Skip to content
CogniSkill

SC-300 Fundamentals

Users, Groups and Identity

Users, Groups and Identity

Microsoft Entra ID allows organizations to manage different types of identities and organize access to resources efficiently.

Two of the most important objects you’ll work with are users and groups. Understanding how these objects are used is fundamental to identity administration and provides the foundation for more advanced topics such as role assignment, application access, Conditional Access, and identity governance.

What You’ll Learn

By the end of this lesson, you should be able to:

  • Understand the purpose of user identities in Microsoft Entra ID
  • Recognize the difference between internal and external identities
  • Explain why organizations use groups
  • Understand assigned and dynamic group membership at a foundational level
  • Recognize the difference between authentication and access assignment
  • Understand why identity lifecycle management matters
  • Apply the principle of least privilege to basic identity scenarios

User Identities

A user identity represents a person who needs to interact with organizational resources.

Examples include:

  • Employees
  • Administrators
  • Contractors
  • Consultants
  • Partners
  • Guests

A user account contains information that allows Microsoft Entra ID and connected services to identify and manage that person.

Depending on the environment, administrators may create users directly in Microsoft Entra ID or manage identities through processes connected to other identity systems.

Internal and External Identities

Not everyone who needs access to organizational resources is an employee.

Organizations routinely collaborate with suppliers, contractors, consultants, customers, and business partners.

Instead of treating every external person exactly like an internal employee, Microsoft Entra provides capabilities for managing external identities.

The important security principle is that collaboration should not require organizations to provide more access than necessary.

For example, an external consultant working on a six-month project might need access to a specific collaboration resource but should not automatically receive access to unrelated internal systems.

Why Groups Matter

Imagine an organization with 5,000 employees.

Assigning permissions individually to every employee can quickly become difficult to manage.

Groups help administrators organize identities and can simplify access management.

For example, an organization might have groups representing:

  • Finance employees
  • Help desk staff
  • Security analysts
  • Project members
  • Application users
  • Regional employees

Instead of assigning access separately to every individual, access can often be managed using an appropriate group.

This can improve consistency and reduce repetitive administrative work.

Assigned Membership

With assigned membership, administrators explicitly add or remove members from a group.

For example, an administrator could create a group called:

Finance Application Users

The administrator then adds the appropriate employees to that group.

This approach is straightforward, but administrators need to maintain membership as users join, leave, or change roles.

Dynamic Membership

Microsoft Entra ID can also support dynamic membership for appropriate group types and configurations.

Rather than manually maintaining every member, administrators define membership rules based on supported user or device attributes.

For example, an organization could use an attribute-based rule so that users meeting particular criteria are automatically evaluated for membership.

The key distinction is:

Assigned membership → membership is explicitly managed.

Dynamic membership → membership is evaluated using configured rules.

Dynamic groups can reduce repetitive administration, but the rules must be designed carefully because group membership may affect access.

Groups and Access

Groups become particularly useful when connected to access decisions.

Suppose 75 employees need access to the same business application.

One approach would be to assign the application individually to all 75 users.

A more manageable approach may be to use an appropriate group and manage membership in that group.

When someone joins the relevant team, their membership can be added or otherwise determined according to the organization’s process.

When they leave that role, the membership—and therefore associated access—can be reviewed or removed.

This illustrates an important IAM principle:

Access should follow business need.

Identity Lifecycle

An identity changes over time.

A useful way to think about this is the joiner, mover, leaver lifecycle.

Joiner

A person joins the organization.

They need an identity and appropriate initial access.

Mover

The person changes jobs, departments, responsibilities, or projects.

Their access may need to change as well.

Leaver

The person leaves the organization.

Access should be removed according to organizational requirements.

The mover stage is especially important. If old permissions are continually retained as employees change roles, users can gradually accumulate access they no longer require.

This is sometimes referred to as privilege or permission accumulation.

Good identity governance aims to reduce unnecessary access over time.

Administrative Identities

Administrative accounts require particular attention because they can perform sensitive operations.

An ordinary user may need access to email, documents, and business applications.

An administrator may be able to:

  • Modify identities
  • Change configurations
  • Manage access
  • Assign certain privileges
  • Perform security-sensitive operations

For that reason, administrative access should be carefully controlled.

The principle of least privilege remains important:

Provide the permissions required to perform the task—not unnecessary additional privileges.

Later in the course, you’ll see how governance and privileged-access concepts can help organizations manage elevated access more effectively.

Practical Scenario

Contoso hires Priya as a financial analyst.

Her identity is created and she receives the access required for her finance role.

She becomes a member of the appropriate groups and gains access to the finance applications required for her job.

One year later, Priya moves to a business intelligence team.

If Contoso simply gives her the new access without reviewing her old access, she may retain finance permissions that are no longer required.

A better process evaluates:

What access does Priya need in her new role?

and

What access should be removed from her previous role?

This is why identity administration involves more than simply creating accounts.

External User Scenario

Suppose Contoso hires an external consultant for a three-month project.

The consultant needs access to a specific collaboration environment.

The goal should not be:

“Create an account and give the consultant normal employee access.”

Instead, administrators should consider:

  • What resource does the consultant need?
  • How much access is required?
  • How long should the access remain?
  • How will the access be reviewed?
  • What happens when the engagement ends?

This is the type of security reasoning that becomes increasingly important as you move from basic identity administration into identity governance.

SC-300 Exam Focus

When evaluating an identity scenario, pay attention to the requirement.

If many users require the same access, consider whether group-based management is appropriate.

If membership should change according to supported attributes, think about dynamic membership.

If someone changes roles, think about the identity lifecycle and whether old access should be removed.

If an external user needs access, consider how the organization can enable collaboration without unnecessarily expanding access.

And whenever privileges are involved, remember:

Least privilege is usually preferable to excessive permanent access.

Quick Review

Before continuing, make sure you understand:

  • User identities represent people who interact with organizational resources.
  • External identities allow organizations to collaborate beyond their internal workforce.
  • Groups can simplify identity and access administration.
  • Assigned membership is explicitly maintained.
  • Dynamic membership uses configured rules to evaluate membership.
  • Access requirements can change when a person’s role changes.
  • Joiner, mover, and leaver processes are important parts of identity lifecycle management.
  • Administrative privileges require stronger control.
  • Least privilege means granting only the access necessary to perform required tasks.

Continue to Lesson 4

Now that you understand how identities can be organized and managed, the next step is learning how those identities prove who they are.

In Lesson 4, we’ll explore passwords, multifactor authentication, passwordless methods, self-service password reset, and stronger authentication.

Next: Authentication Fundamentals →