What Entra ID Is

Microsoft Entra ID: Integrations & Access Troubleshooting

Course 1 ยท Chapter 1 ยท What Entra ID Is โ€” and Where It Sits

A client rings: nobody on their side can sign in to your system. Their staff can still open Outlook and Teams without trouble, so the problem isn't their internet or their computers. Somewhere between the sign-in button and your system, a connection to Microsoft Entra ID has stopped working. This course teaches you to find out where, to read the evidence, and to explain it to the client. This first chapter gives you the map: what Entra ID is, what lives inside it, and where the pieces you'll be troubleshooting sit.

What this chapter does and doesn't do
No portal clicking yet, except for one small exercise. The aim is that, by the end, when someone says "the integration in Entra expired", you can say whose tenant it's in, what the integration is for, and who has to fix it. The details of integrations, tokens and logs follow in Chapters 2 to 9.

Identity, Authentication and Authorization

Three words come up in every Entra conversation, and they are not interchangeable. Microsoft's own definitions:

TermWhat it meansExample
IdentityA collection of identifiers or attributes that represents a person, software component, machine or other resource in a system.A work email address and the account behind it
Authentication (AuthN)Challenging someone or something for credentials to prove that it is who or what it claims to be.Password plus an MFA prompt
Authorization (AuthZ)Deciding whether an authenticated identity may access a particular resource, and at what level."This user may open the support system, but not its admin pages"

Authentication comes first and authorization after it. Microsoft's documentation also notes that the information from authentication is carried in an ID token and the information from authorization in an access token. Don't worry about tokens yet; Chapter 3 follows them step by step. For now, remember the pair of questions every sign-in answers: Who are you? and Are you allowed in?

Why this matters for support
"I can't sign in" can mean two different failures. Either the person couldn't prove who they are (authentication), or they were identified but not permitted (authorization). The fix, and the person who can do it, differ. Later chapters teach you to tell them apart from the logs. See also the Authentication & Session Security course for the general ideas of sessions and credentials.

What Microsoft Entra ID Is

Microsoft Entra ID is a cloud-based identity and access management service. Microsoft describes it as providing authentication, policy enforcement and protection for users, devices, apps and resources. In plain terms it is the organisation's central list of who exists and what they may reach, together with the service that checks credentials when they try.

That makes it an identity provider (IdP): one trusted place that creates, stores and manages identity information, so that every other system doesn't have to keep its own list of usernames and passwords. Those other systems hand the sign-in to the identity provider and trust its answer. Your product, when it offers "Sign in with Microsoft", is exactly such a system.

A client's user The client's tenant Your system --------------- ------------------- ----------- clicks "Sign in with -> Microsoft Entra ID Microsoft" on your page checks who they are (password, MFA, policies) decides if they may go on <- sends a signed answer -> trusts the answer (tokens or an assertion) lets the user in

Three consequences follow, and they explain most of this course. The decision to let someone in is made in the client's Entra tenant, not in your system. Your system's job is to ask correctly and to check that the answer really came from Entra. And when the connection between the two breaks, every user of that client is affected together, while other clients, with their own tenants, carry on as normal.

The Name: Azure AD Became Entra ID

You'll meet both names. Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID. The change was publicly announced on 11 July 2023, and the new name started to appear across Microsoft experiences from 15 August 2023; plan and SKU display names changed on 1 October 2023. Microsoft says the rename was meant, among other things, to reduce confusion with Windows Server Active Directory.

What Microsoft says did not change
It was a rename, not a new product: existing deployments, configurations and integrations continue to work, and Microsoft states that all existing login URLs, APIs, PowerShell cmdlets and Microsoft Authentication Libraries (MSAL) stay the same. Licensing, terms, SLAs and pricing also stay the same. That is why you will keep seeing "Azure AD" or "AAD" in older articles, in scripts, in your own product's documentation and in some error messages. Treat them as the same thing as Entra ID.
Old nameCurrent name
Azure Active Directory / Azure AD / AADMicrosoft Entra ID
Azure AD tenantMicrosoft Entra tenant
Azure AD Premium P1 / P2Microsoft Entra ID P1 / P2
Azure AD Conditional AccessMicrosoft Entra Conditional Access (second use: Conditional Access)
Azure AD ConnectMicrosoft Entra Connect
Azure AD admin center / Azure portal's Azure AD bladeMicrosoft Entra admin center (entra.microsoft.com), or Microsoft Entra ID in the Azure portal
Azure AD enterprise application / service principalMicrosoft Entra enterprise application / service principal
Azure AD activity logs / audit logMicrosoft Entra activity logs / audit log

