Microsoft Learn references

Microsoft Entra Field Guides: The Complete Collection

Every reference the book lists, as a link, under the book's own headings. If a page has moved, search Microsoft Learn for its title.

Part 1: Entra ID Fundamentals

Entra Platform, Identity Control Plane, and Admin Center

Licensing, Plan Tiers, and License Usage

Tenant Configuration, Domains, and Company Branding

Users, Guests, and External Collaboration

Groups and Dynamic Membership

Custom Security Attributes and Azure ABAC

Microsoft Graph PowerShell and Bulk Operations

Group-Based Licensing

Device Identity and Join Types

Roles, RBAC, and Administrative Units

Privileged Identity Management

Identity Secure Score

Part 2: Authentication and Conditional Access

Conditional Access foundations

Licensing, roles, and security defaults

Authentication methods policy and migration

MFA fundamentals and registration

Phishing-resistant and modern methods

Fallback and recovery methods

Self-service password reset and password protection

Testing, monitoring, and protected actions

Continuous access evaluation and ID Protection

Operational hardening

Part 3: Identity Governance

Identity Governance Overview and Stack

Licensing and Prerequisites

Entitlement Management: Catalogs and Delegation

Building Access Packages, Policies, and Approvals

Advanced Entitlement Management: Auto-Assignment, SoD, Connected Orgs, External Users

Access Reviews

Privileged Identity Management

PIM Alerts, Notifications, and Audit History

Break-Glass Emergency Access Accounts

Lifecycle Workflows

Monitoring, Audit Log Routing, and Identity Secure Score

Certification (SC-300)

Part 4: Workload Identities and Application Management

Workload Identity Concepts and the Entra Product Family

Licensing and Prerequisites

Choosing and Securing a Service Account

Managed Identities

App Registrations, Service Principals, and Microsoft Graph

App Authentication: Secrets, Certificates, and Federated Credentials

API Permissions and the Consent Framework

App Roles and Authorization

Enterprise Applications, SSO, and Provisioning

Application Proxy

Conditional Access App Control and Defender for Cloud Apps

Securing Workload Identities: Conditional Access, ID Protection, and Governance

Part 5: Hybrid Identity and Global Secure Access

Hybrid identity overview and tooling

Cloud Sync

Connect Sync architecture, prerequisites, and operations

Authentication: PHS, PTA, and federation

Seamless SSO and staged rollout

Monitoring with Connect Health

Cloud Kerberos Trust and Windows Hello for Business

Troubleshooting and data hygiene

Global Secure Access: architecture and clients

Private Access

Internet Access, Microsoft traffic, and tenant restrictions

Production readiness: Conditional Access and compliant network