What is Entra ID?
Microsoft Entra ID (formerly Azure AD) is the cloud-based identity and access management (IAM) service at the heart of Azure.
It allows organizations to:
-
Authenticate users and devices.
-
Control access to apps and resources.
-
Integrate with on-premises Active Directory.
-
Enable single sign-on (SSO) across SaaS and Azure apps.
Think of Entra ID as the digital gatekeeper that ensures the right people (or systems) get access to the right resources under the right conditions.
Key Design Elements
-
Tenant Structure
-
Every Azure environment has a tenant, representing your organization.
-
You may design with:
-
Single tenant (common for medium enterprises).
-
Multi-tenant (used for mergers, acquisitions, or global scale).
-
-
User Types
-
Internal Users – employees within the tenant.
-
Guest Users (B2B) – partners invited into your tenant.
-
Customer Users (B2C) – consumers logging into your apps with Google, Facebook, etc.
-
Authentication Methods
-
Passwordless (Windows Hello, FIDO2 keys, Authenticator app).
-
Multi-factor Authentication (MFA).
-
Conditional Access (e.g., block risky sign-ins).
-
Single Sign-On (SSO)
-
Centralizes identity → one login for Microsoft 365, Azure, SaaS apps (Salesforce, ServiceNow, etc.).
🚨 Confusion Buster
-
Entra ID vs Active Directory (on-prem):
-
On-prem AD manages Windows devices and domain-joined machines.
-
Entra ID manages cloud identities and SaaS access.
-
-
B2B vs B2C:
-
B2B = external partners collaborating inside your tenant.
-
B2C = customers signing in to your apps.
-
Example Enterprise Scenario
A multinational company wants to:
-
Provide single login for Microsoft 365 and Salesforce.
-
Allow external consultants access to a Teams channel.
-
Enable customers to log into a mobile app with Gmail credentials.
Correct design:
-
Use Entra ID tenant for internal employees.
-
Enable B2B collaboration for consultants.
-
Use Entra B2C for customer-facing app.
Exam Tips
-
If the question says “centralized authentication for Azure apps” → Entra ID.
-
If it says “partners need access to your Azure resources” → B2B.
-
If it says “customers sign in with Facebook or Google” → B2C.
-
If it says “require no passwords” → Passwordless authentication in Entra ID.
What to Expect in the Exam
-
Direct Q: “Which service provides cloud-based identity management in Azure?” → Entra ID.
-
Scenario Q: “Company needs a solution for customer login to their retail app using Google accounts.” → Entra B2C.
-
Trick Q: “On-prem AD and Azure AD are the same.” → False.