A few names were deliberately not changed: Windows Server Active Directory and its related services (AD DS, AD FS), Azure AD B2C, the Azure AD Graph and Azure AD PowerShell modules (both on the path to deprecation, with Microsoft Graph and Microsoft Graph PowerShell as the replacements), and the Microsoft Authentication Library. If a document uses "Azure AD" in one of those names, it is still correct.

Expect the portal to move
Microsoft changes menu names and layouts often, and the rename itself changed many of them. Every navigation path in this course is checked against Microsoft's documentation as of writing, but the portal may differ by the time you read it. When a menu is missing, search the portal's search box for the name, and trust the concept over the exact click path.

The Entra Family, and Where Entra ID Fits

"Microsoft Entra" is the name of a family of identity and network-access products. Microsoft Entra ID is the foundational one. The others are good to recognise, because they appear in the portal and in client conversations, but this course concentrates on Entra ID.

ProductWhat it is for (in Microsoft's words, simplified)Relevance to this course
Microsoft Entra IDCloud identity and access management: authentication, policy enforcement and protection for users, devices, apps and resourcesThe subject of this course
Microsoft Entra Workload IDIdentity and access management for workload identities: applications, services and containersClosely related, because an application that signs in without a person is a workload identity
Microsoft Entra External IDSecure access for guests, partners and customersRelevant when the client's users are guests rather than employees
Microsoft Entra ID ProtectionDetects and reports identity-based risksCan cause sign-in blocks or extra prompts
Microsoft Entra ID GovernanceAutomates access requests, assignments and reviewsMostly background
Microsoft Entra Domain ServicesManaged domain services (group policy, LDAP, Kerberos/NTLM) for legacy apps in the cloudNot used by modern sign-in integrations
Microsoft Entra Verified ID, Private Access, Internet Access, Agent IDVerifiable credentials; secure access to private and internet resources; identities for AI agentsNot covered

Tenants

Everything in Entra ID lives inside a tenant: one organisation's own, separate instance of the service. Each tenant has:

  • a tenant ID, a unique identifier (a GUID) that names it,
  • an initial domain name of the form something.onmicrosoft.com, created with the tenant, and
  • optionally one or more custom domains, the organisation's own names, such as contoso.com.

If an organisation subscribes to Microsoft 365, Azure or Dynamics CRM Online, it is already using Entra ID: Microsoft's documentation says that every such tenant is automatically a Microsoft Entra tenant. This is why the same set of work accounts opens Outlook, Teams and, once someone has set it up, your system.

One client = one tenant (usually)
Each client organisation normally has its own tenant, with its own users, policies and administrators. That's why "it's broken for Fabrikam but fine for Contoso" is such a useful clue: it points to something in Fabrikam's tenant or in the connection to it, rather than to your system as a whole. A few organisations have more than one tenant, so always confirm which tenant ID the failing connection points to.

What lives inside a tenant

ObjectWhat it isWhy a support engineer cares
UsersThe identities of people (employees, and guests invited in)Who is trying to sign in, and are they enabled?
GroupsCollections of users used to grant accessAccess is often given to a group, so removing someone from it can lock them out
DevicesRegistered, joined or managed devicesPolicies can require a compliant or joined device
ApplicationsThe apps that use Entra for sign-in or that call Entra-protected APIs (app registrations and enterprise applications)This is where "the integration" lives (Chapters 2 and 5)
RolesBuilt-in Entra roles that delegate administrationDecide what you can see and what the client's admin must do (Chapter 5)
PoliciesRules such as Conditional Access that decide when and how sign-in is allowedA healthy integration can still be blocked by a policy (Chapter 6)
LogsRecords of sign-ins and of changes made in the tenantThe evidence for every investigation (Chapter 7)

Entra ID and the Other Systems It Touches

Entra ID and on-premises Active Directory

Many organisations have two directories: Windows Server Active Directory Domain Services (AD DS) in their own data centre, and Entra ID in the cloud. They are related but not the same thing. Microsoft describes Entra ID as an identity-as-a-service solution for apps across cloud and on-premises, where AD DS was built for managing on-premises infrastructure.

