Microsoft Learn references
Microsoft Entra Field Guides: The Complete Collection
Every reference the book lists, as a link, under the book's own headings. If a page has moved, search Microsoft Learn for its title.
Part 1: Entra ID Fundamentals
Entra Platform, Identity Control Plane, and Admin Center
- What is Microsoft Entra?
- Microsoft Entra service description
- What is the Microsoft Entra admin center?
- Microsoft Entra security operations guide (identity as a control plane)
- Microsoft Entra fundamentals (functional areas)
- What's new (roadmap and change announcements)
Licensing, Plan Tiers, and License Usage
- Microsoft Entra licensing
- Sign up for Microsoft Entra ID P1 or P2 editions
- Microsoft Entra license usage insights
- What is Microsoft Entra ID Governance?
- Microsoft Entra plans and pricing
Tenant Configuration, Domains, and Company Branding
- Add your custom domain name to your tenant
- Manage custom domain names in your Microsoft Entra ID
- Configure your company branding
- Customize the sign-in experience with branding themes
Users, Guests, and External Collaboration
- Bulk create users in Microsoft Entra ID
- Restore or remove a recently deleted user
- Configure external collaboration settings for B2B
- What is Microsoft Entra B2B collaboration?
- Tutorial: Bulk invite B2B collaboration users
Groups and Dynamic Membership
- Manage rules for dynamic membership groups in Microsoft Entra ID
- Create simpler, more efficient rules for dynamic membership groups
Custom Security Attributes and Azure ABAC
- Manage access to custom security attributes in Microsoft Entra ID
- Add or deactivate custom security attribute definitions
- Overview of custom security attributes using the Microsoft Graph API
- What is Azure attribute-based access control (Azure ABAC)?
Microsoft Graph PowerShell and Bulk Operations
- Get started with the Microsoft Graph PowerShell SDK
- Authentication module cmdlets (Connect-MgGraph)
- Bulk operations service limitations
- Bulk operations in Microsoft Entra ID (Preview)
Group-Based Licensing
- What is group-based licensing in Microsoft Entra ID?
- Scenarios, limitations, and known issues for group-based licensing
- Group-based licensing PowerShell examples
- Assign or unassign licenses to a group in the Microsoft 365 admin center
Device Identity and Join Types
- What is a device identity?
- Microsoft Entra joined devices
- Microsoft Entra hybrid joined devices
- Troubleshoot devices by using the dsregcmd command
- Pending devices in Microsoft Entra ID
- Manage device identities using the Microsoft Entra admin center
Roles, RBAC, and Administrative Units
- Overview of role-based access control in Microsoft Entra ID
- Understand roles in Microsoft Entra ID
- Least privileged roles by task in Microsoft Entra ID
- Administrative units in Microsoft Entra ID
- Create or delete administrative units
- Restricted management administrative units
- Azure roles, Microsoft Entra roles, and classic subscription administrator roles
- Elevate access to manage all Azure subscriptions and management groups
Privileged Identity Management
- Start using Privileged Identity Management
- Configure Microsoft Entra role settings in PIM
- Plan a Privileged Identity Management deployment
Identity Secure Score
Part 2: Authentication and Conditional Access
Conditional Access foundations
- What is Conditional Access?
