☁️ Cloud AD — Microsoft Entra ID

A beginner-friendly guide to running your identity directory in the cloud with Microsoft Entra ID (formerly Azure AD)

1. What is Microsoft Entra ID?

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access service. If on-prem Active Directory is the badge office in your building, Entra ID is the same badge concept hosted in Microsoft's cloud — no server to buy, no DC to run, and it is what signs you into Microsoft 365, Azure, and thousands of other apps.

🏢 Analogy — Bank Account vs a Credit Card Network
On-prem AD is like running your own bank: you buy the building, the vault, the staff. Entra ID is like joining a global payment network instead — the clearing house, security, and uptime are all managed for you, and you only worry about your own accounts. Same idea (identity + rules), but you don't operate the infrastructure.

🎯 Real-World Examples

ScenarioWithout a cloud directoryWith Entra ID
Employee joinsCreate + configure an account on every appOne user in Entra ID — sign-in works across all connected apps
Sign into Microsoft 365Manual or voucher-based accountsSSO — one password, plus MFA
Access from anywhereVPN into the office networkSign in wherever you are — no VPN needed

2. Why choose a cloud directory? (The Benefits)

☁️ Zero infrastructure
No servers, no licences to manage — Microsoft runs everything.
🔑 SSO everywhere
One sign-in for thousands of cloud apps: Microsoft 365, Shopify, Salesforce, and more.
📱 MFA built in
Strong multi-factor authentication for every account, no extra setup per user.
🚦 Conditional Access
Rules like "only allow sign-ins from trusted devices or regions".
🌍 Works from anywhere
Users sign in wherever they are — no VPN back to the office.
🔁 Hybrid friendly
Syncs with your on-prem AD, so you get the best of both worlds.

3. On-prem AD vs Entra ID vs Other Cloud Directories

FeatureWindows Server ADEntra ID (cloud)Auth0 / Okta
Where it runsYour own serverMicrosoft's cloudCloud (SaaS)
FocusManaging network & domain computersCloud sign-in & app accessApp authentication (developer focus)
ProtocolsLDAP, KerberosOAuth 2, OpenID Connect, SAMLOAuth 2, OpenID Connect, SAML
DevicesDomain-joined PCs you ownMicrosoft 365, Azure, Windows 11 (Entra join)Apps, not devices
LicenseWindows Server + CALFree tier, then P1/P2 per userPer-user / per-CI
🏢 Analogy — Property Manager vs. Tenant
If AD on-prem is owning and managing an office building, Entra ID is renting premium space in Microsoft's complex — the plumbing, security guards, and maintenance are the landlord's job. Okta/Auth0 are property managers with flexible floorplans for apps you build. Choose by whether you own devices (AD), use MS cloud apps (Entra), or build apps and want login-for-anyone (Okta/Auth0).

4. Entra ID + Your Existing AD (Hybrid)

You don't have to choose between your on-prem Active Directory and the cloud — the standard approach is a hybrid setup: keep AD as the source of truth for users, and sync that identity to Entra ID.

🔌 How the sync works

  1. Entra Connect Sync (cloud tool) runs inside your network next to your AD.
  2. It continuously copies users, groups, and passwords (hashes) from AD up to Entra ID.
  3. Employees get one identity: same username works on-prem and in the cloud.
  4. You manage the authoritative copy in AD; the cloud is the shadow copy for the Microsoft ecosystem.

If you have no Windows server, you can run Entra ID alone, with Entra ID as the only directory.

5. Core Concepts

TermWhat it is
TenantYour isolated "namespace" in Entra ID — one per organisation
UserAn account for a person (or service) that can sign in
GroupA collection of users used to assign licenses and access in bulk
Conditional AccessPolicy rules deciding when/where access is allowed
SSOSingle sign-on — authenticate once, no repeated passwords
MFAMulti-factor auth — password plus authenticator app, SMS, or phone
Enterprise AppA registered app (e.g. ServiceNow) that can accept Entra ID sign-ins

6. Step-by-Step: Try Entra ID

Create a free tenant

Go to entra.microsoft.com (or the Microsoft 365 admin centre), sign in with any Microsoft account, and start a trial of Microsoft 365 or create a free Entra ID tenant.

Add a user

In the portal: Users → All users → New user. Fill in name, username, and initial password. That's your first cloud identity.

Create a group and assign

Groups → New group, then add the user. Groups are how you later target MFA policies and app permission grants.

Turn on MFA

Under Security → MFA, enable enrollment for the group. Users will register an authenticator on next sign-in.

Add a Conditional Access policy

Protection → Conditional Access → New policy. Example: "Require MFA for all users" or "Block sign-ins from unexpected regions".

Sync your on-prem AD (optional)

Install Microsoft Entra Connect on a server that can reach your Windows AD, configure Azure AD Sync, and your on-prem users start appearing as cloud users.

7. Quick Reference

ItemWhat it does
entra.microsoft.comThe Entra admin portal
UsersManage identities (create, edit, delete, guest)
GroupsAssign access & license to many people at once
Conditional AccessPolicy rules for sign-in (MFA, devices, location)
Enterprise appsConnect apps to Entra ID for SSO
Microsoft Entra ConnectSync on-prem AD → Entra ID

8. Best Practices

🔐 MFA for everyone
Turn on MFA by default — most of the cost, huge security win.
🚦 Conditional Access over deny-all
Write rules that adapt to risk (location, device) instead of blanket blocks.
🔭 Least-privilege roles
Nobody is "Global Admin for life" — give just enough permission per role.
🔁 Sync, don't duplicate
Use Microsoft Entra Connect so on-prem AD stays the one source of truth.
📊 Audit constantly
Watch sign-in logs & identity risk reports in the cloud.
🧱 Guard the tenant
Your Entra tenant is the crown jewels — protect the tenant owner account like a root credential.

Entra ID is what happens when AD's "badge office" moves to the cloud and leaves the servers behind.
Try it free — one tenant, a few users, and you'll see the whole model.

Created by jcmatira