Windows Server Active DirectoryMicrosoft Entra ID
WhereOn-premises serversMicrosoft's cloud
Typical app sign-in methodsLDAP, Windows-integrated authentication (Kerberos, NTLM)OAuth 2.0, OpenID Connect, SAML and WS-Federation (WS-*)
SaaS appsNot supported natively; needs a federation system such as AD FSSaaS apps using OAuth 2.0, SAML or WS-* can use it directly
DevicesDomain join, Group PolicyMicrosoft Entra join, Intune management, and checks through Conditional Access

Organisations that have both usually run Microsoft Entra Connect, which syncs identities from AD DS to Entra ID so people use one account in both places. For your purposes, remember that modern sign-in integrations talk to Entra ID, not to AD DS. If a client says "it's our Active Directory", that is a prompt to find out whether they mean the on-premises directory, Entra ID, or the sync between them.

Entra ID, Microsoft 365 and Azure

Microsoft 365 and Azure use Entra ID for their own sign-in; they are customers of the same service your integration uses. The licence level of the tenant (Entra ID Free, P1 or P2, or Microsoft Entra Suite) decides which features exist. Microsoft 365 E3 includes Microsoft Entra ID P1 and Microsoft 365 E5 includes Microsoft Entra ID P2. The licence matters to this course in one practical way: it limits some features and how long some logs are kept, which Chapter 7 covers precisely.

Entra ID and your system

Your system is neither Microsoft 365 nor Active Directory. It is an application that relies on the client's Entra ID to sign people in. In identity vocabulary it is a "relying party", although you'll more often hear "the application" or "the integration". Chapter 2 explains how it is registered with the tenant and what the different integration types are.

Whose Side Is It?

An integration has two ends, and troubleshooting starts by working out which end is at fault and who owns it. In broad terms:

ItemNormally lives inWho can change it
The client's users, groups and sign-in policiesThe client's tenantThe client's Entra administrators
The integration object for your system (registration or enterprise application)The client's tenant (details depend on how it was set up; Chapter 2)The client's administrators, or you if they gave you the right role
The secret, certificate or setting your system uses to talk to EntraBoth ends: it is created in the tenant and then stored in your systemBoth sides must agree: a change in one place has to be copied to the other (Chapters 4 and 8)
Your system's own configuration and logsYour platformYou
Microsoft Entra ID service itselfMicrosoftMicrosoft (check the service health notices if everything is failing)
The most common failure, in one sentence
The connection works because a credential in the client's tenant matches what your system holds; credentials have expiry dates; when one expires, or is replaced on one side only, the match fails and every user is refused at once. That is why this course keeps coming back to expiry (Chapter 4), logs (Chapter 7) and both sides must change together (Chapter 8).

Where You Manage Entra ID

You can see and manage Microsoft Entra in three web portals, per Microsoft's documentation:

  • the Microsoft Entra admin center, https://entra.microsoft.com, the dedicated portal;
  • the Azure portal, https://portal.azure.com, where Microsoft Entra ID appears as a service; and
  • the Microsoft 365 admin center.

Administrators can also automate it through Microsoft Graph and the Microsoft Graph PowerShell module. As a support engineer you will mostly be reading the portal, often together with the client's administrator, so the first practical skill is finding which tenant you are looking at.

Finding the tenant ID

These are the steps Microsoft documents. You need to sign in as at least a Global Reader.

