What Entra ID Is
Microsoft Entra ID: Integrations & Access Troubleshooting
Course 1 ยท Chapter 1 ยท What Entra ID Is โ and Where It Sits
A client rings: nobody on their side can sign in to your system. Their staff can still open Outlook and Teams without trouble, so the problem isn't their internet or their computers. Somewhere between the sign-in button and your system, a connection to Microsoft Entra ID has stopped working. This course teaches you to find out where, to read the evidence, and to explain it to the client. This first chapter gives you the map: what Entra ID is, what lives inside it, and where the pieces you'll be troubleshooting sit.
Identity, Authentication and Authorization
Three words come up in every Entra conversation, and they are not interchangeable. Microsoft's own definitions:
| Term | What it means | Example |
|---|---|---|
| Identity | A collection of identifiers or attributes that represents a person, software component, machine or other resource in a system. | A work email address and the account behind it |
| Authentication (AuthN) | Challenging someone or something for credentials to prove that it is who or what it claims to be. | Password plus an MFA prompt |
| Authorization (AuthZ) | Deciding whether an authenticated identity may access a particular resource, and at what level. | "This user may open the support system, but not its admin pages" |
Authentication comes first and authorization after it. Microsoft's documentation also notes that the information from authentication is carried in an ID token and the information from authorization in an access token. Don't worry about tokens yet; Chapter 3 follows them step by step. For now, remember the pair of questions every sign-in answers: Who are you? and Are you allowed in?
What Microsoft Entra ID Is
Microsoft Entra ID is a cloud-based identity and access management service. Microsoft describes it as providing authentication, policy enforcement and protection for users, devices, apps and resources. In plain terms it is the organisation's central list of who exists and what they may reach, together with the service that checks credentials when they try.
That makes it an identity provider (IdP): one trusted place that creates, stores and manages identity information, so that every other system doesn't have to keep its own list of usernames and passwords. Those other systems hand the sign-in to the identity provider and trust its answer. Your product, when it offers "Sign in with Microsoft", is exactly such a system.
Three consequences follow, and they explain most of this course. The decision to let someone in is made in the client's Entra tenant, not in your system. Your system's job is to ask correctly and to check that the answer really came from Entra. And when the connection between the two breaks, every user of that client is affected together, while other clients, with their own tenants, carry on as normal.
The Name: Azure AD Became Entra ID
You'll meet both names. Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID. The change was publicly announced on 11 July 2023, and the new name started to appear across Microsoft experiences from 15 August 2023; plan and SKU display names changed on 1 October 2023. Microsoft says the rename was meant, among other things, to reduce confusion with Windows Server Active Directory.
| Old name | Current name |
|---|---|
| Azure Active Directory / Azure AD / AAD | Microsoft Entra ID |
| Azure AD tenant | Microsoft Entra tenant |
| Azure AD Premium P1 / P2 | Microsoft Entra ID P1 / P2 |
| Azure AD Conditional Access | Microsoft Entra Conditional Access (second use: Conditional Access) |
| Azure AD Connect | Microsoft Entra Connect |
| Azure AD admin center / Azure portal's Azure AD blade | Microsoft Entra admin center (entra.microsoft.com), or Microsoft Entra ID in the Azure portal |
| Azure AD enterprise application / service principal | Microsoft Entra enterprise application / service principal |
| Azure AD activity logs / audit log | Microsoft Entra activity logs / audit log |
A few names were deliberately not changed: Windows Server Active Directory and its related services (AD DS, AD FS), Azure AD B2C, the Azure AD Graph and Azure AD PowerShell modules (both on the path to deprecation, with Microsoft Graph and Microsoft Graph PowerShell as the replacements), and the Microsoft Authentication Library. If a document uses "Azure AD" in one of those names, it is still correct.
The Entra Family, and Where Entra ID Fits
"Microsoft Entra" is the name of a family of identity and network-access products. Microsoft Entra ID is the foundational one. The others are good to recognise, because they appear in the portal and in client conversations, but this course concentrates on Entra ID.