- Plan a Conditional Access deployment
- Build a Conditional Access policy
- Conditional Access: Conditions
- Conditional Access: Grant
- Conditional Access: Session
- Conditional Access policy templates
- Conditional Access: Filter for applications
- Conditional Access: Target resources
- Improved enforcement for All resources policies with resource exclusions
- Choose how baseline scopes are enforced (Baseline scopes settings)
- Conditional Access: Network assignment
- Target agent identities in Conditional Access policies
Licensing, roles, and security defaults
- Security defaults in Microsoft Entra ID
- Microsoft Entra built-in roles
- Features and licenses for Microsoft Entra multifactor authentication
Authentication methods policy and migration
- Manage authentication methods for Microsoft Entra ID
- How to migrate MFA and SSPR policy settings to the Authentication methods policy
MFA fundamentals and registration
- Combined security information registration overview
- Enable combined security information registration
- How number matching works in MFA push notifications for Authenticator
- Configure Microsoft Entra multifactor authentication settings
Phishing-resistant and modern methods
- How to enable passkeys (FIDO2) in Microsoft Entra ID
- Enable FIDO2 security key sign-in to Windows 10 and 11 devices
- Enable passwordless sign-in with Authenticator
- Cloud Kerberos trust deployment guide (Windows Hello for Business)
- Plan a Windows Hello for Business deployment
- Set up Microsoft Entra certificate-based authentication
- Conditional Access authentication strengths
- How Conditional Access authentication strengths work
Fallback and recovery methods
- Configure Temporary Access Pass to register passwordless authentication methods
- Authentication methods in Microsoft Entra ID - OATH tokens
- How to manage OATH tokens in Microsoft Entra ID (Preview)
- Email one-time passcode authentication for B2B guests
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Frequently asked questions about SMS and voice retirement
- Configure and enable users for SMS-based authentication using Microsoft Entra ID
Self-service password reset and password protection
- Plan a Microsoft Entra self-service password reset deployment
- Tutorial: Enable Microsoft Entra self-service password reset
- Prepopulate user authentication contact information for Microsoft Entra self-service password reset (SSPR)
- Tutorial: Enable Microsoft Entra self-service password reset writeback to an on-premises environment
- Enable Microsoft Entra SSPR on the Windows sign-in screen
- Eliminate bad passwords using Microsoft Entra Password Protection
- Plan and deploy on-premises Microsoft Entra Password Protection
- Enable on-premises Microsoft Entra Password Protection
Testing, monitoring, and protected actions
- Analyze Conditional Access policy impact (report-only mode)
- Conditional Access insights and reporting
- Troubleshoot Conditional Access policies with the What If tool
- Troubleshoot sign-in problems with Conditional Access
- Service dependencies in Microsoft Entra Conditional Access
- Use audit logs to troubleshoot Conditional Access policy changes
- View applied Conditional Access details in the Microsoft Entra activity logs
- Configure adaptive session lifetime policies
- What are protected actions in Microsoft Entra ID?
- Add, test, or remove protected actions in Microsoft Entra ID
Continuous access evaluation and ID Protection
- Continuous access evaluation
- Monitor and troubleshoot continuous access evaluation
- Risk-based access policies (Microsoft Entra ID Protection)
- Configure and enable risk policies
Operational hardening
- Manage emergency access accounts in Microsoft Entra ID
- Block legacy authentication with Conditional Access
- Require phishing-resistant multifactor authentication for administrators
Part 3: Identity Governance
Identity Governance Overview and Stack
- What is Microsoft Entra ID Governance?
- Introduction to Microsoft Entra ID Governance deployment guide
- Overview of Microsoft Entra ID Governance using Microsoft Graph
- Identity governance dashboard
Licensing and Prerequisites
- Microsoft Entra ID Governance licensing fundamentals
- Microsoft Entra licensing
- Microsoft Entra ID Governance licensing for guest users
- Microsoft Entra ID Governance service limits
Entitlement Management: Catalogs and Delegation
- Manage external access with Microsoft Entra entitlement management
- Create and manage a catalog of resources in entitlement management
- Delegation and roles in entitlement management
- Delegate access governance to catalog creators in entitlement management
- Delegate access governance to access package managers in entitlement management
Building Access Packages, Policies, and Approvals
- Create an access package in entitlement management
- Change request settings for an access package in entitlement management
- Change approval and requestor information settings for an access package
- Change lifecycle settings for an access package in entitlement management
- Tutorial: Manage access to resources in entitlement management
Advanced Entitlement Management: Auto-Assignment, SoD, Connected Orgs, External Users
- Configure an automatic assignment policy for an access package
- Configure separation of duties checks for an access package
- Manage connected organizations in entitlement management
- Govern access for external users in entitlement management
- Manage guest user lifecycle (mark guest as governed)
- Trigger Logic Apps with custom extensions in entitlement management
- Set up Microsoft Entra terms of use with Conditional Access
Access Reviews
- What are access reviews?
