Microsoft Entra (Identity)
Identity, authentication, Conditional Access, PIM, and governance. 37 guides in this topic.
- App consent policies and the admin consent workflowHow to stop consent phishing without blocking legitimate apps: Entra ID app consent policies, the admin consent workflow, and a review process that scales.
- Conditional Access break-glass account designHow to design break-glass accounts that survive every Conditional Access disaster — credentials, monitoring, and recovery.
- Cross-Tenant Access Settings designHow to design Cross-Tenant Access Settings (CTAS) — the foundational trust controls for B2B and cross-tenant collaboration.
- Cross-tenant calendar sharingHow to share calendar free/busy between Microsoft 365 tenants — organisation relationships and modern alternatives.
- Cross-tenant synchronization in Entra IDCross-tenant synchronization auto-provisions B2B guests between Microsoft Entra ID tenants in a multi-tenant organisation.
- Entitlement Management access packagesHow access packages bundle Microsoft 365 access into requestable, governed units — the modern way to provision access at scale.
- Entra Connect vs Entra Cloud SyncThe two ways to sync on-prem Active Directory to Entra ID — what each does, the scenarios that still force the old tool, and which to use today.
- Entra External ID vs Azure AD B2CMicrosoft has two products for customer identity. Here's the difference and which to pick today.
- Entra ID Administrative UnitsAdministrative Units scope admin roles to subsets of the directory — for delegated administration without tenant-wide privileges.
- Entra ID app registrations and enterprise appsTwo sides of the same coin — app registrations define an app, enterprise apps grant it to your tenant. Here's how they relate.
- Entra ID authentication contextsAuthentication contexts let Conditional Access trigger step-up authentication for specific actions, not just specific apps.
- Entra ID B2B guest accessHow Entra ID B2B brings external users into your tenant as guests — invitations, controls, and lifecycle.
- Entra ID Conditional Access designDesigning a Conditional Access baseline — policies, principles, the order they should be written in, and the operational habits that keep the estate healthy over time.
- Entra ID custom rolesHow to design and assign custom administrative roles in Microsoft Entra ID for fine-grained least-privilege access.
- Entra ID Governance explainedMicrosoft's identity governance product — access reviews, entitlement management, lifecycle workflows, and separation of duties — plus the P2 vs Entra Suite vs standalone licensing maze, and a rollout order that works.
- Entra ID groups and group-based licensingGroup types in Entra ID, dynamic groups, and using groups to assign licences automatically.
- Entra ID Lifecycle WorkflowsLifecycle Workflows automate joiner-mover-leaver tasks based on user attribute triggers.
- Entra ID Multi-Tenant OrganizationsMTO is Microsoft's modern model for running multiple Microsoft 365 tenants as one organisation. Here's what it provides.
- Entra ID passwordless authenticationThe realistic options for going passwordless in Microsoft 365 — Authenticator, FIDO2, Windows Hello, and passkeys.
- Entra ID Privileged Identity ManagementPIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
- Entra ID self-service password resetSSPR lets users reset their own passwords without calling the help desk. Here's the configuration and rollout.
- Entra ID Workload IdentitiesWorkload Identities is Entra ID's product for managing non-human identities — apps, services, scripts — and the risks they create.
- Entra Permissions ManagementMicrosoft's Cloud Infrastructure Entitlement Management (CIEM) product, covering Azure, AWS, and GCP permissions.
- Hybrid identity strategy for Microsoft 365How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
- Microsoft 365 service principal best practicesHow to design, deploy, and operate service principals safely — credentials, permissions, and lifecycle.
- Microsoft Entra Connect HealthConnect Health monitors the hybrid-identity infrastructure — Entra Connect, AD FS, and AD DS.
- Microsoft Entra Global Secure AccessMicrosoft's SSE platform — Internet Access and Private Access for zero-trust network access. Here's what it does.
- Microsoft Entra ID Access ReviewsHow access reviews keep group memberships and role assignments healthy over time — periodic recertification at scale.
- Microsoft Entra ID RecommendationsThe Entra ID Recommendations dashboard surfaces tenant-specific improvement actions based on Microsoft's analysis.
- Microsoft Entra password protectionHow Entra ID's password protection blocks weak and breached passwords — for both cloud and on-prem AD accounts.
- Microsoft Entra Verified IDEntra Verified ID is Microsoft's decentralised identity / verifiable credential service. Here's the model and the use cases.
- PIM operational playbookHow to run Privileged Identity Management as a working process — onboarding, activation, approvals, and audit.
- SAML SSO with Entra IDHow to set up SAML single sign-on between a third-party app and Microsoft Entra ID.
- SCIM provisioning to Entra IDHow SCIM auto-provisions users from HR and identity systems into Entra ID and downstream SaaS apps.
- Testing Conditional Access policiesHow to test Conditional Access policies before enforcing them — report-only mode, what-if, and rollout patterns.
- The Entra Suite explainedMicrosoft's Entra Suite bundles Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection into a single per-user licence. What each product does, how the bundle economics work, and when it's the right SKU.
- Token protection and token theft in Microsoft 365Token theft has become a leading attack pattern. Here's how it works and what Microsoft 365 offers to defend against it.
Looking for something else? Browse all guides.