| Product | What it is for (in Microsoft's words, simplified) | Relevance to this course |
|---|---|---|
| Microsoft Entra ID | Cloud identity and access management: authentication, policy enforcement and protection for users, devices, apps and resources | The subject of this course |
| Microsoft Entra Workload ID | Identity and access management for workload identities: applications, services and containers | Closely related, because an application that signs in without a person is a workload identity |
| Microsoft Entra External ID | Secure access for guests, partners and customers | Relevant when the client's users are guests rather than employees |
| Microsoft Entra ID Protection | Detects and reports identity-based risks | Can cause sign-in blocks or extra prompts |
| Microsoft Entra ID Governance | Automates access requests, assignments and reviews | Mostly background |
| Microsoft Entra Domain Services | Managed domain services (group policy, LDAP, Kerberos/NTLM) for legacy apps in the cloud | Not used by modern sign-in integrations |
| Microsoft Entra Verified ID, Private Access, Internet Access, Agent ID | Verifiable credentials; secure access to private and internet resources; identities for AI agents | Not covered |
Tenants
Everything in Entra ID lives inside a tenant: one organisation's own, separate instance of the service. Each tenant has:
- a tenant ID, a unique identifier (a GUID) that names it,
- an initial domain name of the form
something.onmicrosoft.com, created with the tenant, and - optionally one or more custom domains, the organisation's own names, such as
contoso.com.
If an organisation subscribes to Microsoft 365, Azure or Dynamics CRM Online, it is already using Entra ID: Microsoft's documentation says that every such tenant is automatically a Microsoft Entra tenant. This is why the same set of work accounts opens Outlook, Teams and, once someone has set it up, your system.
What lives inside a tenant
| Object | What it is | Why a support engineer cares |
|---|---|---|
| Users | The identities of people (employees, and guests invited in) | Who is trying to sign in, and are they enabled? |
| Groups | Collections of users used to grant access | Access is often given to a group, so removing someone from it can lock them out |
| Devices | Registered, joined or managed devices | Policies can require a compliant or joined device |
| Applications | The apps that use Entra for sign-in or that call Entra-protected APIs (app registrations and enterprise applications) | This is where "the integration" lives (Chapters 2 and 5) |
| Roles | Built-in Entra roles that delegate administration | Decide what you can see and what the client's admin must do (Chapter 5) |
| Policies | Rules such as Conditional Access that decide when and how sign-in is allowed | A healthy integration can still be blocked by a policy (Chapter 6) |
| Logs | Records of sign-ins and of changes made in the tenant | The evidence for every investigation (Chapter 7) |
Entra ID and the Other Systems It Touches
Entra ID and on-premises Active Directory
Many organisations have two directories: Windows Server Active Directory Domain Services (AD DS) in their own data centre, and Entra ID in the cloud. They are related but not the same thing. Microsoft describes Entra ID as an identity-as-a-service solution for apps across cloud and on-premises, where AD DS was built for managing on-premises infrastructure.
| Windows Server Active Directory | Microsoft Entra ID | |
|---|---|---|
| Where | On-premises servers | Microsoft's cloud |
| Typical app sign-in methods | LDAP, Windows-integrated authentication (Kerberos, NTLM) | OAuth 2.0, OpenID Connect, SAML and WS-Federation (WS-*) |
| SaaS apps | Not supported natively; needs a federation system such as AD FS | SaaS apps using OAuth 2.0, SAML or WS-* can use it directly |
| Devices | Domain join, Group Policy | Microsoft Entra join, Intune management, and checks through Conditional Access |
Organisations that have both usually run Microsoft Entra Connect, which syncs identities from AD DS to Entra ID so people use one account in both places. For your purposes, remember that modern sign-in integrations talk to Entra ID, not to AD DS. If a client says "it's our Active Directory", that is a prompt to find out whether they mean the on-premises directory, Entra ID, or the sync between them.
Entra ID, Microsoft 365 and Azure
Microsoft 365 and Azure use Entra ID for their own sign-in; they are customers of the same service your integration uses. The licence level of the tenant (Entra ID Free, P1 or P2, or Microsoft Entra Suite) decides which features exist. Microsoft 365 E3 includes Microsoft Entra ID P1 and Microsoft 365 E5 includes Microsoft Entra ID P2. The licence matters to this course in one practical way: it limits some features and how long some logs are kept, which Chapter 7 covers precisely.
Entra ID and your system
Your system is neither Microsoft 365 nor Active Directory. It is an application that relies on the client's Entra ID to sign people in. In identity vocabulary it is a "relying party", although you'll more often hear "the application" or "the integration". Chapter 2 explains how it is registered with the tenant and what the different integration types are.
Whose Side Is It?
