Microsoft Identity and Access Administrator — knowledge map
The 67 core concepts of Microsoft Identity and Access Administrator and how they connect. Click a node in the map above to explore related terms and prerequisites; the list below indexes every concept with its definition and links to its prerequisites and related concepts.
Concepts (67)
Authentication (AuthN)
Verifying "who you are" (identity); performed before authorization.
Conditional Access
Grants or challenges access based on conditions like location, device, or risk (a Zero Trust implementation).
Microsoft Entra ID
Cloud identity/access management (formerly Azure AD) providing MFA/SSO/Conditional Access; distinct from on-prem AD DS.
Prerequisites: Conditional Access、Access management (RBAC / least privilege / JIT)
Authentication methods (MFA / passwordless)
Means of verifying identity. Methods stronger than passwords alone, such as multifactor authentication (MFA) and passwordless (FIDO2 security keys, Authenticator, Windows Hello).
Prerequisites: Multi-factor authentication (MFA)
Microsoft Entra authentication for Azure SQL
The recommended Azure SQL authentication. Centralized in Entra ID with MFA, Conditional Access, and passwordless connections via managed identity. Enabled by configuring an Entra ID admin.
Prerequisites: Authentication methods (MFA / passwordless)、Authentication (AuthN)、Conditional Access、Microsoft Entra ID
Microsoft 365 licensing (per-user subscription)
License per user (seat), paid monthly/annually; plans include Business/Enterprise/Frontline; assign in the Microsoft 365 admin center. Differs from AWS/Azure pay-as-you-go.
Prerequisites: Microsoft 365
Microsoft 365
A SaaS productivity suite delivering email, documents, and meetings in the cloud, used via per-user subscription.
Security Service Edge (SSE) / Global Secure Access
A concept inserting a cloud security layer between users and apps. Under Microsoft’s Global Secure Access, it includes Entra Internet Access (SWG) and Entra Private Access (ZTNA). Becomes Zero Trust when integrated with Conditional Access.
Prerequisites: Conditional Access、Microsoft Entra Private Access
Related: Microsoft Entra Internet Access
Access management (RBAC / least privilege / JIT)
Role-based access control (RBAC) grants permissions by job function, applies least privilege, and PIM just-in-time (JIT) elevation enables privileges only when needed.
Prerequisites: Role-based access control (RBAC)
License assignment (direct / group-based)
Access to Microsoft 365 and Copilot features depends on license type, assigned directly to users or in bulk via group-based licensing. Copilot needs a separate license on top of existing M365 licenses.
Prerequisites: Microsoft 365 licensing (per-user subscription)、Microsoft 365、License management (assignment, billing, optimization)
Microsoft Defender for Cloud
Scores security posture (Secure Score) and detects misconfigurations/threats to recommend fixes.
Prerequisites: Microsoft Defender XDR
Multi-factor authentication (MFA)
Strengthens identity proof with a second factor beyond a password.
Prerequisites: Authentication (AuthN)
Hybrid identity (Entra Connect)
Syncs on-prem Active Directory with Entra ID for hybrid identity. Choose authentication among password hash sync, pass-through authentication, and federation (AD FS).
Prerequisites: Authentication methods (MFA / passwordless)、Authentication (AuthN)、Microsoft Entra ID、Pass-through authentication (PTA) / seamless SSO
B2B collaboration (Microsoft Entra External ID)
Invites users from external organizations (e.g., partners) as guests, letting them collaborate using their own existing identity. Now unified under Microsoft Entra External ID, invitations and permissions are governed via Conditional Access and cross-tenant access settings. An invited guest is registered as a guest user object within the inviting organization's own tenant and authenticates with their external organization's credentials—no separate tenant is created for the guest.
Prerequisites: Conditional Access、Cross-tenant access settings
Related: B2C (Azure AD B2C)
B2C (Azure AD B2C)
CIAM (customer identity and access management) functionality that customizes sign-up/sign-in for consumer-facing apps, offering branded login experiences via social login and custom policies. Legacy Azure AD B2C can no longer create new tenants as of May 2025 and is being consolidated/migrated into Microsoft Entra External ID.
