entra1-1 Exercise 3: The Tenant Card ===================================== PART A: THE TEMPLATE -------------------- Paste this at the top of any Entra-related ticket: TENANT CARD Client name: ______________________ Tenant ID: ______________________ (a GUID) Initial domain: ______________________.onmicrosoft.com Primary / custom domain:______________________ Licence level (if known): Free / P1 / P2 / Suite / unknown Client Entra admin: name, role, contact method Integration name: ______________________ (what it's called in their tenant) Integration type: SAML SSO / OIDC / SCIM / other / unknown Our contact for it: ______________________ Date this card was checked: ____________________ PART B: IF YOU HAVE READ ACCESS TO A TENANT ------------------------------------------- Microsoft's documented steps (you need at least the Global Reader role): 1. Sign in at https://entra.microsoft.com 2. Entra ID > Overview > Properties 3. Scroll to the "Tenant ID" box and copy the value. Or, in the Azure portal: Microsoft Entra ID > Properties > Tenant ID. Command-line alternatives from the same Microsoft page: Connect-AzAccount Get-AzTenant az login az account tenant list Note the initial domain (it ends in .onmicrosoft.com) and any custom domains shown in the portal; menu names move, so if you can't find them, search the portal's search box for "Custom domain names". If you have no access to any tenant, use the fictional card below. PART C: A FICTIONAL EXAMPLE --------------------------- TENANT CARD Client name: Fabrikam Ltd Tenant ID: 00000000-0000-0000-0000-000000000000 (example only) Initial domain: fabrikam.onmicrosoft.com Primary / custom domain:fabrikam.example Licence level: unknown (ask the admin) Client Entra admin: A. Admin, IT manager, email Integration name: Acme Support Desk (SSO) Integration type: unknown until checked in Chapter 5 Our contact for it: Support lead Date checked: (today) WHY EACH FIELD HELPS -------------------- Tenant ID Names exactly which tenant you are looking at; avoids confusing two similarly named organisations or a client with several tenants. Domains Lets you match a user's email address to the tenant, and spot a typo or a changed domain. Licence Decides which features exist and how long some logs are kept, so you know what evidence you can still get (Chapter 7). Client admin The person who can see and change the tenant. You'll need them in nearly every investigation (Chapter 5). Integration The name and type tell you which chapters apply (Chapter 2) and name / type let you find it in the portal quickly (Chapter 5). Date checked Tenant details change; a dated card tells the next person how stale it might be. SECURITY NOTE ------------- The tenant ID and domain names are identifiers, not secrets, but treat them with care in anything you share. Never put a client secret, token or certificate private key on a ticket, a card or in a chat. If you must refer to one, record only where it is stored and when it expires. WHY THIS WORKS AS AN ANSWER --------------------------- It turns the chapter's map (tenant, domain, integration, owner) into a habit you use on every ticket, and each field carries a reason, so the card doesn't become paperwork for its own sake.