Instiq

Microsoft Identity and Access Administrator — knowledge map

The 67 core concepts of Microsoft Identity and Access Administrator and how they connect. Click a node in the map above to explore related terms and prerequisites; the list below indexes every concept with its definition and links to its prerequisites and related concepts.

Concepts (67)

  • Authentication (AuthN)

    Verifying "who you are" (identity); performed before authorization.

  • Conditional Access

    Grants or challenges access based on conditions like location, device, or risk (a Zero Trust implementation).

  • Microsoft Entra ID

    Cloud identity/access management (formerly Azure AD) providing MFA/SSO/Conditional Access; distinct from on-prem AD DS.

    Prerequisites: Conditional AccessAccess management (RBAC / least privilege / JIT)

  • Authentication methods (MFA / passwordless)

    Means of verifying identity. Methods stronger than passwords alone, such as multifactor authentication (MFA) and passwordless (FIDO2 security keys, Authenticator, Windows Hello).

    Prerequisites: Multi-factor authentication (MFA)

  • Microsoft Entra authentication for Azure SQL

    The recommended Azure SQL authentication. Centralized in Entra ID with MFA, Conditional Access, and passwordless connections via managed identity. Enabled by configuring an Entra ID admin.

    Prerequisites: Authentication methods (MFA / passwordless)Authentication (AuthN)Conditional AccessMicrosoft Entra ID

  • Microsoft 365 licensing (per-user subscription)

    License per user (seat), paid monthly/annually; plans include Business/Enterprise/Frontline; assign in the Microsoft 365 admin center. Differs from AWS/Azure pay-as-you-go.

    Prerequisites: Microsoft 365

  • Microsoft 365

    A SaaS productivity suite delivering email, documents, and meetings in the cloud, used via per-user subscription.

  • Security Service Edge (SSE) / Global Secure Access

    A concept inserting a cloud security layer between users and apps. Under Microsoft’s Global Secure Access, it includes Entra Internet Access (SWG) and Entra Private Access (ZTNA). Becomes Zero Trust when integrated with Conditional Access.

    Prerequisites: Conditional AccessMicrosoft Entra Private Access

    Related: Microsoft Entra Internet Access

  • Access management (RBAC / least privilege / JIT)

    Role-based access control (RBAC) grants permissions by job function, applies least privilege, and PIM just-in-time (JIT) elevation enables privileges only when needed.

    Prerequisites: Role-based access control (RBAC)

  • License assignment (direct / group-based)

    Access to Microsoft 365 and Copilot features depends on license type, assigned directly to users or in bulk via group-based licensing. Copilot needs a separate license on top of existing M365 licenses.

    Prerequisites: Microsoft 365 licensing (per-user subscription)Microsoft 365License management (assignment, billing, optimization)

  • Microsoft Defender for Cloud

    Scores security posture (Secure Score) and detects misconfigurations/threats to recommend fixes.

    Prerequisites: Microsoft Defender XDR

  • Multi-factor authentication (MFA)

    Strengthens identity proof with a second factor beyond a password.

    Prerequisites: Authentication (AuthN)

  • Hybrid identity (Entra Connect)

    Syncs on-prem Active Directory with Entra ID for hybrid identity. Choose authentication among password hash sync, pass-through authentication, and federation (AD FS).

    Prerequisites: Authentication methods (MFA / passwordless)Authentication (AuthN)Microsoft Entra IDPass-through authentication (PTA) / seamless SSO

  • B2B collaboration (Microsoft Entra External ID)

    Invites users from external organizations (e.g., partners) as guests, letting them collaborate using their own existing identity. Now unified under Microsoft Entra External ID, invitations and permissions are governed via Conditional Access and cross-tenant access settings. An invited guest is registered as a guest user object within the inviting organization's own tenant and authenticates with their external organization's credentials—no separate tenant is created for the guest.

    Prerequisites: Conditional AccessCross-tenant access settings

    Related: B2C (Azure AD B2C)

  • B2C (Azure AD B2C)

    CIAM (customer identity and access management) functionality that customizes sign-up/sign-in for consumer-facing apps, offering branded login experiences via social login and custom policies. Legacy Azure AD B2C can no longer create new tenants as of May 2025 and is being consolidated/migrated into Microsoft Entra External ID.

