Microsoft Entra ID and Authentication

Covers Entra ID features, identity types (user/service principal/managed identity), MFA, passwordless auth, and SSPR.

Azure SC-900: A Complete Guide to Microsoft Entra ID and Authentication Methods

What happens at a company when a new employee joins? The IT team creates an account, assigns an email address, and grants access to the systems they need. When the employee leaves, all of that is revoked. What if there are hundreds or thousands of employees? What if you add contractors and customers into the mix? Managing all of these identities systematically is exactly what Microsoft Entra ID does.

 

What Is Microsoft Entra ID?

Think of a library's membership management system — tracking who is a member, what services they can use, and how long their membership is valid. Microsoft Entra ID plays that role in the cloud world.

Microsoft Entra ID is Microsoft's cloud-based identity and access management service. It was formerly known as Azure Active Directory (Azure AD). It manages all users, groups, and applications in an organization, and controls who can access what.

Difference from Traditional Active Directory

The traditional Active Directory (AD) running on an internal company server is designed for office computers and on-premises systems. Microsoft Entra ID was built from the ground up for the cloud. It integrates with cloud applications like Microsoft 365, Azure, and Salesforce.

Key differences: Traditional AD: On-premises network-centric, uses LDAP/Kerberos protocols. Microsoft Entra ID: Cloud-centric, uses OAuth 2.0/OIDC/SAML protocols.

 

Identity Types: Many Kinds of Identity

A company is not made up of full-time employees alone. There are interns, contractor staff, automated programs, and company-owned laptops. Microsoft Entra ID manages all of these types of identities.

User

The most basic type of identity. Full-time employees fall under this category. Users are people who log in with a username and password.

Service Principal

The identity used when an application or service — rather than a person — needs to access a system. Like a delivery driver's separate access card to enter a building, this is the identity a program uses to access other services.

Examples: a web application accessing a database, or a CI/CD pipeline deploying Azure resources.

Managed Identity

An evolved form of the service principal. Regular service principals require management of a secret (a credential value). If this secret is exposed, it becomes a security risk. With a Managed Identity, Azure automatically manages this secret, so developers do not have to worry about it.

There are two types:

System-assigned Managed Identity: Tied to a specific resource such as an Azure VM or App Service. When that resource is deleted, the identity is also deleted. A 1:1 relationship.

User-assigned Managed Identity: Created independently and can be assigned to multiple resources simultaneously. Multiple VMs can share the same Managed Identity.

Device

Not only people, but devices can also have identities. When a company laptop is registered with Microsoft Entra ID, that device itself can be managed as a trusted machine. This enables policies such as "allow access to certain apps only from company-owned devices."

Guest User

Used when temporarily inviting contractor staff or partners. Guests can log in using their own organization's account (for example, a Google account) and have limited access to only specific resources.

 

Hybrid Identity: Connecting On-Premises and the Cloud

Imagine moving modern appliances into an old house. The existing wiring and the new appliances need to connect properly. In the enterprise world, organizations often need to connect their existing on-premises Active Directory with Microsoft Entra ID in the cloud.

Microsoft Entra Connect (formerly Azure AD Connect) serves this role. It synchronizes user information from the on-premises AD with Microsoft Entra ID. Employees can use a single identity for both on-premises and cloud systems, without managing separate accounts for each.

This is called hybrid identity. It provides a consistent user experience across both on-premises systems and cloud services.

 

MFA: Why Passwords Alone Are Not Enough

Imagine your front door has only one lock. If someone has a single key, they can copy it and walk in. But what if there are two locks of different types? Much harder to get in.

MFA (Multi-Factor Authentication) verifies identity using two or more methods. A password alone is not sufficient.

The 3 Categories of Authentication Factors

Something you know: Password, PIN, security question answers.

Something you have: Smartphone (to receive an SMS code), security key, smart card.

Something you are: Fingerprint, facial recognition, iris scan.

MFA combines two or more of these categories. A password (something you know) combined with a smartphone app (something you have) is the most common pairing.

Why MFA Matters

Statistics show that enabling MFA alone blocks 99.9% of automated attacks. Even if a password is leaked, without the smartphone, login is not possible.

 

Passwordless Authentication: More Secure Without a Password

It may sound paradoxical to say that removing passwords actually makes things more secure. But it makes sense when you think about it. Passwords can be guessed, leaked, or stolen through phishing. If there is no password at all, those attacks become impossible.

Windows Hello for Business

Used on PCs and laptops. Log in to Windows using facial recognition or a fingerprint. This biometric data is stored only on the device and is never transmitted over the network. Far more secure than a password.

Microsoft Authenticator App

An app installed on a smartphone. When a login attempt is made, a notification appears in the app. Select the number shown on the screen in the app, or approve with a fingerprint, and login is complete. No password entry is required.

FIDO2 Security Key

A physical security key in USB or NFC form. Products like YubiKey are typical examples. Insert the key into a computer and authentication is complete. Completely immune to phishing attacks, because it is designed not to work on fake websites.

 

SSPR: Resetting Your Own Password

Imagine it is 11 PM on a Saturday and you cannot remember your password. The IT help desk opens Monday morning at 9 AM. Imagine how frustrating that is.

SSPR (Self-Service Password Reset) solves this problem. Employees can reset their own passwords without IT team assistance. They verify their identity using a registered email or phone number, or by answering security questions.

Advantages of SSPR: Users: Can resolve the issue themselves at any time, 24/7. IT team: Reduced burden of handling password reset requests. Company: Lower IT costs.

 

External Identities: Managing People Outside the Organization

A company does not only manage its own employees. It also collaborates with contractors, partners, and customers. Microsoft Entra External ID securely manages these external users.

B2B (Business-to-Business)

Back to blog list