Protect M365 From On Premises Attacks
The guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Architecture.
The guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.
The guidance now links to a different Microsoft Entra Cloud Sync article for provisioning groups to Active Directory Domain Services.
The documentation now explains that agents should use an agent identity blueprint and the `#Microsoft.Graph.AgentIdentity` object, rather than standard app-registration APIs. It also lists supported creation channels, roles, permissions, and .NET usage.
The agent identity architecture planning page now links to the correct interactive agent authentication article instead of the previous broken path.
Learn about Microsoft Entra tenant architecture for collaborating production tenants so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for hybrid identity and isolation so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for nonproduction environments so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for primary production tenants so that you can identify your needs and compare architectural options.
Learn how to compose your Microsoft Entra tenant estate from common tenant architecture patterns so that you can meet your requirements with as few tenants as possible.
Learn about Microsoft Entra tenant architecture for business partner access so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for critical business systems so that you can identify your needs and compare architectural options.
Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.
1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).
Learn about edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations for Microsoft Entra External ID.
Learn how to prepare for and execute tenant-scoped recovery under the shared responsibility model.
At this point, you completed initiate and plan stages of your Secure Access Services Edge (SASE) deployment project. You understand what you need to implement for whom. You defined which users to enable in each wave. You have a schedule for each wave's deployment. You have met [licensing requirements](../global-secure-access/overview-what-is-global-secure-access.md#licensing-overview). You're ready to enable Microsoft Entra Internet Access.
1. Create end user communications to set expectations and provide an escalation path.
1. Create end user communications to set expectations and provide an escalation path.
- A test user who isn't an administrator to verify that policies work as expected before you deploy real users. To create a user, follow the steps in [How to create, invite, and delete users](../fundamentals/how-to-create-delete-users.md).
Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.
Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.
Azure Active Directory B2C deployment guide for planning, implementation, and monitoring
Learn methods to build resilience in customer identity and access management (CIAM) using Azure AD B2C.
A Microsoft Entra documentation page was updated: Configure Advanced F5 Kerberos Delegation for Multi-Tier SaaS Architectures.
Learn to convert local guests into Microsoft Entra B2B guest accounts by identifying apps and local guest accounts, migration, and more.
Learn, deploy, and test Microsoft Entra ID Protection so that you can detect, investigate, and remediate identity-based risks.
Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.
Learn about the official collection of Microsoft Entra ID icons that you can use in architectural diagrams, training materials, or documentation.
Learn to securely deploy and operate Microsoft Entra External ID architectures with Microsoft Entra.
Learn about improving risk analysis to identify risky users, discern risk event types, and examine risk levels for access and identity decisions.
Learn how identity administrators use real-time risk detection features in Microsoft Entra ID Protection to grant user access to protected resources.
Learn how Security Operations Center (SOC) admins use Microsoft Entra ID Protection to bring identity risk-related telemetry into security investigations.
Learn how IT administrators use Microsoft Entra ID Protection to identify and remediate identity risks for users that access enterprise-managed resources.
Configure Microsoft Entra Suite products for upgrading existing VPN solution to a scalable cloud-based solution and move towards Secure Access Service Edge (SASE).
Configure Microsoft Entra Suite products for strict default internet access policies to control internet access according to business requirements.
Configure Microsoft Entra Suite products for hiring new remote employees and providing them with secure and seamless access to apps and resources.
The Microsoft Entra Suite deployment scenarios article series provides guidance regarding the Microsoft Entra Suite.
Locate and engage partners for guidance on Microsoft Entra deployment.
This article is for use by the delivery expert that plans on delivering the Microsoft Entra Suite Workshop to customers. It aims to provide delivery experts with a comprehensive overview of the tasks that is required to successfully deliver the Microsoft Entra Suite Workshop to customers. It's structured chronologically following the standard and typical flow of a workshop delivery. It outlines how to use the Microsoft Entra Suite Workshop to deploy all the components of the suite. It gives organizations and IT admins a detailed plan to design and deploy Microsoft Entra ID Governance, Microsoft Entra Private Access, Microsoft Entra Internet Access, and Microsoft Entra Verified ID.
