Skip to main content

paw-design

Guidance for designing Privileged Access Workstations (PAW) and the Microsoft privileged access strategy (enterprise access model, clean source principle, tiered admin isolation). Covers when to use Enterprise vs Specialized vs Privileged device profiles, hardening (Entra-join, Intune, app allowlisting, Credential Guard), Conditional Access enforcement, and rollout. WHEN: privileged access workstation, PAW, secure admin workstation, enterprise access model, privileged access strategy, admin isolation, secured workstation, clean source principle, tier 0 protection, control plane, dedicated admin device, hardened workstation, Credential Guard, FIDO2 admin. DO NOT USE for general endpoint hardening (use defender-for-endpoint) or device compliance policy (use intune-device-mgmt).

Jump to install

Source facts

Repository
vinayaklatthe/microsoft-security-skills
Last source activity
June 11, 2026 at 12:19
Detected SKILL.md language
English
Stars
170
Forks
35

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.