Key takeaways
What is Microsoft Entra ID?
Microsoft Entra ID is Microsoft's cloud-based identity and access management service. It authenticates users, devices, applications and workloads, then provides the identity information and authorisation controls used to access Microsoft 365, Azure, software-as-a-service applications and custom applications.
Every Microsoft 365 organisation already relies on a Microsoft Entra tenant. The tenant contains identities, groups, registered applications, devices, policies, administrative roles, logs and security configuration. The quality of this identity foundation has a direct effect on the security and usability of the wider cloud environment.
Identity is now the control plane for modern work. A compromised or poorly governed identity can bypass otherwise strong network and endpoint controls.
Authentication
Prove who or what is signing in using passwords, MFA, passkeys, certificates and other methods.
Authorisation
Determine which applications, data and administrative actions an identity may access.
Directory services
Store users, groups, devices, service principals, domains and organisational attributes.
Protection and governance
Detect risk, enforce access policy, review entitlements and control privileged roles.
Tenant architecture and governance
A Microsoft Entra tenant is a security boundary and administrative boundary. Start with clear ownership, verified domains, contact details, emergency access, administrative roles and change processes. Avoid creating additional tenants without a justified business, legal or isolation requirement because each tenant introduces separate identity lifecycle, security, application and support obligations.
Core governance decisions
- Who owns the tenant and approves identity architecture changes?
- Which domains and user principal name formats are standard?
- How are administrative roles assigned, activated and reviewed?
- How are applications approved, registered and consented?
- How are guests, contractors and partner organisations governed?
- Which logs are retained and forwarded to security operations?
Use least-privilege roles rather than assigning Global Administrator for convenience. Separate everyday user accounts from privileged administration accounts, and maintain two dedicated emergency access accounts.
User and group lifecycle
Identity lifecycle management begins before the account is created. Define authoritative data sources, naming standards, required attributes, manager relationships, licence rules, group membership and access approval. A good joiner, mover and leaver process ensures that access follows the person's role rather than accumulating indefinitely.
Joiner
Create the identity from an authoritative request or HR source, assign baseline groups and licences, register authentication and provide only the access needed for the role.
Mover
Reassess access when department, location, manager or duties change. Remove access that no longer applies before adding new privileges.
Leaver
Block sign-in promptly, revoke sessions, preserve required business data, remove licences and group membership, and delete the identity according to retention policy.
Periodic review
Confirm managers, guest sponsors and application owners still validate access, and remove stale or unexplained entitlements.
Groups and dynamic membership
Use groups to assign licences, applications and policy wherever practical. Dynamic groups can reduce manual administration when reliable attributes are available, but their rules should be documented and monitored. Avoid reusing one group for unrelated purposes because a future membership change may create unexpected access or policy impact.
Authentication strategy
Passwords remain common, but they should not be the only factor protecting important resources. Microsoft Entra supports a range of methods including Microsoft Authenticator, passkeys and FIDO2 security keys, Windows Hello for Business, certificate-based authentication, temporary access passes and OATH tokens.
Choose methods according to user needs, device availability, security risk and recovery requirements. Administrators and high-risk users should use phishing-resistant methods. Temporary Access Pass can support secure onboarding and recovery without relying on a weak initial password.
| Method | Typical use | Security consideration |
|---|---|---|
| Microsoft Authenticator | Broad workforce MFA and passwordless sign-in | Number matching and registration controls improve resistance to push fatigue. |
| Passkeys / FIDO2 keys | Phishing-resistant sign-in | Strong choice for administrators and high-value roles. |
| Windows Hello for Business | Passwordless Windows sign-in | Bound to the device and protected by PIN or biometrics. |
| Certificate-based authentication | Regulated, smart-card or specialist environments | Requires certificate lifecycle and trust management. |
| Temporary Access Pass | Onboarding and recovery | Time-limited and useful for bootstrapping strong methods. |
MFA and self-service password reset
Enforce multifactor authentication through Conditional Access rather than relying on per-user MFA settings. Conditional Access allows the requirement to reflect user role, application sensitivity, device state, location and risk. Protect authentication method registration so an attacker with a stolen password cannot easily register their own method.
