
A Security Group Is Not a Wall Until You Say So: Department Isolation in Microsoft 365

Conversational department isolation in Microsoft 365, run and verified with Sia.
You build the group. You name it right. HR Team. Dev Team. Clean, obvious, done.
You assign the app to the group, close the ticket, and move to the next one.
Nobody told you the app is still open to every other identity in the tenant.
IT admins are careful people. But the one step that never throws an error when you skip it is exactly the one that gets skipped under load. In Microsoft Entra, that step is "assignment required." Until it reads true on the app, "assigned to the group" is a label, not a boundary.
The request that never really ends
Every department that spins up sends the same ticket in different words. New team, needs its own apps, lock it down. Underneath that one line is a handful of separate jobs, and each one has its own way of quietly not getting finished.
Spinning up the group. Created, named, tidy. The app it is supposed to guard is still reachable by the whole tenant until one more setting gets flipped.
Mapping the right app to the right group. Usually done from memory, which means it is one busy afternoon away from HR's app landing under Dev's group.
Scoping the licenses that come with it. Skip this and seats spread quietly past whoever actually needs them.
Turning on enforcement. The step with no error message when it is missing. Miss it, and "assigned to the group" means nothing.
Keeping membership current. People get added by hand, nobody removes them, and six months later the group means whatever it happened to accumulate.
None of this is hard. All of it is repetitive. And the step most likely to get dropped, turning on enforcement, is the one that decides whether the group is a boundary or just a name.
What we asked Sia to do
Here is that same request, handed to Sia as one plain-English instruction, typed into the Sia CLI against a tenant that started with no security groups at all:
"Create two separate security groups in Microsoft Entra named HR Team and Dev Team. Assign the Microsoft Forms application to the HR group and the Microsoft Planner application to the Dev group, and enable assignment required on both applications to enforce strict perimeter lockdown."
Sia broke that into six steps and ran all of them. It created an HR Team. It created a Dev Team. It found the Forms and Planner service principals. It bound Forms to HR Team and Planner to Dev Team. Then it turned on assignment required for both apps, the enforcement step, built into the task instead of skipped under load.
Then it checked its own work. A refresh of the Entra admin center showed both groups present. Dev Team had Planner attached. HR Team had Forms attached. Assignment required read true on both apps. Only members of each group can reach their app. Everyone outside it is blocked.
The same pattern holds for the requests that never made it into this demo. "Add Priya to the Dev Team." Done. "Lock the Planner app to just the offsite team until Friday." Done. No verification screenshot needed for those, just the same short loop every time. Instruction in, state changed, checked.
Watch it happen
The full sequence, run and verified live in Entra ID.
Before Sia, with Sia
Before Sia: build the group, track down the right app, remember to flip assignment required, hope step four did not get skipped this time.
With Sia: one sentence. Group created, app bound, enforcement on, checked.
Before Sia: find out which apps are actually locked down by pulling a report, cross-checking it by hand, and hoping it is still accurate by the time you finish.
With Sia: ask, and get the real answer back in seconds.
Before Sia: onboard a new team's access across groups, apps, and licenses over a few days.
With Sia: the same afternoon.
Before Sia: find out an app quietly reverted to open access at next year's audit.
With Sia: ask right now, instead of waiting for the audit to find it.
What Sia actually touches
Sia works directly against Microsoft Entra ID: security groups, enterprise application assignments, the service principals behind them, and the licenses tied to each group. Forms and Planner are what this walkthrough used. The same binding pattern holds for any app registered in the tenant.
The interaction is conversational. The execution is not a guess. Every change runs through the same governance that lets Sia act on production networks: a mutation gate with three verdicts, allow, require approval, or block, sensitive changes queued for a human, destructive operations blocked outright, and every action written to an append-only, HMAC-signed audit log that exports with its signatures intact. When compliance asks which apps are enforced and who is in each group, the answer is a query against a signed record, not an afternoon of stitching portal logs together.
This is not only an IT admin's job anymore
None of this needs an IT admin at the keyboard for every request. A department manager can ask Sia to lock down their own team's app, or add someone to their own group, scoped to exactly their team and not the whole tenant. Ask Sia to touch another department's group from inside Dev, and it will not. Access control did not disappear. Sia runs inside the role-based scope you set, so the permission model moves from "a human clicking with admin rights" to "an agent acting within a policy you defined."
It is the same Sia whether the request comes in through the command line, the web, or the desktop app. The surface is just the door.
What this actually changes
New departments get isolated the day they are created, not the quarter after. Apps stay locked down without a human remembering to double-check. Anyone authorized can ask what is enforced right now, instead of waiting for the next audit to find out. And the tickets that should take one sentence stop sitting in the queue.
The org chart was always tidy. Now the tenant finally agrees with it, at the speed you actually work.
Availability
Department isolation runs on the Microsoft 365 integration that is in Sia now, across the Sia CLI, the Sia Desktop App, and the web. We deliver Sia as part of the Scogo platform to enterprise customers, so there is no public download.
If you run Microsoft 365 across a real org and your team is spending its days flipping settings in Entra, we want to put Sia in front of your tenant. Start with a pilot at scogo.ai/request-demo.
Autonomous where it is safe, governed where it matters, on the record everywhere.

Written by
Karan Singh
Co-founder & CTO
Published on