    Prerequisites: Microsoft Entra IDAccess management (RBAC / least privilege / JIT)

    Related: B2B collaboration (Microsoft Entra External ID)

  • Log Analytics workspace

    A data store that aggregates and retains logs/metrics from various resources. Queried with KQL (Kusto Query Language) for analysis, and underlies Microsoft Sentinel and Azure Monitor alerts. Access control and retention (default 30 days, extendable) are set per workspace.

    Prerequisites: KQL (Kusto Query Language)Retention policy

  • Microsoft Entra Application Proxy

    Securely publishes on-prem web apps externally without a VPN, fronting them with Entra authentication + pre-authentication. Global Secure Access Private Access is the evolution, supporting non-web protocols too.

    Prerequisites: Authentication (AuthN)Microsoft Entra authentication for Azure SQLSecurity Service Edge (SSE) / Global Secure Access

  • Microsoft Authenticator

    A smartphone-app method for multifactor and passwordless sign-in. Combining push approval with number matching mitigates accidental approvals and MFA fatigue attacks. Stronger than SMS and a practical method second to passkeys (FIDO2).

    Prerequisites: Authentication methods (MFA / passwordless)Multi-factor authentication (MFA)

  • Identity Secure Score

    A numeric measure of identity posture in Microsoft Entra ID. It shows the current score and recommended improvements, guiding actions like enforcing MFA or Conditional Access.

    Prerequisites: Conditional AccessMicrosoft Entra ID

  • Diagnostic settings

    Configuration that routes a resource's logs/metrics to a destination (Log Analytics workspace, storage account for long-term archive, or Event Hub for external SIEM integration). Resource logs are not aggregated by default unless diagnostic settings route them—unlike the activity log, which is recorded automatically per subscription. Data collection rules (DCRs) let you fine-tune what's collected and how it's transformed.

    Prerequisites: Azure storage accountLog Analytics workspace

  • Microsoft Entra ID Protection

    Computes user/sign-in risk from leaked credentials, impossible travel, etc., integrating with Conditional Access.

    Prerequisites: Conditional AccessMicrosoft Entra ID

  • Managed identity

    An identity letting apps access Azure resources securely without managing secrets; a service principal auto-managed by Azure.

  • Microsoft Intune

    A cloud service to manage/secure devices and apps; MDM manages the device itself, MAM manages in-app data; integrates with Conditional Access.

    Prerequisites: Conditional Access

  • Microsoft 365 Groups

    A backbone that provides shared membership and resources across multiple services (Teams, SharePoint, Outlook, Planner, etc.), enabling cross-service collaboration from one group.

    Prerequisites: Microsoft 365Microsoft TeamsSharePoint

  • Windows Hello for Business

    Enables passwordless authentication using biometrics (face/fingerprint) or a PIN, binding credentials to the device for phishing resistance.

    Prerequisites: Authentication methods (MFA / passwordless)Authentication (AuthN)

  • Microsoft Entra Internet Access

    Part of Global Secure Access (SSE). Inspects/controls users’ internet/SaaS-bound traffic as a secure web gateway with cross-tenant protection. Distinguished by destination from Entra Private Access (ZTNA to internal apps).

    Prerequisites: Microsoft Entra Private Access

    Related: Security Service Edge (SSE) / Global Secure Access

  • MFA registration campaign

    Nudges users to register stronger authentication methods (e.g., Microsoft Authenticator), migrating gradually from weak methods like SMS. A nudge, not a hard block.

    Prerequisites: Authentication methods (MFA / passwordless)Authentication (AuthN)Microsoft Authenticator

  • Entra ID Governance

    Ensures the right people have the right access to the right resources for the right time. Includes entitlement management (access packages), access reviews, Privileged Identity Management (PIM), and lifecycle workflows.

    Prerequisites: Microsoft Entra IDAccess reviews

  • Workload identity federation

    A general-purpose mechanism where a cloud provider validates an OIDC (or similar) token issued by an external identity provider via a configured trust relationship, then exchanges it for short-lived credentials—granting access without any long-lived secret or password. Azure DevOps service connections, GitHub Actions, GCP, and AWS's OIDC federation all implement equivalent versions of this pattern. In Azure specifically, the exchange yields a token for a role-assigned service principal or managed identity, which is mechanically different from AWS's 'assume role' terminology.