Prerequisites: Microsoft Entra ID、Access management (RBAC / least privilege / JIT)
Log Analytics workspace
A data store that aggregates and retains logs/metrics from various resources. Queried with KQL (Kusto Query Language) for analysis, and underlies Microsoft Sentinel and Azure Monitor alerts. Access control and retention (default 30 days, extendable) are set per workspace.
Prerequisites: KQL (Kusto Query Language)、Retention policy
Microsoft Entra Application Proxy
Securely publishes on-prem web apps externally without a VPN, fronting them with Entra authentication + pre-authentication. Global Secure Access Private Access is the evolution, supporting non-web protocols too.
Prerequisites: Authentication (AuthN)、Microsoft Entra authentication for Azure SQL、Security Service Edge (SSE) / Global Secure Access
Microsoft Authenticator
A smartphone-app method for multifactor and passwordless sign-in. Combining push approval with number matching mitigates accidental approvals and MFA fatigue attacks. Stronger than SMS and a practical method second to passkeys (FIDO2).
Prerequisites: Authentication methods (MFA / passwordless)、Multi-factor authentication (MFA)
Identity Secure Score
A numeric measure of identity posture in Microsoft Entra ID. It shows the current score and recommended improvements, guiding actions like enforcing MFA or Conditional Access.
Prerequisites: Conditional Access、Microsoft Entra ID
Diagnostic settings
Configuration that routes a resource's logs/metrics to a destination (Log Analytics workspace, storage account for long-term archive, or Event Hub for external SIEM integration). Resource logs are not aggregated by default unless diagnostic settings route them—unlike the activity log, which is recorded automatically per subscription. Data collection rules (DCRs) let you fine-tune what's collected and how it's transformed.
Prerequisites: Azure storage account、Log Analytics workspace
Microsoft Entra ID Protection
Computes user/sign-in risk from leaked credentials, impossible travel, etc., integrating with Conditional Access.
Prerequisites: Conditional Access、Microsoft Entra ID
Managed identity
An identity letting apps access Azure resources securely without managing secrets; a service principal auto-managed by Azure.
Microsoft Intune
A cloud service to manage/secure devices and apps; MDM manages the device itself, MAM manages in-app data; integrates with Conditional Access.
Prerequisites: Conditional Access
Microsoft 365 Groups
A backbone that provides shared membership and resources across multiple services (Teams, SharePoint, Outlook, Planner, etc.), enabling cross-service collaboration from one group.
Prerequisites: Microsoft 365、Microsoft Teams、SharePoint
Windows Hello for Business
Enables passwordless authentication using biometrics (face/fingerprint) or a PIN, binding credentials to the device for phishing resistance.
Prerequisites: Authentication methods (MFA / passwordless)、Authentication (AuthN)
Microsoft Entra Internet Access
Part of Global Secure Access (SSE). Inspects/controls users’ internet/SaaS-bound traffic as a secure web gateway with cross-tenant protection. Distinguished by destination from Entra Private Access (ZTNA to internal apps).
Prerequisites: Microsoft Entra Private Access
Admin consent workflow
Lets users request app permissions and admins review/approve—curbing user consent to risky permissions and reducing consent-phishing risk. Used together with consent policies.
MFA registration campaign
Nudges users to register stronger authentication methods (e.g., Microsoft Authenticator), migrating gradually from weak methods like SMS. A nudge, not a hard block.
Prerequisites: Authentication methods (MFA / passwordless)、Authentication (AuthN)、Microsoft Authenticator
Entra ID Governance
Ensures the right people have the right access to the right resources for the right time. Includes entitlement management (access packages), access reviews, Privileged Identity Management (PIM), and lifecycle workflows.
Prerequisites: Microsoft Entra ID、Access reviews
Workload identity federation
A general-purpose mechanism where a cloud provider validates an OIDC (or similar) token issued by an external identity provider via a configured trust relationship, then exchanges it for short-lived credentials—granting access without any long-lived secret or password. Azure DevOps service connections, GitHub Actions, GCP, and AWS's OIDC federation all implement equivalent versions of this pattern. In Azure specifically, the exchange yields a token for a role-assigned service principal or managed identity, which is mechanically different from AWS's 'assume role' terminology.