# Microsoft Entra admin center 1. Sign in at https://entra.microsoft.com (at least Global Reader) 2. Entra ID > Overview > Properties 3. Scroll to the "Tenant ID" box # Azure portal 1. Sign in at https://portal.azure.com 2. Microsoft Entra ID > Properties 3. Scroll to the "Tenant ID" box # Azure PowerShell (after Connect-AzAccount) Get-AzTenant # Azure CLI az account tenant list
Start every ticket with a "tenant card"
Record these on any Entra-related ticket: the client's tenant ID, their initial .onmicrosoft.com domain and primary custom domain, the licence level if you know it, and the name of an administrator you can contact. A five-minute habit that saves hours when the person who set the integration up has left the company. Chapter 5 shows where else to look, and Chapter 7's logs ask for the tenant ID too. For the wider habit of keeping this kind of record, see the Documentation & Runbooks course.

Terms to Keep Handy

TermMeaning in one line
TenantAn organisation's own instance of Entra ID, with its own users, apps and policies
Tenant IDThe unique GUID that identifies a tenant
Identity provider (IdP)The service that authenticates users and vouches for them to other systems
Authentication / authorizationProving who you are / being allowed to do something
Single sign-on (SSO)Signing in once and using the same identity across many applications
MFAMultifactor authentication: more than one proof of identity
Conditional AccessEntra policies that decide when sign-in is allowed, blocked or needs extra proof
Microsoft Entra ConnectThe tool that syncs identities from on-premises Active Directory to Entra ID
Microsoft GraphThe API through which Entra data and tasks can be accessed programmatically
Azure AD / AADThe former name of Microsoft Entra ID
One word of caution about what's coming
Several later chapters quote Microsoft's lifetimes and limits (how long a client secret can last, how long logs are kept, what a given error code means). Those numbers change, so each is verified against Microsoft's current documentation when the chapter is written, and every chapter points at the Microsoft Learn page it relied on. Always re-check a figure before telling a client it is a rule.

Hands-On Exercises

All three use fictional organisations. Do not paste real tenant IDs, secrets or client names into notes you share.

Exercise 1

Fabrikam Ltd's staff use "Sign in with Microsoft" on your product, "Acme Support Desk". Last week it began failing for everyone at Fabrikam, while Contoso, another client, is unaffected. Identify the identity provider, the tenant, the relying party, where authentication and authorization happen, and give three possible causes that fit the evidence.

๐Ÿ“„ View solution
Exercise 2

An old internal runbook mentions ten things: "Azure AD tenant", "Azure Active Directory Premium P1", "AAD Connect", "Azure AD Conditional Access", "Azure AD B2C", "ADAL", "Azure AD PowerShell", "AD FS", "Azure AD Graph" and "DirSync". For each, say whether it was renamed, and if so give the current name; if not, say what it is now.

๐Ÿ“„ View solution
Exercise 3

Write a "tenant card" template for support tickets. If you have read access to any Entra tenant (a work or training tenant), find its tenant ID in the portal, and note its initial domain. If not, fill the card in with the fictional details provided, and explain why each field helps in a sign-in investigation.

๐Ÿ“„ View solution

Chapter 1 Quick Reference

  • Entra ID = cloud identity provider: it authenticates, applies policies, and vouches for users to other systems
  • Authentication proves who you are; authorization decides what you may do
  • Renamed from Azure AD (announced 11 July 2023); URLs, APIs, PowerShell cmdlets and MSAL are unchanged
  • Not renamed: Active Directory / AD FS, Azure AD B2C, the Azure AD Graph and Azure AD PowerShell modules, ADAL/MSAL
  • Everything lives in a tenant (tenant ID + .onmicrosoft.com domain + custom domains); one client is normally one tenant
  • Your system is an application that relies on the client's tenant to sign people in
  • The decision is made in the client's tenant; a broken connection affects all that client's users at once
  • Portals: entra.microsoft.com, portal.azure.com, Microsoft 365 admin center
  • Tenant ID: Entra admin center > Entra ID > Overview > Properties (at least Global Reader), or Get-AzTenant / az account tenant list
  • Start every ticket with a tenant card: tenant ID, domains, licence level, admin contact