Entra ID guides
Microsoft's cloud identity and access service — the directory behind every Microsoft 365 sign-in. See the glossary entry →
80 guides touch on entra id.
- App consent policies and the admin consent workflow
How to stop consent phishing without blocking legitimate apps: Entra ID app consent policies, the admin consent workflow, and a review process that scales.
- Assigning licenses with group-based licensing in Entra ID
How to assign Microsoft 365 licences with group-based licensing in Entra ID: build the groups, set usage location, migrate direct assignments, fix errors.
- Branding and customisation in Microsoft 365
How to apply your organisation's branding across Microsoft 365 — logos, themes, sign-in pages, and app launcher customisation.
- Cleaning up unused enterprise apps in Entra ID
How to find unused service principals in Entra ID — sign-in activity, credentials, assignments — remove them without breaking year-end integrations.
- Continuous Access Evaluation explained
How CAE revokes access tokens in near real time when risk signals change — and what to do to make sure it works.
- Cross-tenant synchronization in Entra ID
Cross-tenant synchronization auto-provisions B2B guests between Microsoft Entra ID tenants in a multi-tenant organisation.
- Entitlement Management access packages
How access packages bundle Microsoft 365 access into requestable, governed units — the modern way to provision access at scale.
- Entra Connect vs Entra Cloud Sync
The two ways to sync on-prem Active Directory to Entra ID — what each does, the scenarios that still force the old tool, and which to use today.
- Entra External ID vs Azure AD B2C
Microsoft has two products for customer identity. Here's the difference and which to pick today.
- Entra ID Administrative Units
Administrative Units scope admin roles to subsets of the directory — for delegated administration without tenant-wide privileges.
- Entra ID app registrations and enterprise apps
Two sides of the same coin — app registrations define an app, enterprise apps grant it to your tenant. Here's how they relate.
- Entra ID authentication contexts
Authentication contexts let Conditional Access trigger step-up authentication for specific actions, not just specific apps.
- Entra ID B2B guest access
How Entra ID B2B brings external users into your tenant as guests — invitations, controls, and lifecycle.
- Entra ID Conditional Access design
Designing a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
- Entra ID custom roles
How to design and assign custom administrative roles in Microsoft Entra ID for fine-grained least-privilege access.
- Entra ID Governance explained
Entra ID Governance explained: access reviews, entitlement management, lifecycle workflows, separation of duties, P2 vs Suite licensing, and rollout order.
- Entra ID groups and group-based licensing
Group types in Entra ID, dynamic groups, and using groups to assign licences automatically.
- Entra ID Lifecycle Workflows
Lifecycle Workflows automate joiner-mover-leaver tasks based on user attribute triggers.
- Entra ID passwordless authentication
The realistic options for going passwordless in Microsoft 365 — Authenticator, FIDO2, Windows Hello, and passkeys.
- Entra ID Privileged Identity Management
PIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
- Entra ID self-service password reset
SSPR lets users reset their own passwords without calling the help desk. Here's the configuration and rollout.
- Entra ID vs Okta
Entra ID vs Okta as the identity provider: Okta's neutrality and app-integration depth against Entra's Microsoft 365 bundling and Conditional Access.
- Entra ID vs Ping Identity
Entra ID vs Ping Identity (PingOne, PingFederate, ForgeRock): federation depth, hybrid deployment, and CIAM against Entra's bundled workforce identity.
- Entra Permissions Management
Microsoft's Cloud Infrastructure Entitlement Management (CIEM) product, covering Azure, AWS, and GCP permissions.
- External access and guest access in Microsoft Teams
The four ways outsiders can collaborate with you in Teams — and the trade-offs between guest, external access, shared channels, and anonymous join.
- How to block a compromised account in Microsoft 365
How to block a compromised Microsoft 365 account in ten minutes: disable sign-in, revoke sessions, reset password and MFA, kill inbox rules and forwarding.
