A Practical Guide to Identity and Access Management Design from Entra ID to PIM

Key concepts for the AZ-305 Identity & Access domain (20–25% of the exam): Entra ID permission model, RBAC inheritance, Conditional Access MFA strategy, Managed Identity

AZ-305 Solution Architect exam allocates roughly 20–25% of all questions to the Identity and Access Management domain. Beyond memorizing RBAC roles, you must be able to design who can access what, under which identity, and at which scope. This guide covers Entra ID core concepts, RBAC inheritance, Conditional Access, Managed Identity, and Privileged Identity Management — the most frequently tested topics — paired with practical scenarios. Whether you are new to AZ-305 or an experienced cloud engineer, this guide gives you decision criteria you can apply right away.

---

 

Entra ID Core Concepts

Microsoft Entra ID (formerly Azure Active Directory) is the access management backbone of the Azure environment. Just as a badge determines which areas of a building you can enter, Entra ID decides which cloud resources a given identity can access.

Delegated Permission vs Application Permission

Delegated Permission means an app acts on behalf of the signed-in user. It accesses resources only within the scopes the user has explicitly consented to, using the Authorization Code Flow. For example, when a web app needs to read a signed-in user's calendar, it uses Calendars.Read (Delegated).

Application Permission means the app runs under its own identity with no user present. It uses the Client Credentials Flow, and Admin Consent is mandatory. When a backend API defines App Roles and those roles are assigned as application permissions to a client app, those roles appear in the claim of the access token.

Keyword guide: if you see "on behalf of the user" or "user consent," choose Delegated Permission. If you see "service-to-service authentication with no user interaction," choose Application Permission.

Administrative Units and Delegated Administration

To let department IT admins manage only their own department's users, assign the User Administrator role scoped to the corresponding Administrative Unit (AU). Because the Helpdesk Administrator role cannot create new users, you must select User Administrator when new account creation is required.

Hybrid Identity: PHS vs PTA vs AD FS

Password Hash Synchronization (PHS) syncs password hashes to Entra ID, so cloud authentication continues even if the on-premises AD goes down. Pass-through Authentication (PTA) forwards authentication requests to an on-premises agent, so authentication fails if the on-premises connection is lost.

Exam tip: if the requirement is "maintain cloud authentication even during on-premises outage," choose PHS. If "passwords must not be stored in the cloud," choose PTA or AD FS. Note that Microsoft Entra Connect can synchronize multiple on-premises AD forests into a single Entra tenant; child domains within a single forest are handled by a single agent.

!Hybrid identity: PHS, PTA, and AD FS

RBAC Design and Permission Delegation

RBAC (Role-Based Access Control) is like giving different keys to different job titles. Azure RBAC role assignments automatically inherit from higher scopes down to lower scopes.

Assigning a role at the Management Group level applies automatically to all child subscriptions and resources — no additional configuration needed. Nested groups are also supported, so a role on a parent group propagates to members of child groups.

Key limitation: RBAC role assignments do not cross tenant boundaries. To grant Reader access to five subscriptions spread across two independent Entra tenants, assign at the Management Group level once per tenant — two assignments total.

Contributor limitation: Contributor can create, modify, and delete resources, but it does not include . If you need to grant roles to other users, Owner or User Access Administrator is required.

ABAC lets you further refine access based on resource attributes (tags, container names) without changing existing roles. It is currently supported only for Azure Blob Storage data plane operations — Files, Queue, and Table Storage are not supported.

---

 

Conditional Access and MFA Strategy

Conditional Access is a Zero Trust policy engine that evaluates composite signals — user, device, location, app, and risk level — and responds with Allow, Block, or a step-up authentication challenge.

Forcing MFA registration and forcing MFA sign-in are different things. Forcing MFA registration uses the Conditional Access MFA Registration policy to make users enroll an MFA method. Forcing MFA sign-in sets the "Require MFA" option in the Grant control so that access is allowed only after the user completes MFA authentication at sign-in time.

To block BYOD and allow access only from managed devices, set the "Compliant Device" condition. Azure Firewall and NSG do not understand device management state, so always use Conditional Access for device-based access control.

