Cross-product topic

Architecture

A cross-product view of Microsoft Entra changes related to Architecture.

Latest Architecture changes

Road to the cloud: Introduction

Architecture

Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirem…

Gsa Poc Internet Access

Architecture

1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.

Gsa Poc Internet Access

Architecture

1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).

Deployment External Operations

Architecture

Learn about edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations for Microsoft Entra External ID.

Plan for tenant recoverability

Architecture

Learn how to prepare for and execute tenant-scoped recovery under the shared responsibility model.

Gsa Deployment Guide Internet Access

Architecture

At this point, you completed initiate and plan stages of your Secure Access Services Edge (SASE) deployment project. You understand what you need to implement for whom. You defined which users to enable in each wave. You have a schedule for each wave's deploy…

Id Protection Guide Introduction

Architecture

- A test user who isn't an administrator to verify that policies work as expected before you deploy real users. To create a user, follow the steps in [How to create, invite, and delete users](../fundamentals/how-to-create-delete-users.md).

Agent Id Design Patterns

Architecture

Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.

Plan Agent Identity Architecture

Architecture

Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.

B2c Deployment Plans

Architecture

Azure Active Directory B2C deployment guide for planning, implementation, and monitoring

Backup Authentication System

Architecture

Explore the resilience features of Microsoft Entra ID's backup authentication system, designed to maintain authentication availability for users and services.

Backup Authentication System Apps

Architecture

Learn how to configure your application to support the Microsoft Entra backup authentication system for enhanced resilience and security.

Microsoft Entra Agent ID design patterns

Architecture

Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.

Microsoft Entra architecture icons

Architecture

Learn about the official collection of Microsoft Entra ID icons that you can use in architectural diagrams, training materials, or documentation.

Microsoft Entra Suite workshop delivery guide

Architecture

This article is for use by the delivery expert that plans on delivering the Microsoft Entra Suite Workshop to customers. It aims to provide delivery experts with a comprehensive overview of the tasks that is required to successfully deliver the Microsoft Entr…

Plan a single sign-on deployment

Architecture

Plan your single sign‑on deployment in Microsoft Entra ID. Streamline role assignments, certificate management, and licensing to ensure uninterrupted access.

Plan your agent identity architecture

Architecture

Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.

Recover From Deletions

Architecture

Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.

Secure Generative AI with Microsoft Entra

Architecture

Learn how to mitigate specific security challenges that Generative AI (Gen AI) poses to ensure organizational security with Microsoft Entra.

Id Protection Guide Introduction

Architecture

- [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)

Recoverability Overview

Architecture

- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.

Resilience In Credentials

Architecture

|Certificate Based Authentication (CBA)|In most cases (depending on configuration) CBA will require a revocation check. This adds an external dependency on the CRL distribution point (CDP) |[Understanding the certificate revocation process](~/identity/authent…

Agent Id Design Patterns

Architecture

This article describes common AI agent deployment patterns and how they map to Microsoft Entra Agent ID. The article starts with a review of key identity concepts, describes permisssions and trust boundaries, and then walks through common deployment patterns.

Microsoft Entra Agent ID design patterns

Architecture

Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.

Plan your agent identity architecture

Architecture

Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.

Secure Generative Ai

Architecture

Enforce least privilege principles and apply the right access controls to keep your organization secure with [Conditional Access policies](../identity/conditional-access/plan-conditional-access.md). Think of Conditional Access policies as if-then statements w…

Recoverability Overview

Architecture

- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.

B2c Deployment Plans

Architecture

- See, [Tutorial: Create an Azure Active Directory B2C tenant](/azure/active-directory-b2c/tutorial-create-tenant)

Pim Deployment Plan

Architecture

You assign users the role with the [least privileges necessary to perform their tasks](~/identity/role-based-access-control/delegate-by-task.md). This practice minimizes the number of Global Administrators and instead uses specific administrator roles for cer…

10 Secure Local Guest

Architecture

Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)

Architecture overview

Architecture

Learn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.

Conceptual Deployment Plan

Architecture

An end-to-end guide for planning the deployment of application proxy within your organization

What Is App Proxy

Architecture

Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.

Licensing Governance

Architecture

|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |

Secure Best Practices

Architecture

The following are design considerations for all isolation configurations. Throughout this content, there are many links. We link to content, rather than duplicate it here, so you'll always have access to the most up-to-date information.

Id Protection Guide Analyze

Architecture

A Log Analytics workspace is a data store to collect log data types from Azure and non-Azure resources and applications. We recommend you send all log data to one Log Analytics workspace.

Backup Authentication System

Architecture

To enhance its resilience posture, the backup authentication system can't perform fresh revocation checks. Instead, it relies on the state of the certificate revocation list (CRL) check that's performed when the session was last backed up. If you need to revo…

Conditional Access Session

Architecture

Conditional Access App Control uses a reverse proxy architecture and is uniquely integrated with Microsoft Entra Conditional Access. Microsoft Entra Conditional Access allows you to enforce access controls on your organization’s apps based on certain conditio…

Gsa Poc Private Access

Architecture

When customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).

Id Protection Guide Detect

Architecture

To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor Sign-in risk and User [risk policies](../id-protection/concept-identity-protection-policies.md) in Microsoft Entra Conditional Access. If yo…

Id Protection Guide Introduction

Architecture

Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:

Id Protection Guide Investigate

Architecture

Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:

Id Protection Guide Remediate

Architecture

- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)

Microsoft Entra deployment plans

Architecture

Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/what-is-entra.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.