Self-service password reset reduces support demand and gives users a controlled recovery path. In hybrid identity environments, password writeback can allow a cloud-initiated reset to update the on-premises directory when properly licensed and configured. Align SSPR methods with the authentication methods policy and define a helpdesk process for users who lose every registered method.
Hybrid identity
Hybrid identity connects on-premises Active Directory with Microsoft Entra ID. Common authentication approaches include password hash synchronisation, pass-through authentication and federation. Password hash synchronisation is often the simplest and most resilient option because cloud authentication can continue without a real-time dependency on on-premises agents.
Microsoft Entra Cloud Sync and Microsoft Entra Connect Sync can synchronise users and groups. The correct choice depends on topology, attribute requirements, writeback needs and existing architecture. Whichever tool is used, protect synchronisation servers or agents, document filtering and transformation rules, monitor health and avoid unsupported manual changes to synchronised attributes.
Hybrid identity flow
Enterprise applications and application registrations
Enterprise applications represent service principals used in the tenant. Application registrations define applications that your organisation develops or integrates. Both can hold permissions and become powerful access paths, so application governance is a core identity security responsibility.
Use single sign-on where possible and automate provisioning through standards such as SCIM. Assign applications to groups, establish an application owner and periodically review sign-in activity and permissions. User consent should be controlled so individuals cannot grant high-impact permissions to unverified applications without review.
Application governance checklist
Device identities
Devices can be Microsoft Entra registered, Microsoft Entra joined or Microsoft Entra hybrid joined. The appropriate state depends on ownership, operating model and whether on-premises domain dependence remains. Device identity provides a signal that Conditional Access can combine with Microsoft Intune compliance.
| State | Typical scenario | Management note |
|---|---|---|
| Entra registered | Personal or bring-your-own devices | Creates a workplace identity relationship without full organisational join. |
| Entra joined | Cloud-native organisation-owned Windows devices | Well suited to Intune and Windows Autopilot. |
| Entra hybrid joined | Devices dependent on on-premises Active Directory | Adds cloud identity while retaining domain join and legacy dependencies. |
Cloud-native join is usually simpler for new devices where applications and operations no longer require traditional domain join. Hybrid join can be a useful transition, but it should not become a permanent default without reviewing the dependencies that make it necessary.
Conditional Access and identity protection
Conditional Access uses identity, application, device, location, client and risk signals to enforce access requirements. Establish emergency access accounts, block legacy authentication, protect administrators, require MFA and add device or authentication strength controls according to application sensitivity.
Microsoft Entra ID Protection detects risky users and risky sign-ins. With Microsoft Entra ID P2, these signals can trigger automated Conditional Access decisions such as requiring secure password change, strong authentication or blocking access. Security teams should investigate risk events rather than treating automation as a complete substitute for response.
Privileged access management
Administrative access should be limited in number, separate from normal productivity accounts and protected with stronger authentication. Microsoft Entra Privileged Identity Management can make eligible role assignments activate only when needed, with approval, MFA, justification, time limits and notifications.
Review permanent assignments, eliminate unnecessary Global Administrators and use task-specific roles. Protect privileged accounts with phishing-resistant authentication and, where practical, require access from managed privileged workstations. Monitor role activation, role changes, application consent and emergency account activity.
Separate accounts
Use distinct identities for everyday work and privileged administration.
Just-in-time roles
Make users eligible and require activation instead of leaving roles permanently active.
Stronger authentication
Require phishing-resistant methods for sensitive directory roles.
Access reviews
Regularly confirm that eligible and active role assignments remain necessary.
