Microsoft Entra ID
Microsoft Entra ID (formerly Azure Active Directory) is Azure's cloud-based identity and access management service, handling authentication and authorization for users, groups, and applications across Azure resources and Microsoft 365. It underpins role-based access control (RBAC), Managed Identities, conditional access, and single sign-on across an organization's entire cloud footprint, replacing scattered per-app credentials with one central identity provider.
Microsoft Entra ID
Entra ID is the identity backbone behind every Azure sign-in — users, groups, app registrations, and Conditional Access policies all live here.
Why It Matters in Production
CRED enforces Entra ID as the single identity source for every internal tool (Azure Portal, GitHub, internal dashboards), so offboarding an employee in one place revokes access everywhere via SSO.
az ad user list --query "[].{Name:displayName, UPN:userPrincipalName}" --output table
RememberEntra ID (identity) and Azure RBAC (authorization) are separate systems — being an Entra ID user doesn't grant any Azure resource access until an RBAC role is assigned.
Frequently Asked Questions
Why did Microsoft rename Azure Active Directory to Microsoft Entra ID?
The rename reflects that the service had outgrown being just Azure's directory — Entra ID now underpins identity across Microsoft 365, Azure resources, and third-party SaaS apps via SSO, not only Azure infrastructure. Functionally it's the same service: the same tenant, same Graph API, same RBAC and Conditional Access engine. The name change grouped it under the broader 'Microsoft Entra' identity and access product family rather than signaling a technical rewrite.
What's a common misconfiguration teams make with Entra ID Conditional Access?
A frequent mistake is testing a new Conditional Access policy (like requiring MFA or blocking legacy auth) in report-only mode and then forgetting to actually enforce it, leaving the org unprotected while dashboards show it as 'active.' Another is creating a policy that has no exclusion for break-glass emergency accounts, which can lock every admin out simultaneously if the policy misfires — Microsoft explicitly recommends at least two excluded emergency accounts for this reason.