- How to block legacy authentication with Conditional Access
How to block legacy authentication in Entra ID with Conditional Access: find who still uses it, build the block policy, run report-only, then enforce.
- How to create a break-glass account in Entra ID
How to create an emergency access (break-glass) account in Entra ID: cloud-only, permanent Global Admin, excluded from Conditional Access, FIDO2 keys, alerting.
- How to enable guest access in Microsoft Teams
How to enable guest access in Microsoft Teams: the four switches (Entra, Microsoft 365 groups, Teams, SharePoint), guest permissions, domain lists, testing.
- How to enable self-service password reset in Entra ID
How to enable self-service password reset in Entra ID: scope, methods, registration enforcement, password writeback for hybrid, and Windows lock-screen reset.
- How to offboard a user in Microsoft 365
How to offboard a user in Microsoft 365: block sign-in, revoke sessions, handle the mailbox and OneDrive, wipe devices, remove licences, delete on schedule.
- How to require compliant devices with Conditional Access
How to require a compliant or hybrid-joined device with Conditional Access: the Intune compliance policy first, the grant control, exclusions, report-only.
- How to require MFA for all users with Conditional Access
How to require MFA for all users in Entra ID with Conditional Access: the exclusions that matter, report-only rollout, registration campaign, enforcement.
- How to reset MFA for a user in Entra ID
How to reset a user's MFA in Entra ID when they have a new phone or lost their authenticator: re-register, revoke sessions, and issue a Temporary Access Pass.
- How to restore a deleted user in Microsoft 365
How to restore a deleted user in Microsoft 365 within the 30-day window: admin center and Graph routes, UPN conflicts, what comes back, and after 30 days.
- How to set up PIM for the Global Administrator role
How to set up Privileged Identity Management for Global Administrator in Entra ID: role settings, convert permanent admins to eligible, approvals, and alerts.
- Hybrid identity strategy for Microsoft 365
How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
- Intune compliance policies and Conditional Access
Combining Intune compliance with Conditional Access gives you device-aware access control — the heart of zero trust.
- Intune macOS management
How Intune manages Mac devices — enrolment via Apple Business Manager, configuration, app deployment, and compliance.
- Intune Windows Autopilot
Windows Autopilot provisions new PCs straight to the end user with zero IT touch. Here's how it works.
- Microsoft 365 Apps Cloud Policy
The Microsoft 365 Apps Cloud Policy service applies Office app policies to users regardless of device, replacing per-device Group Policy.
- Microsoft 365 for enterprise
What changes when Microsoft 365 is deployed at enterprise scale — plans, identity, governance, and lifecycle.
- Microsoft 365 Group naming and expiration policies
Naming conventions and expiration policies keep group sprawl manageable. Here's how each works.
- Microsoft 365 Groups vs Teams vs SharePoint sites
Three closely-related concepts that confuse a lot of users. Here's the model.
- Microsoft 365 offboarding process
A complete offboarding workflow for departing users — account, data, licence, and audit handling.
- Microsoft 365 onboarding new users
A clean joiner workflow for Microsoft 365 — provisioning, access, training, and first-week experience.
- Microsoft 365 security and compliance
A practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
- Microsoft 365 service principal best practices
How to design, deploy, and operate service principals safely — credentials, permissions, and lifecycle.
- Microsoft Defender for Identity explained
Defender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here's how it works.
- Microsoft Defender for Identity sensor deployment
How to plan and roll out Defender for Identity sensors — DCs, AD FS, Entra Connect, and tuning.
- Microsoft Entra Connect Health
Connect Health monitors the hybrid-identity infrastructure — Entra Connect, AD FS, and AD DS.
- Microsoft Entra Global Secure Access
Microsoft's SSE platform — Internet Access and Private Access for zero-trust network access. Here's what it does.
- Microsoft Entra ID Access Reviews
How access reviews keep group memberships and role assignments healthy over time — periodic recertification at scale.