Requiring MFA for administrators accessing the Azure Portal can be solved with a single policy that combines user group, cloud app (Microsoft Azure Management), and Grant control (Require MFA).

VM access security: use Azure Bastion when you need RDP/SSH access without exposing a public IP. JIT VM Access temporarily opens a public port, so if the requirement is "remove public IP exposure," choose Bastion + Conditional Access.

---

 

Managed Identity and Service Authentication

Use Managed Identity when you need service-to-service authentication in Azure without storing credentials in code or configuration files. The Azure platform automatically issues and renews tokens, eliminating expiry and rotation management overhead.

System-assigned Managed Identity has a lifecycle tied to the specific Azure resource. When the resource is deleted, the identity is automatically removed as well. User-assigned Managed Identity can be shared across multiple resources.

Exam tip: if each resource needs a separate credential, choose System-assigned. If multiple resources share the same identity, choose User-assigned.

Key Vault integration pattern: assign the "Key Vault Secrets User" role to the Managed Identity to access secrets without any code changes. If authentication succeeds but reads fail, the authorization step is missing. Successful Managed Identity authentication only confirms the identity; reading a secret separately requires Get/List permissions.

To obtain a Managed Identity token from inside a VM using only REST calls (no SDK), use the Azure Instance Metadata Service (IMDS).

---

 

Service Comparison Table

| Service | Primary Use | License | Key Feature | |---------|-------------|---------|-------------| | Entra ID PIM | JIT privileged role management | P2 | Eligible assignment, approval workflow, audit log | | Access Reviews | Periodic access rights review | P2 | Recurrence schedule, self-review, auto-remove on no response | | Entitlement Management | Time-limited access for external users | P2 | Access packages, automatic expiry, self-service request | | Conditional Access | Conditional access policy engine | P1 | Composite signal evaluation: user/device/location/app | | Application Proxy | Publish on-premises apps without VPN | P1 | Reverse proxy, KCD support, no code changes required | | Entra Domain Services | Fully managed LDAP/Kerberos domain | Separate SKU | No on-premises connectivity needed, legacy app compatible |

---

 

Frequently Confused Selection Criteria on the Exam

Decision criteria based on actual exam scenario patterns.

PIM vs Access Reviews — PIM controls when a role is activated; Access Reviews periodically determines who should continue holding a role. When both requirements appear together, choose PIM + Access Reviews.

Application Proxy vs Azure Bastion — Application Proxy publishes HTTP/HTTPS-based web apps to the internet without VPN. Azure Bastion is exclusively for RDP/SSH access to VMs. For SSO access to an on-premises IWA app without VPN, choose Application Proxy.

Entra B2B vs B2C — If partner employees already have Entra ID accounts, use B2B guest invitation. If the target audience is consumers or users with social accounts, choose B2C.

Entra Domain Services vs Entra Connect — If a legacy app uses LDAP authentication and there must be no on-premises connectivity, choose Entra Domain Services. If the goal is to synchronize on-premises AD users into Entra ID, use Entra Connect.

OAuth 2.0 flow selection — When a web app calls a backend API on behalf of a signed-in user, use the On-Behalf-Of (OBO) Flow. For service-to-service calls with no user, use Client Credentials Flow. For a user logging directly into an app, use Authorization Code Flow.

---

 

Practical Tips for Real-World Application

Convert permanent role assignments to Eligible assignments (PIM) wherever possible. Requiring on-demand activation reduces the risk of privilege abuse. Keep role assignments to a minimum using group-based assignments, keeping the 4,000 role assignments per subscription limit in mind.

Make full use of the Management Group hierarchy. As the number of subscriptions grows, assigning roles individually to each subscription becomes inefficient. Assigning a role once at the Management Group level automatically propagates to all child subscriptions.

Automate external user lifecycle management with Entitlement Management access packages. Grant access only for the duration of a project and auto-revoke at expiry — zero operational overhead. Set up Access Reviews on a quarterly schedule to regularly prune unnecessary permissions.

Switching all Azure resource-to-resource authentication to Managed Identity is security best practice. Using from the Azure SDK lets your code work in both local development and production environments without credential changes.

---

 

Summary

Back to blog list