Identity Governance
Microsoft Entra ID Governance capabilities help manage access packages, entitlement lifecycles, access reviews, lifecycle workflows and privileged access. Entitlement management can bundle groups, applications and SharePoint sites into access packages with request, approval, expiry and review policies.
Access reviews are valuable for guests, privileged roles and high-impact application groups. Reviews need accountable reviewers, useful context and a default action for non-response. A review that repeatedly approves all access without evidence creates administration without meaningful governance.
External identities and collaboration
Microsoft Entra External ID supports business collaboration with guests and external organisations. Define who may invite guests, which domains are allowed or restricted, how cross-tenant trust is configured and how guest access expires. Require a sponsor or owner for external users and review guests that have no recent sign-in or no continuing business purpose.
Cross-tenant access settings can govern inbound and outbound collaboration and determine whether MFA or device claims from another tenant are trusted. Trust should be deliberate and limited to organisations whose controls are understood.
Monitoring, logs and security operations
Microsoft Entra produces sign-in logs, audit logs, provisioning logs and risk information. Define who reviews these records, how long they are retained and whether they are exported to a SIEM or Log Analytics workspace. Alert on privileged role changes, emergency account activity, risky sign-ins, impossible or unusual travel, application consent, credential additions and repeated authentication failures.
Operational dashboards should also track stale accounts, inactive guests, unused applications, expiring credentials, failed provisioning, synchronisation health and authentication method registration. These indicators reveal governance problems before they become incidents.
Common Entra ID mistakes
Too many Global Administrators
Broad privileges are assigned because role design has not been completed.
Shared administrator accounts
Accountability is lost and credentials are difficult to protect or revoke.
Weak guest governance
External users remain indefinitely after projects and relationships end.
Uncontrolled application consent
Applications receive access to organisational data without sufficient review.
Hybrid identity without monitoring
Synchronisation failures or unsafe rules go unnoticed.
No lifecycle ownership
Joiner, mover and leaver actions depend on informal manual requests.
Microsoft Entra ID deployment roadmap
Assess the tenant
Inventory domains, users, groups, roles, applications, devices, guests, synchronisation and authentication methods.
Secure administration
Create emergency access, reduce privileged assignments and establish separate admin accounts.
Modernise authentication
Deploy approved methods, MFA, passwordless options, SSPR and registration controls.
Implement access policy
Use Conditional Access to protect administrators, users, applications and devices.
Improve lifecycle
Standardise joiner, mover and leaver processes, groups, licences and guest sponsorship.
Govern applications
Control consent, SSO, provisioning, credentials and enterprise application ownership.
Add governance capabilities
Use PIM, access reviews, entitlement management and lifecycle workflows where appropriate.
Operationalise monitoring
Create dashboards, alerts, log retention and recurring configuration reviews.
Microsoft Entra ID checklist
Frequently asked questions
Microsoft Entra ID is Microsoft's cloud identity and access management service for users, devices, applications and workloads.
Yes. Azure Active Directory was renamed Microsoft Entra ID. Existing capabilities, licences and technical identifiers largely continue under the new name.
Yes. Microsoft 365 relies on a Microsoft Entra tenant for identities, authentication, applications, devices and access policy.
Registered devices usually represent a workplace relationship on a personal device, while joined devices use Microsoft Entra ID as the primary organisational identity for sign-in.
Hybrid identity synchronises or connects on-premises Active Directory identities with Microsoft Entra ID so users can access both on-premises and cloud resources.
Privileged administration should normally use separate accounts with stronger controls, limited roles and just-in-time activation where available.
Require a business sponsor, limit invitation rights, apply access policy, set expiry or reviews and remove guests when the business need ends.
Monitor sign-in, audit, provisioning and risk logs, especially privileged changes, risky events, application consent, emergency accounts and repeated failures.
Strengthening your identity environment?
Fedelta can review your Microsoft Entra tenant, improve authentication and access controls, and establish practical identity governance.