Microsoft Entra ID
Microsoft Entra ID is Microsoft's cloud identity and access management service. It stores identities for people, devices, and applications, authenticates them, issues tokens to connected applications, and applies access policies inside an organization's tenant.
itWindows and Microsoft infrastructure | OpenSkills.info
Intro
Microsoft Entra ID
Microsoft Entra ID is a cloud identity and access management service. It maintains a directory of identities and application relationships, authenticates users and workloads, issues signed tokens, and evaluates access policy. Microsoft 365, Azure, Dynamics 365, custom applications, and many third-party services can rely on it as an identity provider.
Entra ID was formerly named Azure Active Directory. The rename did not turn it into Windows Server Active Directory Domain Services. The two systems can exchange selected identity data in a hybrid design, but they use different architectures and serve different operating models.
The tenant is the control boundary
A tenant is a dedicated Entra ID directory instance. It contains users, groups, devices, application objects, service principals, roles, domains, and policies for an organization. Every tenant starts with an onmicrosoft.com domain, and administrators can add verified custom domains.
The tenant forms an identity and policy boundary. An identity can exist in more than one tenant, but each copy is a separate directory object with its own object identifier, assignments, and lifecycle. Collaboration across tenants therefore depends on explicit guest, federation, or cross-tenant relationships.
An Azure subscription trusts one tenant for identities, but the subscription is not the tenant. Azure resources and Azure role assignments live in the Azure resource hierarchy. Entra directory roles govern directory resources. Keeping these boundaries separate prevents a common error: assuming that an Azure subscription Owner is automatically an Entra Global Administrator, or the reverse.
Directory objects represent actors and applications
Human identities represent employees, administrators, guests, partners, and other people. Groups collect identities so access can follow maintained membership instead of repeated assignments to individuals.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://learn.microsoft.com/en-us/entra/fundamentals/what-is-entra
Supports
- Entra ID as the foundational cloud identity and access management service in the Entra family
- Tenant domains, Entra product boundaries, administration through the portal and Microsoft Graph
- Workload identities, managed identities, governance, protection, and external identity placement
- https://learn.microsoft.com/en-us/entra/fundamentals/identity-fundamental-concepts
Supports
- Authentication, authorization, identity, identity provider, federation, provisioning, MFA, and SSO definitions
- Human, workload, device, and agent identity categories
- https://learn.microsoft.com/en-us/entra/identity/
Supports
- Official feature map for users, roles, authentication, applications, Conditional Access, devices, hybrid identity, provisioning, and monitoring
- https://learn.microsoft.com/en-us/entra/architecture/architecture
Supports
- Partition, primary replica, secondary replica, routing, replication, failover, and consistency architecture
- Eventual consistency and delegated versus application-only session consistency behavior
- https://learn.microsoft.com/en-us/entra/identity/authentication/overview-authentication
Supports
- Supported authentication methods and their use for primary, secondary, and recovery scenarios
- Phishing-resistant method guidance
- https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview
Supports
- Conditional Access as an if-then policy engine using identity-driven signals
- Assignments, conditions, grant controls, and Zero Trust placement
- https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/what-is-application-management
Supports
- Application registration, enterprise application, consent, assignment, SSO, provisioning, token, certificate, governance, and cleanup lifecycle
- https://learn.microsoft.com/en-us/entra/identity-platform/security-tokens
Supports
- ID, access, and refresh token purposes and consumers
- Access-token validation, claims, discovery metadata, and supported authentication libraries
- https://learn.microsoft.com/en-us/entra/identity-platform/id-tokens
Supports
- ID tokens as authentication proof for clients rather than API authorization
- https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/
Supports
- Entra roles, groups, administrative units, scoped assignments, least-privileged task mapping, and custom roles
- https://learn.microsoft.com/en-us/entra/identity/hybrid/whatis-hybrid-identity
Supports
- Hybrid identity as a common identity spanning on-premises and cloud resources
- Synchronization and authentication placement