    Prerequisites: Service connectionManaged identity

  • Role-based access control (RBAC)

    Authorization that grants permissions by assigning roles to identities at a scope; least privilege, inherited downward.

  • Self-service password reset (SSPR)

    An Entra feature letting users reset passwords without an admin, requiring multiple authentication methods and supporting password writeback to on-prem.

    Prerequisites: Authentication (AuthN)

  • Azure storage account

    A container bundling Blob, File, Table, and Queue storage services.

  • CIEM

    Cloud Infrastructure Entitlement Management continuously scans identity permissions across Azure, AWS, and GCP to surface and reduce over-provisioned (unused) entitlements. Distinct from PIM, which handles just-in-time privilege elevation—CIEM is an inventory practice that trims the standing permissions themselves.

    Prerequisites: Access management (RBAC / least privilege / JIT)

  • KQL (Kusto Query Language)

    A read-only query language for fast search/aggregation over log/time-series data; used with Eventhouse/KQL databases.

  • License management (assignment, billing, optimization)

    Managing licenses end to end: assigning purchased licenses to users, billing per user monthly/annually, and reviewing usage to reclaim unused seats (optimization). Add-ons extend features.

    Prerequisites: Microsoft 365 licensing (per-user subscription)

  • Protected actions

    Protection that blocks the most dangerous admin operations (e.g., deleting Conditional Access policies) unless a strong authentication context (e.g., phishing-resistant MFA) is met. Adds a stricter gate than ordinary role permissions.

    Prerequisites: Authentication (AuthN)Conditional Access

    Related: Authentication context

  • Access package (entitlement management)

    Defines a bundle of access a role needs (groups, apps, SharePoint) with a policy for who can request, who approves, and for how long. Users self-request via My Access; access auto-expires.

    Prerequisites: SharePoint

  • Access reviews

    Periodically re-checks existing access (groups/apps/roles/guests) and removes what is not needed. Auto-apply removes denials automatically; PIM integration inventories privileged roles. The continuous-inventory counterpart to entitlement management (entry).

  • Delegated vs application permissions (API permissions)

    Delegated permissions act on behalf of the signed-in user and never exceed their rights; application permissions act as the app alone, are powerful, and require admin consent. Background daemons use application permissions.

    Prerequisites: Admin consent workflow

  • Authentication context

    A label that requires extra authentication (e.g., phishing-resistant MFA) for specific actions/apps. Combined with Conditional Access and protected actions to enforce "strong auth only for the most dangerous operations."

    Prerequisites: Authentication (AuthN)Conditional Access

    Related: Protected actions

  • Certificate-based authentication (CBA)

    Authenticates users with X.509 certificates—a phishing-resistant method; combined with smart cards for high-assurance authentication. A phishing-resistant MFA alongside passkeys (FIDO2).

    Prerequisites: Authentication (AuthN)

  • Microsoft Entra Connect Health

    Monitors the health, errors, and performance of sync/authentication agents (Connect Sync, PTA, AD FS, etc.), giving visibility into the hybrid identity foundation.

    Prerequisites: Authentication (AuthN)Hybrid identity (Entra Connect)

  • Cross-tenant access settings

    Per-partner-tenant control of inbound/outbound access and whether to trust the partner’s MFA/device-compliance claims. Differs in role from cross-tenant synchronization (auto-provisioning users).

    Related: Cross-tenant synchronization

  • Federated credentials (workload identity federation)

    Authenticates an app by trusting tokens from an external IdP (e.g., GitHub Actions) without storing a client secret or certificate. Ideal for keyless authentication from CI/CD pipelines.

    Prerequisites: Authentication (AuthN)Workload identity federation

  • Microsoft Graph PowerShell

    A PowerShell module to automate Entra/Microsoft 365. The successor to the older AzureAD/MSOnline modules, used to programmatically run repetitive tasks like attribute updates and license assignment.

    Prerequisites: Microsoft 365 licensing (per-user subscription)Microsoft 365License management (assignment, billing, optimization)

  • Pass-through authentication (PTA) / seamless SSO

    PTA validates authentication on an on-prem agent, storing no passwords in the cloud; seamless SSO signs in domain-joined PCs on the corporate network without extra prompts. Contrast with PHS, the simplest method that authenticates in the cloud.