- Microsoft Entra ID Recommendations
The Entra ID Recommendations dashboard surfaces tenant-specific improvement actions based on Microsoft's analysis.
- Microsoft Entra password protection
How Entra ID's password protection blocks weak and breached passwords — for both cloud and on-prem AD accounts.
- Microsoft Entra Verified ID
Entra Verified ID is Microsoft's decentralised identity / verifiable credential service. Here's the model and the use cases.
- Microsoft Intune and device management
Microsoft Intune explained: what it manages, how policies work, how enrollment and compliance fit together, and where it sits in Microsoft 365.
- Microsoft Sentinel cost optimisation
How to control Microsoft Sentinel costs — ingestion tuning, commitment tiers, retention, and data tiering.
- Microsoft Sentinel for Microsoft 365
How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
- Microsoft Sentinel onboarding
How to onboard Microsoft Sentinel — workspace setup, data connectors, and starting analytic rules.
- Microsoft Tunnel for Intune
Microsoft Tunnel provides per-app VPN for managed mobile devices — the Intune-integrated way to access on-prem resources.
- Migrating from Google Workspace to Microsoft 365
A practical migration playbook for moving from Google Workspace to Microsoft 365 — workloads, tools, and pitfalls.
- Migrating from on-premises Exchange to Microsoft 365
How to move mailboxes from Exchange Server to Exchange Online — the migration types, hybrid deployment, and the realistic plan.
- Multi-language Microsoft 365 tenant setup
How to support multiple languages across a Microsoft 365 tenant — UI, content, communications, and accessibility.
- OneDrive for Business vs OneDrive (personal)
Two products, one name — the differences between work and consumer OneDrive, and why mixing them is a bad idea.
- Restoring a deleted Microsoft 365 group and its resources
What comes back when you restore a deleted Microsoft 365 group: the 30-day window, the order things reappear, what does not return, and after the window.
- Retiring on-prem Active Directory: what still requires it
What still needs on-premises Active Directory in a Microsoft 365 organisation — Kerberos, file servers, RADIUS, printing — what replaces each, and the order.
- SAML SSO with Entra ID
How to set up SAML single sign-on between a third-party app and Microsoft Entra ID.
- SCIM provisioning to Entra ID
How SCIM auto-provisions users from HR and identity systems into Entra ID and downstream SaaS apps.
- SharePoint Advanced Management
SharePoint Advanced Management adds governance, oversharing controls, and Copilot-ready controls to SharePoint Online.
- SharePoint external sharing
The layered controls that decide who outside your organisation can access SharePoint and OneDrive content — and a sane baseline configuration.
- Teams Common Area Phones
How Teams Phone supports shared, deskless phones for reception, warehouses, and shop floors.
- The Entra Suite explained
Entra Suite explained: Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection in one licence — what each does and when it pays.
- Universal Print overview
Microsoft's cloud printing service for Microsoft 365 — what it does, how to deploy it, and the limits.
- Viva Learning and LinkedIn Learning integration
How LinkedIn Learning shows up in Viva Learning: free curated content vs a full subscription, admin setup on both sides, SSO, assignment sync, and the gaps.
- What is Microsoft 365?
What Microsoft 365 is: what's in the suite, who each plan is for, how the pieces fit together, and what changed since the Office 365 days.
- What is Microsoft Entra ID?
What Microsoft Entra ID is: the identity service behind every Microsoft 365 sign-in, how it relates to Active Directory, and the licensing tiers that matter.
- What is SharePoint?
What SharePoint is: the platform behind Microsoft 365 file storage, team sites, intranets, Teams, and OneDrive — how it works and how to run it well.
- Windows 365 explained
What Windows 365 is: how Cloud PCs work, the licensing tiers, how it connects to Intune and Entra ID, and when it beats AVD or a physical laptop.
- Windows Autopatch
Microsoft's managed Windows update service — what it does, where it differs from Windows Update for Business, and when to use it.