Learn to harness AI-powered insights and automation and demonstrate the value of Security Copilot in Entra in your environment.
Plan your single sign‑on deployment in Microsoft Entra ID. Streamline role assignments, certificate management, and licensing to ensure uninterrupted access.
Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
Resilience through developer best practices in Customer Identity and Access Management using Azure AD B2C
Resilience through monitoring and analytics using Azure AD B2C
Learn methods to build resilience in end-user experience with Azure AD B2C
Learn about methods to build resilient interfaces with external processes.
Learn about case studies to reduce your dependency on traditional on-premises Active Directory services.
Learn to plan your migration workstream of IAM from Active Directory Domain Services (AD DS) to Microsoft Entra ID.
Learn how to mitigate specific security challenges that Generative AI (Gen AI) poses to ensure organizational security with Microsoft Entra.
Learn about baselines, and how to monitor and alert on potential security issues with privileged accounts in Microsoft Entra ID.
In this article, learn the steps you need to perform to integrate F5 with Microsoft Entra ID.
Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
This article describes common AI agent deployment patterns and how they map to Microsoft Entra Agent ID. The article starts with a review of key identity concepts, describes permisssions and trust boundaries, and then walks through common deployment patterns.
Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.
Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.
- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.
Learn about security considerations and architecture for using Microsoft Entra application proxy.
A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
- See, [Tutorial: Create an Azure Active Directory B2C tenant](/azure/active-directory-b2c/tutorial-create-tenant)
You assign users the role with the [least privileges necessary to perform their tasks](~/identity/role-based-access-control/delegate-by-task.md). This practice minimizes the number of Global Administrators and instead uses specific administrator roles for certain scenarios.
Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)
Learn foundational information to plan and design your solution
A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
Presents an overview of on-premises application provisioning architecture.
A Microsoft Entra documentation page was updated: Multi Tenant Common Considerations.
Learn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.
An end-to-end guide for planning the deployment of application proxy within your organization
A design pattern describing how to verify in helpdesk scenarios
Planning guide for a successful Lifecycle Workflow deployment.
Planning guide for a successful access reviews deployment.
Team members who need to create sensitivity labels require permissions to:
- [Microsoft Global Secure Access deployment guide for Microsoft Traffic](gsa-deployment-guide-microsoft-traffic.md)
A Microsoft Entra documentation page was updated: Road To The Cloud Ad Minimization.
|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |
The following are design considerations for all isolation configurations. Throughout this content, there are many links. We link to content, rather than duplicate it here, so you'll always have access to the most up-to-date information.
Follow these steps to create an Entitlement management catalog:
Follow these steps to create an Entitlement management catalog for the scenario.
A Log Analytics workspace is a data store to collect log data types from Azure and non-Azure resources and applications. We recommend you send all log data to one Log Analytics workspace.
Microsoft Entra introduces soft deletion and restoration for cloud security groups, allowing recovery within 30 days while preserving settings, ownership, and membership. Rollout begins in late October 2025 (preview) and February 2026 (general availability). Deleted groups remove access until restored; audit logs track actions.
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
When customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).
Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:
Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:
- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)
* [Microsoft Entra ID Governance](../id-governance/identity-governance-overview.md)
The following products and services appear in this guide:
The following products and services appear in this guide:
Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/what-is-entra.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.
These functional areas are provided by Microsoft Entra ID that are relevant to isolated environments. To learn more about the capabilities of Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).
Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/what-is-entra.md)
Presents an overview of on-premises application provisioning architecture.
This topic describes the architecture of Microsoft Entra Connect Sync and explains the terms used.
- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
The following diagram shows a high-level architecture of provisioning engine connecting to a single forest, although multiple forests are supported. This architecture shows how the various components interact with each other.
A Microsoft Entra documentation page was updated: Permissions Manage Ops Guide Alerts.
A Microsoft Entra documentation page was updated: Permissions Manage Ops Guide Intro.