Cross-product topic

Architecture

A cross-product view of Microsoft Entra changes related to Architecture.

Latest Architecture changes

Protect M365 From On Premises Attacks

Architecture

The guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.

Road To The Cloud Implement

Architecture

The guidance now links to a different Microsoft Entra Cloud Sync article for provisioning groups to Active Directory Domain Services.

Plan Agent Identity Architecture

Architecture

The documentation now explains that agents should use an agent identity blueprint and the `#Microsoft.Graph.AgentIdentity` object, rather than standard app-registration APIs. It also lists supported creation channels, roles, permissions, and .NET usage.

Plan Agent Identity Architecture

Architecture

The agent identity architecture planning page now links to the correct interactive agent authentication article instead of the previous broken path.

Road to the cloud: Introduction

Architecture

Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.

Gsa Poc Internet Access

Architecture

1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.

Gsa Poc Internet Access

Architecture

1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).

Deployment External Operations

Architecture

Learn about edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations for Microsoft Entra External ID.

Plan for tenant recoverability

Architecture

Learn how to prepare for and execute tenant-scoped recovery under the shared responsibility model.

Gsa Deployment Guide Internet Access

Architecture

At this point, you completed initiate and plan stages of your Secure Access Services Edge (SASE) deployment project. You understand what you need to implement for whom. You defined which users to enable in each wave. You have a schedule for each wave's deployment. You have met [licensing requirements](../global-secure-access/overview-what-is-global-secure-access.md#licensing-overview). You're ready to enable Microsoft Entra Internet Access.

Id Protection Guide Introduction

Architecture

- A test user who isn't an administrator to verify that policies work as expected before you deploy real users. To create a user, follow the steps in [How to create, invite, and delete users](../fundamentals/how-to-create-delete-users.md).

Agent Id Design Patterns

Architecture

Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.

Plan Agent Identity Architecture

Architecture

Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.

B2c Deployment Plans

Architecture

Azure Active Directory B2C deployment guide for planning, implementation, and monitoring

Microsoft Entra Agent ID design patterns

Architecture

Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.

Microsoft Entra architecture icons

Architecture

Learn about the official collection of Microsoft Entra ID icons that you can use in architectural diagrams, training materials, or documentation.

Microsoft Entra Suite workshop delivery guide

Architecture

This article is for use by the delivery expert that plans on delivering the Microsoft Entra Suite Workshop to customers. It aims to provide delivery experts with a comprehensive overview of the tasks that is required to successfully deliver the Microsoft Entra Suite Workshop to customers. It's structured chronologically following the standard and typical flow of a workshop delivery. It outlines how to use the Microsoft Entra Suite Workshop to deploy all the components of the suite. It gives organizations and IT admins a detailed plan to design and deploy Microsoft Entra ID Governance, Microsoft Entra Private Access, Microsoft Entra Internet Access, and Microsoft Entra Verified ID.

Plan a single sign-on deployment

Architecture

Plan your single sign‑on deployment in Microsoft Entra ID. Streamline role assignments, certificate management, and licensing to ensure uninterrupted access.

Plan your agent identity architecture

Architecture

Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.

Recover From Deletions

Architecture

Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.

Secure Generative AI with Microsoft Entra

Architecture

Learn how to mitigate specific security challenges that Generative AI (Gen AI) poses to ensure organizational security with Microsoft Entra.

Connect To Cloud Sync Decision Guide

Architecture

Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.

Recoverability Overview

Architecture

- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.

Agent Id Design Patterns

Architecture

This article describes common AI agent deployment patterns and how they map to Microsoft Entra Agent ID. The article starts with a review of key identity concepts, describes permisssions and trust boundaries, and then walks through common deployment patterns.

Microsoft Entra Agent ID design patterns

Architecture

Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.

Plan your agent identity architecture

Architecture

Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.

Recoverability Overview

Architecture

- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.

B2c Deployment Plans

Architecture

- See, [Tutorial: Create an Azure Active Directory B2C tenant](/azure/active-directory-b2c/tutorial-create-tenant)

Pim Deployment Plan

Architecture

You assign users the role with the [least privileges necessary to perform their tasks](~/identity/role-based-access-control/delegate-by-task.md). This practice minimizes the number of Global Administrators and instead uses specific administrator roles for certain scenarios.

10 Secure Local Guest

Architecture

Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)

Architecture overview

Architecture

Learn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.

Conceptual Deployment Plan

Architecture

An end-to-end guide for planning the deployment of application proxy within your organization

Licensing Governance

Architecture

|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |

Secure Best Practices

Architecture

The following are design considerations for all isolation configurations. Throughout this content, there are many links. We link to content, rather than duplicate it here, so you'll always have access to the most up-to-date information.

Id Protection Guide Analyze

Architecture

A Log Analytics workspace is a data store to collect log data types from Azure and non-Azure resources and applications. We recommend you send all log data to one Log Analytics workspace.

Gsa Poc Private Access

Architecture

When customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).

Id Protection Guide Introduction

Architecture

Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:

Id Protection Guide Investigate

Architecture

Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:

Id Protection Guide Remediate

Architecture

- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)

Microsoft Entra deployment plans

Architecture

Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/what-is-entra.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.

Secure Fundamentals

Architecture

These functional areas are provided by Microsoft Entra ID that are relevant to isolated environments. To learn more about the capabilities of Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).

What is the Microsoft Entra architecture?

Architecture

Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/what-is-entra.md)

Recoverability Overview

Architecture

- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.

Plan Connect Performance Factors

Architecture

The following diagram shows a high-level architecture of provisioning engine connecting to a single forest, although multiple forests are supported. This architecture shows how the various components interact with each other.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…