- Create an access review of groups and applications in Microsoft Entra ID
- Review recommendations for Access reviews
- Review access to groups and applications in access reviews
- Create an access review of Azure resource and Microsoft Entra roles in PIM
- Create an access review of an access package in entitlement management
- Plan a Microsoft Entra access reviews deployment
Privileged Identity Management
- Start using Privileged Identity Management
- Plan a Privileged Identity Management deployment
- Configure Microsoft Entra role settings in Privileged Identity Management
- Configure Azure resource role settings in Privileged Identity Management
- Privileged Identity Management (PIM) for Groups
- Assign eligibility for a group in Privileged Identity Management
- Approve or deny requests for Microsoft Entra roles in Privileged Identity Management
PIM Alerts, Notifications, and Audit History
- Configure security alerts for Microsoft Entra roles in Privileged Identity Management
- Email notifications in PIM
- View audit history for Microsoft Entra roles in Privileged Identity Management
- View activity and audit history for Azure resource roles in Privileged Identity Management
- Microsoft Entra security operations for Privileged Identity Management
Break-Glass Emergency Access Accounts
- Manage emergency access accounts in Microsoft Entra ID
- Privileged Access (PA-5: Set up emergency access)
- Conditional Access policy templates: user exclusions
Lifecycle Workflows
- What are lifecycle workflows?
- Understanding lifecycle workflows
- Create a lifecycle workflow
- Lifecycle workflows execution conditions and scheduling
- Lifecycle Workflows custom task extension
- Trigger Logic Apps based on custom task extensions
- Plan a Lifecycle Workflow deployment
- Lifecycle Workflows built-in tasks
- Restore or remove a recently deleted user
- Configure the employeeLeaveDateTime property for a user
Monitoring, Audit Log Routing, and Identity Secure Score
- Configure Microsoft Entra diagnostic settings for activity logs
- Integrate Microsoft Entra logs with Azure Monitor logs
- Archive logs and reporting on entitlement management in Azure Monitor
- What is Identity Secure Score?
- What are Microsoft Entra recommendations?
Certification (SC-300)
- Study guide for Exam SC-300: Microsoft Identity and Access Administrator
- SC-300: Plan and implement an identity governance strategy (Training)
Part 4: Workload Identities and Application Management
Workload Identity Concepts and the Entra Product Family
- What are workload identities?
- Application and service principal objects in Microsoft Entra ID
- How and why applications are added to Microsoft Entra ID
- What is Microsoft Entra?
- Authorize applications, resources, and workloads with Microsoft Entra ID
- What is Microsoft Entra Agent ID?
- Microsoft Entra service limits and restrictions
Licensing and Prerequisites
- Frequently asked questions about Microsoft Entra Workload ID
- Microsoft Entra licensing
- What is Microsoft Entra ID Protection?
- Microsoft Entra ID Governance licensing fundamentals
Choosing and Securing a Service Account
- Securing cloud-based service accounts
- Provide application identity credentials when there's no user
- Manage application identities securely and automatically (IM-3)
Managed Identities
- What is managed identities for Azure resources?
- Managed identity best practice recommendations
- How managed identities for Azure resources work with Azure virtual machines
- Assign an application role to a managed identity using PowerShell
- Use Microsoft Entra Workload ID with Azure Kubernetes Service (AKS)
App Registrations, Service Principals, and Microsoft Graph
- Register an application with the Microsoft identity platform
- Manage Microsoft Entra applications and service principals by using Microsoft Graph
- Deactivate an app registration
App Authentication: Secrets, Certificates, and Federated Credentials
- Add and manage application credentials in Microsoft Entra ID
- Microsoft identity platform application authentication certificate credentials
- Workload identity federation concepts
- Configure an app to trust an external identity provider
- Configure an application to trust a managed identity
- Set up a Flexible Federated identity credential (preview)
- Migrate applications away from secret-based authentication
API Permissions and the Consent Framework
- Overview of user and admin consent
- Configure how users consent to applications
- Configure the admin consent workflow
- Review permissions granted to enterprise applications
App Roles and Authorization
- Add app roles to your application and receive them in the token
- Manage users and groups assignment to an application
Enterprise Applications, SSO, and Provisioning
- Enable SAML single sign-on for an enterprise application
- How Application Provisioning works in Microsoft Entra ID
- Tutorial: Develop and plan provisioning for a SCIM endpoint in Microsoft Entra ID
- Microsoft Entra on-premises application provisioning to SCIM-enabled apps
Application Proxy
- Microsoft Entra application proxy
- Add an on-premises application for remote access through application proxy in Microsoft Entra ID
- Security considerations for accessing apps remotely with Microsoft Entra application proxy
- Microsoft Entra private network connectors
Conditional Access App Control and Defender for Cloud Apps
- Conditional Access app control in Microsoft Defender for Cloud Apps
- Create Microsoft Defender for Cloud Apps session policies
- Create Microsoft Defender for Cloud Apps access policies
Securing Workload Identities: Conditional Access, ID Protection, and Governance
- Conditional Access for workload identities
- Continuous access evaluation for workload identities
- Securing workload identities
- Create an access review of Azure resource and Microsoft Entra roles in PIM
- Microsoft Entra security operations guide for Applications
- What are Microsoft Entra recommendations?
