A beginner-friendly guide to running your identity directory in the cloud with Microsoft Entra ID (formerly Azure AD)
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access service. If on-prem Active Directory is the badge office in your building, Entra ID is the same badge concept hosted in Microsoft's cloud — no server to buy, no DC to run, and it is what signs you into Microsoft 365, Azure, and thousands of other apps.
| Scenario | Without a cloud directory | With Entra ID |
|---|---|---|
| Employee joins | Create + configure an account on every app | One user in Entra ID — sign-in works across all connected apps |
| Sign into Microsoft 365 | Manual or voucher-based accounts | SSO — one password, plus MFA |
| Access from anywhere | VPN into the office network | Sign in wherever you are — no VPN needed |
| Feature | Windows Server AD | Entra ID (cloud) | Auth0 / Okta |
|---|---|---|---|
| Where it runs | Your own server | Microsoft's cloud | Cloud (SaaS) |
| Focus | Managing network & domain computers | Cloud sign-in & app access | App authentication (developer focus) |
| Protocols | LDAP, Kerberos | OAuth 2, OpenID Connect, SAML | OAuth 2, OpenID Connect, SAML |
| Devices | Domain-joined PCs you own | Microsoft 365, Azure, Windows 11 (Entra join) | Apps, not devices |
| License | Windows Server + CAL | Free tier, then P1/P2 per user | Per-user / per-CI |
You don't have to choose between your on-prem Active Directory and the cloud — the standard approach is a hybrid setup: keep AD as the source of truth for users, and sync that identity to Entra ID.
If you have no Windows server, you can run Entra ID alone, with Entra ID as the only directory.
| Term | What it is |
|---|---|
| Tenant | Your isolated "namespace" in Entra ID — one per organisation |
| User | An account for a person (or service) that can sign in |
| Group | A collection of users used to assign licenses and access in bulk |
| Conditional Access | Policy rules deciding when/where access is allowed |
| SSO | Single sign-on — authenticate once, no repeated passwords |
| MFA | Multi-factor auth — password plus authenticator app, SMS, or phone |
| Enterprise App | A registered app (e.g. ServiceNow) that can accept Entra ID sign-ins |
Go to entra.microsoft.com (or the Microsoft 365 admin centre), sign in with any Microsoft account, and start a trial of Microsoft 365 or create a free Entra ID tenant.
In the portal: Users → All users → New user. Fill in name, username, and initial password. That's your first cloud identity.
Groups → New group, then add the user. Groups are how you later target MFA policies and app permission grants.
Under Security → MFA, enable enrollment for the group. Users will register an authenticator on next sign-in.
Protection → Conditional Access → New policy. Example: "Require MFA for all users" or "Block sign-ins from unexpected regions".
Install Microsoft Entra Connect on a server that can reach your Windows AD, configure Azure AD Sync, and your on-prem users start appearing as cloud users.
| Item | What it does |
|---|---|
entra.microsoft.com | The Entra admin portal |
| Users | Manage identities (create, edit, delete, guest) |
| Groups | Assign access & license to many people at once |
| Conditional Access | Policy rules for sign-in (MFA, devices, location) |
| Enterprise apps | Connect apps to Entra ID for SSO |
| Microsoft Entra Connect | Sync on-prem AD → Entra ID |
Entra ID is what happens when AD's "badge office" moves to the cloud and leaves the servers behind.
Try it free — one tenant, a few users, and you'll see the whole model.
Created by jcmatira