Prerequisites: Service connection、Managed identity
Role-based access control (RBAC)
Authorization that grants permissions by assigning roles to identities at a scope; least privilege, inherited downward.
Self-service password reset (SSPR)
An Entra feature letting users reset passwords without an admin, requiring multiple authentication methods and supporting password writeback to on-prem.
Prerequisites: Authentication (AuthN)
Azure storage account
A container bundling Blob, File, Table, and Queue storage services.
CIEM
Cloud Infrastructure Entitlement Management continuously scans identity permissions across Azure, AWS, and GCP to surface and reduce over-provisioned (unused) entitlements. Distinct from PIM, which handles just-in-time privilege elevation—CIEM is an inventory practice that trims the standing permissions themselves.
Prerequisites: Access management (RBAC / least privilege / JIT)
KQL (Kusto Query Language)
A read-only query language for fast search/aggregation over log/time-series data; used with Eventhouse/KQL databases.
License management (assignment, billing, optimization)
Managing licenses end to end: assigning purchased licenses to users, billing per user monthly/annually, and reviewing usage to reclaim unused seats (optimization). Add-ons extend features.
Prerequisites: Microsoft 365 licensing (per-user subscription)
Protected actions
Protection that blocks the most dangerous admin operations (e.g., deleting Conditional Access policies) unless a strong authentication context (e.g., phishing-resistant MFA) is met. Adds a stricter gate than ordinary role permissions.
Prerequisites: Authentication (AuthN)、Conditional Access
Related: Authentication context
Access package (entitlement management)
Defines a bundle of access a role needs (groups, apps, SharePoint) with a policy for who can request, who approves, and for how long. Users self-request via My Access; access auto-expires.
Prerequisites: SharePoint
Access reviews
Periodically re-checks existing access (groups/apps/roles/guests) and removes what is not needed. Auto-apply removes denials automatically; PIM integration inventories privileged roles. The continuous-inventory counterpart to entitlement management (entry).
Delegated vs application permissions (API permissions)
Delegated permissions act on behalf of the signed-in user and never exceed their rights; application permissions act as the app alone, are powerful, and require admin consent. Background daemons use application permissions.
Prerequisites: Admin consent workflow
Authentication context
A label that requires extra authentication (e.g., phishing-resistant MFA) for specific actions/apps. Combined with Conditional Access and protected actions to enforce "strong auth only for the most dangerous operations."
Prerequisites: Authentication (AuthN)、Conditional Access
Related: Protected actions
Certificate-based authentication (CBA)
Authenticates users with X.509 certificates—a phishing-resistant method; combined with smart cards for high-assurance authentication. A phishing-resistant MFA alongside passkeys (FIDO2).
Prerequisites: Authentication (AuthN)
Microsoft Entra Connect Health
Monitors the health, errors, and performance of sync/authentication agents (Connect Sync, PTA, AD FS, etc.), giving visibility into the hybrid identity foundation.
Prerequisites: Authentication (AuthN)、Hybrid identity (Entra Connect)
Cross-tenant access settings
Per-partner-tenant control of inbound/outbound access and whether to trust the partner’s MFA/device-compliance claims. Differs in role from cross-tenant synchronization (auto-provisioning users).
Related: Cross-tenant synchronization
Federated credentials (workload identity federation)
Authenticates an app by trusting tokens from an external IdP (e.g., GitHub Actions) without storing a client secret or certificate. Ideal for keyless authentication from CI/CD pipelines.
Prerequisites: Authentication (AuthN)、Workload identity federation
Microsoft Graph PowerShell
A PowerShell module to automate Entra/Microsoft 365. The successor to the older AzureAD/MSOnline modules, used to programmatically run repetitive tasks like attribute updates and license assignment.
Prerequisites: Microsoft 365 licensing (per-user subscription)、Microsoft 365、License management (assignment, billing, optimization)
Pass-through authentication (PTA) / seamless SSO
PTA validates authentication on an on-prem agent, storing no passwords in the cloud; seamless SSO signs in domain-joined PCs on the corporate network without extra prompts. Contrast with PHS, the simplest method that authenticates in the cloud.