An integration has two ends, and troubleshooting starts by working out which end is at fault and who owns it. In broad terms:
| Item | Normally lives in | Who can change it |
|---|---|---|
| The client's users, groups and sign-in policies | The client's tenant | The client's Entra administrators |
| The integration object for your system (registration or enterprise application) | The client's tenant (details depend on how it was set up; Chapter 2) | The client's administrators, or you if they gave you the right role |
| The secret, certificate or setting your system uses to talk to Entra | Both ends: it is created in the tenant and then stored in your system | Both sides must agree: a change in one place has to be copied to the other (Chapters 4 and 8) |
| Your system's own configuration and logs | Your platform | You |
| Microsoft Entra ID service itself | Microsoft | Microsoft (check the service health notices if everything is failing) |
Where You Manage Entra ID
You can see and manage Microsoft Entra in three web portals, per Microsoft's documentation:
- the Microsoft Entra admin center,
https://entra.microsoft.com, the dedicated portal; - the Azure portal,
https://portal.azure.com, where Microsoft Entra ID appears as a service; and - the Microsoft 365 admin center.
Administrators can also automate it through Microsoft Graph and the Microsoft Graph PowerShell module. As a support engineer you will mostly be reading the portal, often together with the client's administrator, so the first practical skill is finding which tenant you are looking at.
Finding the tenant ID
These are the steps Microsoft documents. You need to sign in as at least a Global Reader.
.onmicrosoft.com domain
and primary custom domain, the licence level if you know it, and the name of an administrator you can contact. A
five-minute habit that saves hours when the person who set the integration up has left the company. Chapter 5 shows
where else to look, and Chapter 7's logs ask for the tenant ID too. For the wider habit of keeping this kind of
record, see the Documentation & Runbooks course.
Terms to Keep Handy
| Term | Meaning in one line |
|---|---|
| Tenant | An organisation's own instance of Entra ID, with its own users, apps and policies |
| Tenant ID | The unique GUID that identifies a tenant |
| Identity provider (IdP) | The service that authenticates users and vouches for them to other systems |
| Authentication / authorization | Proving who you are / being allowed to do something |
| Single sign-on (SSO) | Signing in once and using the same identity across many applications |
| MFA | Multifactor authentication: more than one proof of identity |
| Conditional Access | Entra policies that decide when sign-in is allowed, blocked or needs extra proof |
| Microsoft Entra Connect | The tool that syncs identities from on-premises Active Directory to Entra ID |
| Microsoft Graph | The API through which Entra data and tasks can be accessed programmatically |
| Azure AD / AAD | The former name of Microsoft Entra ID |
Hands-On Exercises
All three use fictional organisations. Do not paste real tenant IDs, secrets or client names into notes you share.
Fabrikam Ltd's staff use "Sign in with Microsoft" on your product, "Acme Support Desk". Last week it began failing for everyone at Fabrikam, while Contoso, another client, is unaffected. Identify the identity provider, the tenant, the relying party, where authentication and authorization happen, and give three possible causes that fit the evidence.
๐ View solutionAn old internal runbook mentions ten things: "Azure AD tenant", "Azure Active Directory Premium P1", "AAD Connect", "Azure AD Conditional Access", "Azure AD B2C", "ADAL", "Azure AD PowerShell", "AD FS", "Azure AD Graph" and "DirSync". For each, say whether it was renamed, and if so give the current name; if not, say what it is now.
๐ View solutionWrite a "tenant card" template for support tickets. If you have read access to any Entra tenant (a work or training tenant), find its tenant ID in the portal, and note its initial domain. If not, fill the card in with the fictional details provided, and explain why each field helps in a sign-in investigation.
๐ View solutionChapter 1 Quick Reference
- Entra ID = cloud identity provider: it authenticates, applies policies, and vouches for users to other systems
- Authentication proves who you are; authorization decides what you may do
- Renamed from Azure AD (announced 11 July 2023); URLs, APIs, PowerShell cmdlets and MSAL are unchanged
- Not renamed: Active Directory / AD FS, Azure AD B2C, the Azure AD Graph and Azure AD PowerShell modules, ADAL/MSAL
- Everything lives in a tenant (tenant ID +
.onmicrosoft.comdomain + custom domains); one client is normally one tenant - Your system is an application that relies on the client's tenant to sign people in
- The decision is made in the client's tenant; a broken connection affects all that client's users at once
- Portals:
entra.microsoft.com,portal.azure.com, Microsoft 365 admin center - Tenant ID: Entra admin center > Entra ID > Overview > Properties (at least Global Reader), or
Get-AzTenant/az account tenant list - Start every ticket with a tenant card: tenant ID, domains, licence level, admin contact