Understanding Microsoft Entra ID
Understanding Microsoft Entra ID
Microsoft Entra ID is Microsoft’s cloud-based identity and access management service. It provides the identity foundation organizations can use to manage users, groups, applications, devices, and access to cloud resources.
For SC-300, understanding Microsoft Entra ID is essential because many of the technologies you’ll encounter throughout your preparation build on this identity platform.
In this lesson, you’ll learn how tenants and directories fit together, how identities are represented, and how Microsoft Entra ID supports access to organizational resources.
What You’ll Learn
By the end of this lesson, you should be able to:
- Explain the purpose of Microsoft Entra ID
- Understand the concept of a Microsoft Entra tenant
- Recognize the relationship between tenants and directories
- Identify common objects stored in Microsoft Entra ID
- Understand cloud and hybrid identity at a foundational level
- Explain how Microsoft Entra ID supports access to applications and resources
What Is Microsoft Entra ID?
Microsoft Entra ID is an identity and access management service.
It allows organizations to establish digital identities and use those identities to control access to resources.
An organization can use Microsoft Entra ID to manage access to services such as Microsoft 365, Azure, enterprise applications, and integrated third-party or custom applications.
Instead of treating every application as a completely separate identity environment, centralized identity management allows organizations to manage authentication and access more consistently.
Understanding Tenants
A tenant represents an organization’s dedicated instance of Microsoft Entra ID.
When an organization establishes a Microsoft cloud environment, a Microsoft Entra tenant can provide the identity boundary for its users, groups, applications, and other directory objects.
Think of the tenant as the organization’s identity environment.
For example, suppose Contoso creates a Microsoft Entra tenant.
Within that environment, Contoso might maintain:
- Employee accounts
- Administrative accounts
- Security groups
- Microsoft 365 groups
- Registered applications
- Enterprise applications
- Devices
- Service principals
- Other identity-related objects
The tenant provides a logical boundary within which these identities and objects can be managed.
Tenant vs. Directory
You’ll frequently encounter the terms tenant and directory when working with Microsoft Entra ID.
They are closely related and are sometimes used informally in similar contexts, but it helps to understand the concepts.
A tenant refers to the organization’s Microsoft Entra instance.
The directory contains identity-related objects associated with that tenant, such as users, groups, applications, and devices.
For introductory purposes, think of it this way:
Tenant = the organization’s identity environment
Directory = the collection of identity objects managed within that environment
As you progress into more advanced Microsoft Entra administration, you’ll encounter scenarios where understanding organizational and resource boundaries becomes increasingly important.
Common Directory Objects
Microsoft Entra ID contains different types of objects.
Users
User objects represent people who interact with organizational resources.
These may include employees, administrators, and external users.
Groups
Groups allow identities to be organized so that access and management can be applied more efficiently.
Instead of assigning the same access individually to hundreds of users, an organization may be able to assign access based on group membership.
Devices
Device identities allow organizations to represent and manage devices within the identity environment.
Device information can also become relevant when organizations make access decisions.
Applications
Applications that integrate with Microsoft Entra ID can be represented through application-related objects.
You’ll explore applications, service principals, permissions, and workload identities later in this course.
Cloud Identity
A cloud identity is created and primarily managed within the cloud identity environment.
For example, an organization operating entirely through cloud services might create users directly in Microsoft Entra ID.
Those users can then authenticate using their cloud identities to access permitted resources.
Cloud-only identity can reduce dependence on traditional on-premises identity infrastructure, although the appropriate architecture depends on the organization’s requirements.
Hybrid Identity
Many organizations have existing on-premises identity infrastructure while also using Microsoft cloud services.
A hybrid identity approach allows organizations to integrate identity across on-premises and cloud environments.
This can provide users with a more consistent identity while allowing organizations to maintain systems that exist in both environments.
For SC-300 preparation, the important foundational idea is:
Cloud identity is primarily managed in the cloud.
Hybrid identity connects or integrates identity across on-premises and cloud environments.
The configuration and management of hybrid identity involves additional technologies and decisions that go beyond this introductory lesson.
Microsoft Entra ID and Applications
Identity becomes useful when it enables controlled access to resources.
Microsoft Entra ID can provide authentication and access capabilities for many types of applications.
For example, an employee might use the same organizational identity to access:
- Outlook
- Microsoft Teams
- SharePoint
- An HR application
- A finance platform
- A custom internal application
Whether the employee can actually access each resource depends on the organization’s configuration and access policies.
This illustrates the difference we introduced in Lesson 1:
Authentication establishes who the user is.
Authorization determines what that user can access.
Single Sign-On
One important identity concept is Single Sign-On (SSO).
SSO can allow a user to authenticate and then access multiple authorized applications without repeatedly entering credentials for every application.
For users, this can create a more convenient experience.
For organizations, centralized identity and authentication can also provide greater consistency in how access is managed.
SSO does not mean that everyone can access everything. Users still require appropriate authorization for individual resources.
Practical Scenario
Suppose Contoso has 500 employees using Microsoft 365 and several cloud applications.
Without centralized identity management, employees might have separate credentials and account-management processes for numerous applications.
Instead, Contoso integrates supported applications with Microsoft Entra ID.
An employee signs in using an organizational identity. Microsoft Entra ID authenticates the user, while access configurations determine which integrated applications the employee is permitted to use.
If that employee leaves the company, administrators have a centralized identity environment from which the user’s organizational access can be managed.
This demonstrates why identity has become a critical security control in cloud environments.
Identity as a Security Boundary
Traditional security strategies often focused heavily on the network perimeter.
Modern organizations may have users working from offices, homes, mobile devices, and other locations while accessing cloud services.
As a result, identity becomes an important part of determining whether access should be allowed.
Instead of assuming that someone is trusted simply because they are connected to a particular network, modern access strategies can consider identity and other signals when making access decisions.
You’ll see this concept again when we explore Conditional Access.
SC-300 Exam Focus
When studying Microsoft Entra ID, make sure you can distinguish between related concepts rather than simply memorizing product names.
For example:
Tenant → the organization’s Microsoft Entra identity environment
Directory → identity-related objects within that environment
User → an identity representing a person
Group → a way to organize identities for management and access
Device → an identity representation of a device
Application → software that can integrate with the identity platform
SSO → allows authorized users to access multiple integrated applications with a more seamless authentication experience
Understanding these relationships will make later SC-300 topics much easier.
Quick Review
Before continuing, make sure you understand these points:
- Microsoft Entra ID is a cloud-based identity and access management service.
- A tenant represents an organization’s Microsoft Entra identity environment.
- Directories contain objects such as users, groups, devices, and applications.
- Cloud identities are primarily managed in the cloud.
- Hybrid identity connects identity across cloud and on-premises environments.
- Microsoft Entra ID can provide identity capabilities for Microsoft and integrated applications.
- Single Sign-On can reduce repeated authentication while authorization still controls resource access.
- Identity is an important component of modern security.
Continue to Lesson 3
Now that you understand the basic Microsoft Entra environment, the next step is learning how organizations manage the identities inside it.
Next: Users, Groups and Identity →