resources Security and Access Control, and Multifactor Authentication, with check marks in the Managed Red Tenant and Managed Dark Tenant columns

We run both services as a managed service, with a team that, as a BSI-qualified APT response provider, regularly stands on the other side when things are already burning, and feeds that experience straight back into the architecture. Our customers include DAX corporations as well as operators of critical infrastructure.

Some things do not belong on the same machine. And some companies cannot afford a Game Over. Better, then, with a wall and an extra life.

Get in touch

Want to know how Managed Red Tenant and Managed Dark Tenant work together in your environment? Write to us and we will walk through your case in detail.
Portrait of Jan Geisbauer, Head of Security at glueckkanja
Half a separation is no separation. When administrative work runs on the same device as email and the browser, a single click decides who gets access to Tier 0. That is the gap we close architecturally, not through awareness training.
Jan GeisbauerHead of Security

Similar Posts