    Prerequisites: Authentication (AuthN)

  • Temporary Access Pass (TAP)

    A time-limited temporary credential used for passwordless onboarding or for re-registering users who lost an authentication method. Not a permanent authentication method.

    Prerequisites: Authentication methods (MFA / passwordless)Authentication (AuthN)

  • Terms of Use (ToU)

    Terms requiring user acceptance as a condition of access. Integrated with Conditional Access and entitlement management so users cannot access without accepting.

    Prerequisites: Conditional Access

  • Microsoft Entra Private Access

    Replaces VPN by granting identity-based, per-app (Zero Trust) access to internal apps, reaching only the needed apps rather than the whole network.

  • SharePoint

    The basis for team/org sites and document sharing; many people co-edit shared documents. Teams channel files are stored here.

    Related: Microsoft Teams

  • Microsoft Defender XDR

    Unifies protection across endpoints/email/identity/SaaS, correlating signals across domains (Endpoint/Office 365/Identity/Cloud Apps).

  • Microsoft Entra Permissions Management

    Microsoft's CIEM product. Analyzes permissions across identities and resources spanning multi-cloud (Azure/AWS/GCP), surfaces a Permission Creep Index score, and proposes remediation for unused entitlements. Distinctive for giving one dashboard view of effective permissions across multiple clouds.

    Prerequisites: CIEM

  • Microsoft Teams

    A collaboration hub for chat, meetings, calls, and teamwork; files are stored behind the scenes in SharePoint/OneDrive.

    Related: SharePoint

  • Microsoft Defender for Cloud Apps

    A CASB (cloud access security broker) that discovers and controls cloud-app usage and shadow IT.

    Prerequisites: Microsoft Defender for CloudMicrosoft Defender XDR

  • Device compliance

    The state of a device meeting Intune policy requirements (encryption, OS version, passcode, etc.). Combined with Conditional Access to allow access only from compliant devices.

    Prerequisites: Conditional AccessMicrosoft Intune

  • Retention policy

    Keeps data for the required period and deletes it when no longer needed, managing its lifecycle.

  • Cross-tenant synchronization

    Auto-provisions users from one Entra tenant into another as B2B guests, removing manual invitations. Distinct from Cross-tenant access settings, which control trust/access for partner tenants.

    Related: Cross-tenant access settings

  • Provisioning logs

    An Entra log recording results of auto-provisioning (create/update/delete of users) to SaaS apps. Differs in purpose from audit logs (directory changes) and sign-in logs (authentication events).

    Prerequisites: Authentication (AuthN)

  • App registrations and enterprise apps

    An app registration is the blueprint (template) for registering an app in Entra ID. An enterprise application is the service principal—the instance of that registration in each tenant—representing sign-in and permissions.

    Prerequisites: Microsoft Entra ID

  • Service connection

    An authorization configuration allowing Azure Pipelines to access external resources (an Azure subscription, container registry, Kubernetes cluster, etc.). Created per project, a pipeline just references the service connection name to authenticate to the target; approvals and checks control which pipelines may use it.

  • Just-In-Time (JIT) VM access

    A Defender for Cloud feature that keeps VM management ports (RDP/SSH) closed by default and, only on request/approval, inserts a temporary allow rule into the NSG/Firewall, auto-closing it after a window. It avoids standing exposure to reduce the attack surface. Unlike Bastion (an always-available jump host), JIT opens access only when needed.

    Prerequisites: Microsoft Defender for Cloud

  • Microsoft Priva

    A solution to manage personal-data privacy risks and handle data subject requests (DSRs), detecting and remediating over-retention or oversharing of personal data.

    Prerequisites: Retention policy

  • PIM active assignment

    Assigning a PIM role in an always-on (active) state. Permissions are usable immediately with no activation step, but standing high privilege raises audit risk—eligible assignment is generally recommended instead. Active assignments can still carry a start/end time bound.

    Prerequisites: PIM eligible assignment

  • PIM eligible assignment

    In PIM, assigning a role as a candidate (eligible) rather than always-on (active). The user self-activates only when needed, elevating with MFA, a justification, optional approval, and a time-bound expiry. Core to a least-privilege design that avoids standing high privilege.

  • Entra identity types

    Identity types managed by Microsoft Entra: users (member/guest), groups, devices, and workload identities (service principals/managed identities) representing apps and services.

    Prerequisites: Managed identity