Prerequisites: Authentication (AuthN)
Temporary Access Pass (TAP)
A time-limited temporary credential used for passwordless onboarding or for re-registering users who lost an authentication method. Not a permanent authentication method.
Prerequisites: Authentication methods (MFA / passwordless)、Authentication (AuthN)
Terms of Use (ToU)
Terms requiring user acceptance as a condition of access. Integrated with Conditional Access and entitlement management so users cannot access without accepting.
Prerequisites: Conditional Access
Microsoft Entra Private Access
Replaces VPN by granting identity-based, per-app (Zero Trust) access to internal apps, reaching only the needed apps rather than the whole network.
Microsoft Defender XDR
Unifies protection across endpoints/email/identity/SaaS, correlating signals across domains (Endpoint/Office 365/Identity/Cloud Apps).
Microsoft Entra Permissions Management
Microsoft's CIEM product. Analyzes permissions across identities and resources spanning multi-cloud (Azure/AWS/GCP), surfaces a Permission Creep Index score, and proposes remediation for unused entitlements. Distinctive for giving one dashboard view of effective permissions across multiple clouds.
Prerequisites: CIEM
Microsoft Teams
A collaboration hub for chat, meetings, calls, and teamwork; files are stored behind the scenes in SharePoint/OneDrive.
Related: SharePoint
Microsoft Defender for Cloud Apps
A CASB (cloud access security broker) that discovers and controls cloud-app usage and shadow IT.
Prerequisites: Microsoft Defender for Cloud、Microsoft Defender XDR
Device compliance
The state of a device meeting Intune policy requirements (encryption, OS version, passcode, etc.). Combined with Conditional Access to allow access only from compliant devices.
Prerequisites: Conditional Access、Microsoft Intune
Retention policy
Keeps data for the required period and deletes it when no longer needed, managing its lifecycle.
Cross-tenant synchronization
Auto-provisions users from one Entra tenant into another as B2B guests, removing manual invitations. Distinct from Cross-tenant access settings, which control trust/access for partner tenants.
Related: Cross-tenant access settings
Provisioning logs
An Entra log recording results of auto-provisioning (create/update/delete of users) to SaaS apps. Differs in purpose from audit logs (directory changes) and sign-in logs (authentication events).
Prerequisites: Authentication (AuthN)
App registrations and enterprise apps
An app registration is the blueprint (template) for registering an app in Entra ID. An enterprise application is the service principal—the instance of that registration in each tenant—representing sign-in and permissions.
Prerequisites: Microsoft Entra ID
Service connection
An authorization configuration allowing Azure Pipelines to access external resources (an Azure subscription, container registry, Kubernetes cluster, etc.). Created per project, a pipeline just references the service connection name to authenticate to the target; approvals and checks control which pipelines may use it.
App permissions and consent (OAuth)
Manages access to enterprise apps via OAuth permission grants. Configure permission scopes and control user vs admin consent to prevent risky delegation.
Prerequisites: Admin consent workflow
Just-In-Time (JIT) VM access
A Defender for Cloud feature that keeps VM management ports (RDP/SSH) closed by default and, only on request/approval, inserts a temporary allow rule into the NSG/Firewall, auto-closing it after a window. It avoids standing exposure to reduce the attack surface. Unlike Bastion (an always-available jump host), JIT opens access only when needed.
Prerequisites: Microsoft Defender for Cloud
Microsoft Priva
A solution to manage personal-data privacy risks and handle data subject requests (DSRs), detecting and remediating over-retention or oversharing of personal data.
Prerequisites: Retention policy
PIM active assignment
Assigning a PIM role in an always-on (active) state. Permissions are usable immediately with no activation step, but standing high privilege raises audit risk—eligible assignment is generally recommended instead. Active assignments can still carry a start/end time bound.
Prerequisites: PIM eligible assignment
PIM eligible assignment
In PIM, assigning a role as a candidate (eligible) rather than always-on (active). The user self-activates only when needed, elevating with MFA, a justification, optional approval, and a time-bound expiry. Core to a least-privilege design that avoids standing high privilege.
Entra identity types
Identity types managed by Microsoft Entra: users (member/guest), groups, devices, and workload identities (service principals/managed identities) representing apps and services.
Prerequisites: Managed identity

