Browse all topics▾
Microsoft 365 Copilot
Power Platform
Microsoft Teams
SharePoint & OneDrive
Exchange & Outlook
Microsoft Entra (Identity)
- Adding a named location without breaking Conditional Access
- App consent policies and the admin consent workflow
- Assigning licenses with group-based licensing in Entra ID
- Cleaning up over-consented app permissions
- Cleaning up unused enterprise apps in Entra ID
- Compromised Microsoft 365 account response runbook
- + 52 more →
Microsoft Defender (Security)
Microsoft Purview (Compliance)
Microsoft Intune (Devices)
Viva & Apps
Developer & APIs
Migration & Tenants
Microsoft Entra (Identity)
Identity, authentication, Conditional Access, PIM, and governance. 58 guides in this topic.
Recently reviewed
- Adding a named location without breaking Conditional AccessHow to add or change a named location in Entra without breaking Conditional Access: MFA and risk side effects, the report-only sequence, the egress-IP trap.
- App consent policies and the admin consent workflowHow to stop consent phishing without blocking legitimate apps: Entra ID app consent policies, the admin consent workflow, and a review process that scales.
- Assigning licenses with group-based licensing in Entra IDHow-toHow to assign Microsoft 365 licences with group-based licensing in Entra ID: build the groups, set usage location, migrate direct assignments, fix errors.
- Cleaning up over-consented app permissionsHow to find apps holding more Graph permission than they use — delegated and application grants, who consented, what is called — and reduce them safely.
- Cleaning up unused enterprise apps in Entra IDHow to find unused service principals in Entra ID — sign-in activity, credentials, assignments — remove them without breaking year-end integrations.
- Compromised Microsoft 365 account response runbookReviewed 2026-09-06Compromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back.
- Conditional Access break-glass account designHow to design break-glass accounts that survive every Conditional Access disaster — credentials, monitoring, and recovery.
- Conditional Access for Microsoft 365 admin accountsConditional Access policies for admin accounts: phishing-resistant MFA, managed devices, short sessions, no legacy auth, plus exclusions and rollout order.
- Cross-Tenant Access Settings designHow to design Cross-Tenant Access Settings (CTAS) — the foundational trust controls for B2B and cross-tenant collaboration.
- Cross-tenant calendar sharingHow to share calendar free/busy between Microsoft 365 tenants — organisation relationships and modern alternatives.
- Cross-tenant synchronization in Entra IDReviewed 2026-09-04Cross-tenant synchronization auto-provisions B2B guests between Microsoft Entra ID tenants in a multi-tenant organisation.
- Entitlement Management access packagesReviewed 2026-09-04How access packages bundle Microsoft 365 access into requestable, governed units — the modern way to provision access at scale.
- Entra Connect vs Entra Cloud SyncReviewed 2026-08-31The two ways to sync on-prem Active Directory to Entra ID — what each does, the scenarios that still force the old tool, and which to use today.
- Entra External ID vs Azure AD B2CMicrosoft has two products for customer identity. Here's the difference and which to pick today.
- Entra ID Administrative UnitsAdministrative Units scope admin roles to subsets of the directory — for delegated administration without tenant-wide privileges.
- Entra ID app registrations and enterprise appsTwo sides of the same coin — app registrations define an app, enterprise apps grant it to your tenant. Here's how they relate.
- Entra ID authentication contextsAuthentication contexts let Conditional Access trigger step-up authentication for specific actions, not just specific apps.
- Entra ID B2B guest accessHow Entra ID B2B brings external users into your tenant as guests — invitations, controls, and lifecycle.
- Entra ID Conditional Access designReviewed 2026-09-06Designing a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
- Entra ID custom rolesHow to design and assign custom administrative roles in Microsoft Entra ID for fine-grained least-privilege access.
- Entra ID Governance explainedEntra ID Governance explained: access reviews, entitlement management, lifecycle workflows, separation of duties, P2 vs Suite licensing, and rollout order.
- Entra ID groups and group-based licensingGroup types in Entra ID, dynamic groups, and using groups to assign licences automatically.
- Entra ID Lifecycle WorkflowsLifecycle Workflows automate joiner-mover-leaver tasks based on user attribute triggers.
- Entra ID Multi-Tenant OrganizationsMTO is Microsoft's modern model for running multiple Microsoft 365 tenants as one organisation. Here's what it provides.
- Entra ID passwordless authenticationThe realistic options for going passwordless in Microsoft 365 — Authenticator, FIDO2, Windows Hello, and passkeys.
- Entra ID Privileged Identity ManagementReviewed 2026-09-03PIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
- Entra ID self-service password resetSSPR lets users reset their own passwords without calling the help desk. Here's the configuration and rollout.
- Entra ID vs OktaComparisonEntra ID vs Okta as the identity provider: Okta's neutrality and app-integration depth against Entra's Microsoft 365 bundling and Conditional Access.
- Entra ID vs Ping IdentityComparisonEntra ID vs Ping Identity (PingOne, PingFederate, ForgeRock): federation depth, hybrid deployment, and CIAM against Entra's bundled workforce identity.
- Entra ID Workload IdentitiesWorkload Identities is Entra ID's product for managing non-human identities — apps, services, scripts — and the risks they create.
- Entra Permissions ManagementMicrosoft's Cloud Infrastructure Entitlement Management (CIEM) product, covering Azure, AWS, and GCP permissions.