- https://learn.microsoft.com/en-us/entra/fundamentals/compare
Supports
- Architectural and protocol differences between Entra ID and Active Directory Domain Services
- https://learn.microsoft.com/en-us/entra/identity/monitoring-health/overview-monitoring-health
Supports
- Sign-in, audit, and provisioning log purposes
- Export to Azure Monitor, event hubs, storage, and SIEM systems
- https://learn.microsoft.com/en-us/entra/identity/monitoring-health/concept-sign-in-log-activity-details
Supports
- Who, how, and target components in sign-in investigation
- Error, authentication, device, location, Conditional Access, correlation, and request details
- https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities
Supports
- Audit logs as evidence of tenant changes and provisioning configuration changes
- https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention
Supports
- License-dependent log retention and export for longer retention
- https://github.com/sindresorhus/awesome
Supports
- Starting index used to discover a relevant identity and access management awesome list
- https://github.com/kdeldycke/awesome-iam
Supports
- IAM ecosystem discovery for Keycloak, authentik, ZITADEL, and Ory Hydra
- https://www.keycloak.org/documentation
Supports
- Keycloak administration, APIs, and self-hosted identity provider documentation
- https://docs.goauthentik.io/providers/
Supports
- OIDC, OAuth 2.0, LDAP, SAML, and proxy provider roles in authentik
- https://zitadel.com/docs
Supports
- ZITADEL authentication, federation, multitenancy, API, service account, and audit capabilities
- https://www.ory.com/hydra
Supports
- Ory Hydra as an OAuth 2.0 and OpenID Connect server that delegates user authentication
- https://www.microsoft.com/security/business/identity-access/microsoft-entra-id
Supports
- Microsoft Entra ID product homepage and cloud workforce identity market placement
- https://www.okta.com/products/workforce-identity/
Supports
- Okta workforce SSO, adaptive MFA, lifecycle management, governance, and API access management
- https://www.pingidentity.com/en/solution/workforce-identity.html
Supports
- Ping workforce authentication, adaptive MFA, directory, and application access placement
- https://duo.com/docs/sso
Supports
- Duo cloud SAML and OIDC identity provider, MFA, access policy, and directory integration
- https://cloud.google.com/identity/
Supports
- Google Cloud Identity SSO, MFA, user, and device management placement
- https://jumpcloud.com/platform
Supports
- JumpCloud directory, identity, device, access, SSO, and MFA placement
- https://www.onelogin.com/solutions/workforce-iam
Supports
- OneLogin cloud directory, SSO, MFA, contextual access, and lifecycle management placement
- https://azure.microsoft.com/en-us/blog/azuread-b2c-ga-announcement/
Supports
- July 2016 Azure AD B2C general availability milestone
- https://www.microsoft.com/en-us/security/blog/2016/07/21/new-microsoft-azure-security-capabilities-now-available/
Supports
- 2016 Azure AD Identity Protection and Privileged Identity Management availability milestones
- https://azure.microsoft.com/en-us/blog/azure-ad-managed-service-identity-updates/
Supports
- 2018 system-assigned and user-assigned managed identity model and service integrations
- https://www.microsoft.com/en-us/microsoft-365/blog/2018/04/17/password-less-sign-in-to-windows-10-azure-ad-using-fido2-is-coming-soon-plus-other-cool-news/
Supports
- April 2018 access reviews and Privileged Identity Management general availability
- Early passwordless FIDO2 preview direction
- https://www.microsoft.com/en-us/microsoft-365/blog/2019/07/10/new-azure-active-directory-capabilities-eliminate-passwords/
Supports
- July 2019 public preview of FIDO2 security key passwordless sign-in for Azure AD
- https://www.microsoft.com/en-us/security/blog/2023/11/06/automatic-conditional-access-policies-in-microsoft-entra-streamline-identity-protection/
Supports
- 2019 creation of security defaults for new tenants
- 2022 extension of security defaults to existing tenants
- https://techcommunity.microsoft.com/blog/microsoft-entra-blog/continuous-access-evaluation-in-azure-ad-is-now-in-public-preview/1751704
Supports
- October 2020 Continuous Access Evaluation public preview
- https://techcommunity.microsoft.com/blog/microsoft-entra-blog/more-coverage-to-protect-your-identities/2365685
Supports
- 2021 Conditional Access for workload identities public preview and near-real-time access evaluation direction
- https://www.microsoft.com/en-us/security/blog/2022/05/31/secure-access-for-a-connected-worldmeet-microsoft-entra/
Supports
- May 2022 introduction of the Microsoft Entra product family
- https://www.microsoft.com/en-us/security/blog/2023/07/11/microsoft-entra-expands-into-security-service-edge-and-azure-ad-becomes-microsoft-entra-id/
Supports
- July 2023 Azure Active Directory rename to Microsoft Entra ID
- Rename continuity for capabilities, licensing, APIs, configurations, and integrations