- Microsoft Entra recommendation: Remove unused credentials from apps (preview)
Part 5: Hybrid Identity and Global Secure Access
Hybrid identity overview and tooling
- Tools used for synchronization
- Choose the right authentication method for your Microsoft Entra hybrid identity solution
- Prerequisites for integrating with Active Directory (hybrid prerequisites)
Cloud Sync
- What is Microsoft Entra Cloud Sync?
- Cloud sync deep dive - how it works
- What is the Microsoft Entra provisioning agent?
- Prerequisites for Microsoft Entra Cloud Sync
- Microsoft Entra Cloud Sync FAQ
- Migrate from Microsoft Entra Connect to Cloud Sync: Decision Guide
- Microsoft Entra Cloud Sync supported topologies and scenarios
Connect Sync architecture, prerequisites, and operations
- Prerequisites for Microsoft Entra Connect
- Microsoft Entra Connect: Design concepts (source anchor)
- Microsoft Entra Connect Sync: Configure filtering
- Microsoft Entra Connect Sync: Scheduler
- Microsoft Entra Connect: Staging server and disaster recovery
- Custom installation of Microsoft Entra Connect
- Microsoft Entra Connect Sync service features
Authentication: PHS, PTA, and federation
- Implement password hash synchronization with Microsoft Entra Connect Sync
- Microsoft Entra pass-through authentication: Technical deep dive
- Microsoft Entra pass-through authentication security deep dive
- Migrate from federation to cloud authentication
Seamless SSO and staged rollout
- Microsoft Entra seamless single sign-on
- Microsoft Entra seamless single sign-on: Technical deep dive
- Quickstart: Microsoft Entra seamless single sign-on
- Microsoft Entra seamless single sign-on: Frequently asked questions
- Migrate to cloud authentication using Staged Rollout
- Deprecation of Basic authentication in Exchange Online
- Block legacy authentication with Conditional Access
- How to customize and filter identity activity logs
- What are Microsoft Entra workbooks?
- Sign-ins using legacy authentication workbook
Monitoring with Connect Health
- Install the Microsoft Entra Connect Health agents
- Monitor Microsoft Entra Connect Sync with Microsoft Entra Connect Health
- Microsoft Entra Connect Health agents for AD FS
- Diagnose and remediate duplicated attribute sync errors
Cloud Kerberos Trust and Windows Hello for Business
- Cloud Kerberos trust deployment guide
- Plan a Windows Hello for Business deployment
- Microsoft Entra Kerberos FAQ
Troubleshooting and data hygiene
- IdFix DirSync Error Remediation Tool
- One or more objects don't sync when using the directory sync tool
- Identity synchronization and duplicate attribute resiliency
Global Secure Access: architecture and clients
- What is Global Secure Access?
- Global Secure Access client overview
- Global Secure Access traffic forwarding profiles
- Understand remote network connectivity
Private Access
- Learn about Microsoft Entra Private Access
- How to configure Quick Access for Global Secure Access
- Use Kerberos for single sign-on (SSO) with Microsoft Entra Private Access
Internet Access, Microsoft traffic, and tenant restrictions
- Tutorial: Enable TLS inspection
- Configure Transport Layer Security inspection settings
- Tutorial: Configure web content filtering with the baseline profile
- Turn on universal tenant restrictions
- Source IP restoration