- How to block legacy authentication with Conditional AccessHow-toHow to block legacy authentication in Entra ID with Conditional Access: find who still uses it, build the block policy, run report-only, then enforce.
- How to bulk-assign Intune configuration profilesHow-toHow to bulk-assign Intune configuration profiles: assignment groups, filters, All devices vs All users, exclusions, and a Graph script for many profiles.
- How to create a break-glass account in Entra IDHow-toHow to create an emergency access (break-glass) account in Entra ID: cloud-only, permanent Global Admin, excluded from Conditional Access, FIDO2 keys, alerting.
- How to enable self-service password reset in Entra IDHow-toHow to enable self-service password reset in Entra ID: scope, methods, registration enforcement, password writeback for hybrid, and Windows lock-screen reset.
- How to require compliant devices with Conditional AccessHow-toHow to require a compliant or hybrid-joined device with Conditional Access: the Intune compliance policy first, the grant control, exclusions, report-only.
- How to require MFA for all users with Conditional AccessHow-toHow to require MFA for all users in Entra ID with Conditional Access: the exclusions that matter, report-only rollout, registration campaign, enforcement.
- How to reset MFA for a user in Entra IDHow-toHow to reset a user's MFA in Entra ID when they have a new phone or lost their authenticator: re-register, revoke sessions, and issue a Temporary Access Pass.
- How to set up PIM for the Global Administrator roleHow-toHow to set up Privileged Identity Management for Global Administrator in Entra ID: role settings, convert permanent admins to eligible, approvals, and alerts.
- Hybrid identity strategy for Microsoft 365Reviewed 2026-09-06How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
- Investigating a suspicious sign-in with Entra sign-in logsHow to work a suspicious sign-in in the Entra sign-in logs: which log, which columns matter, traveller vs attacker, and when to escalate to compromise.
- Microsoft 365 service principal best practicesHow to design, deploy, and operate service principals safely — credentials, permissions, and lifecycle.
- Microsoft Entra Connect HealthConnect Health monitors the hybrid-identity infrastructure — Entra Connect, AD FS, and AD DS.
- Microsoft Entra Global Secure AccessReviewed 2026-09-04Microsoft's SSE platform — Internet Access and Private Access for zero-trust network access. Here's what it does.
- Microsoft Entra ID Access ReviewsReviewed 2026-09-04How access reviews keep group memberships and role assignments healthy over time — periodic recertification at scale.
- Microsoft Entra ID RecommendationsThe Entra ID Recommendations dashboard surfaces tenant-specific improvement actions based on Microsoft's analysis.
- Microsoft Entra password protectionHow Entra ID's password protection blocks weak and breached passwords — for both cloud and on-prem AD accounts.
- Microsoft Entra Verified IDEntra Verified ID is Microsoft's decentralised identity / verifiable credential service. Here's the model and the use cases.
- Migrating Entra Connect Sync to Cloud Sync without an outageStaged runbook for moving a live directory from Entra Connect Sync to Cloud Sync: prerequisite checks, OU-by-OU pilot, cutover, and switching Connect off.
- PIM operational playbookHow to run Privileged Identity Management as a working process — onboarding, activation, approvals, and audit.
- Recovering from a broken Entra Connect SyncRunbook for when Entra Connect sync stops: scheduler, connectivity, and export errors, the deletion threshold protecting you, and rebuilding on a new server.
- Retiring on-prem Active Directory: what still requires itWhat still needs on-premises Active Directory in a Microsoft 365 organisation — Kerberos, file servers, RADIUS, printing — what replaces each, and the order.
- Rotating an app registration secret without downtimeHow to rotate an Entra app registration secret or certificate with zero outage: find every consumer, add the new credential alongside the old, switch, remove.
- SAML SSO with Entra IDHow to set up SAML single sign-on between a third-party app and Microsoft Entra ID.
- SCIM provisioning to Entra IDHow SCIM auto-provisions users from HR and identity systems into Entra ID and downstream SaaS apps.
- Testing Conditional Access policiesHow to test Conditional Access policies before enforcing them — report-only mode, what-if, and rollout patterns.
- The Entra Suite explainedReviewed 2026-09-03Entra Suite explained: Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection in one licence — what each does and when it pays.
- Token protection and token theft in Microsoft 365Token theft has become a leading attack pattern. Here's how it works and what Microsoft 365 offers to defend against it.
Frequently asked
- What is Microsoft Entra ID?
- Entra ID is Microsoft's cloud identity service and the identity provider behind every Microsoft 365 tenant. It handles authentication, MFA, Conditional Access, and identity governance for cloud and on-premises apps.
- Do I need Entra ID P1 or P2?
- P1 (included in Microsoft 365 E3, Business Premium, F3, and E5) unlocks Conditional Access, group-based licensing, and self-service password reset with write-back. P2 (included in E5, add-on otherwise) adds Identity Protection, PIM, and access reviews.
- Where should I start with Conditional Access?
- Enable the security defaults or the Microsoft-managed baseline policies first if you don't yet have designed CA. Then build the core set: block legacy auth, require MFA for all users, require compliant device for admins, and phishing-resistant MFA for privileged roles. Every policy in report-only for at least a week before enforcement.
- How do break-glass accounts work?
- Two cloud-only accounts excluded from every Conditional Access policy, with strong FIDO2 credentials stored physically offline. Sign-ins are alert-monitored so any use that wasn't a documented drill is treated as a P1 incident.
Looking for something else? Browse all guides.