- Entra ID is the identity provider for MSFT clouds
- “Azure”
- M365
- Dynamics 365
- Entra ID is not AD in the cloud.
- Has flat structure/ No OUs
- Has administrative units
- We can create additional tenants
- By default it will <>.onmicrosoft.com
- Can create/add custom domains
- When assigning license to groups only license applied to first level works not to members of nested groups
“Entra connect” to sync between on-prem AD and “Entra ID”
Active directory is always the source of truth.
Even if HR system is connected to Azure. Entra ID talks to on-prem to create object, which then replicates to Entra ID.
references:
Paths into this note
10 notes lead here
-
Add a custom domain in Entra ID
-
Dedicated and Trusted instance of Entra ID
-
Monitoring "Entra ID" - 7/30 days retention
-
For "Entra ID" only TXT or MX records
-
Use AAD (Preferred approach)
-
On user level, we could create and add custom attributes for users in "Entra ID"
-
AuthZ is always against "Entra ID".
-
Permissions applied for Entra ID
-
AAD creates access token and sends it back to IMDS, which gives it to resource