Microsoft Entra collaborating production tenants guidance
Learn about Microsoft Entra tenant architecture for collaborating production tenants so that you can identify your needs and compare architectural options.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Architecture.
Learn about Microsoft Entra tenant architecture for collaborating production tenants so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for hybrid identity and isolation so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for nonproduction environments so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for primary production tenants so that you can identify your needs and compare architectural options.
Learn how to compose your Microsoft Entra tenant estate from common tenant architecture patterns so that you can meet your requirements with as few tenants as possible.
Learn about Microsoft Entra tenant architecture for business partner access so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for critical business systems so that you can identify your needs and compare architectural options.
Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.
1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).
Learn about edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations for Microsoft Entra External ID.
Learn how to prepare for and execute tenant-scoped recovery under the shared responsibility model.
At this point, you completed initiate and plan stages of your Secure Access Services Edge (SASE) deployment project. You understand what you need to implement for whom. You defined which users to enable in each wave. You have a schedule for each wave's deployment. You have met [licensing requirements](../global-secure-access/overview-what-is-global-secure-access.md#licensing-overview). You're ready to enable Microsoft Entra Internet Access.
1. Create end user communications to set expectations and provide an escalation path.
1. Create end user communications to set expectations and provide an escalation path.
- A test user who isn't an administrator to verify that policies work as expected before you deploy real users. To create a user, follow the steps in [How to create, invite, and delete users](../fundamentals/how-to-create-delete-users.md).
Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.
Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.
Azure Active Directory B2C deployment guide for planning, implementation, and monitoring
Explore the resilience features of Microsoft Entra ID's backup authentication system, designed to maintain authentication availability for users and services.
Learn how to configure your application to support the Microsoft Entra backup authentication system for enhanced resilience and security.
Learn methods to build resilience in customer identity and access management (CIAM) using Azure AD B2C.
A Microsoft Entra documentation page was updated: Configure Advanced F5 Kerberos Delegation for Multi-Tier SaaS Architectures.
Learn to convert local guests into Microsoft Entra B2B guest accounts by identifying apps and local guest accounts, migration, and more.
Resilience guidance for application deployments with orchestration of a relying party security token service to change its identity provider
Learn, deploy, and test Microsoft Entra ID Protection so that you can detect, investigate, and remediate identity-based risks.
Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.
Learn about the official collection of Microsoft Entra ID icons that you can use in architectural diagrams, training materials, or documentation.
Learn to securely deploy and operate Microsoft Entra External ID architectures with Microsoft Entra.
Learn about improving risk analysis to identify risky users, discern risk event types, and examine risk levels for access and identity decisions.
Learn how identity administrators use real-time risk detection features in Microsoft Entra ID Protection to grant user access to protected resources.
Learn how Security Operations Center (SOC) admins use Microsoft Entra ID Protection to bring identity risk-related telemetry into security investigations.
Learn how IT administrators use Microsoft Entra ID Protection to identify and remediate identity risks for users that access enterprise-managed resources.
Configure Microsoft Entra Suite products for upgrading existing VPN solution to a scalable cloud-based solution and move towards Secure Access Service Edge (SASE).
Configure Microsoft Entra Suite products for strict default internet access policies to control internet access according to business requirements.
Configure Microsoft Entra Suite products for hiring new remote employees and providing them with secure and seamless access to apps and resources.
The Microsoft Entra Suite deployment scenarios article series provides guidance regarding the Microsoft Entra Suite.
Locate and engage partners for guidance on Microsoft Entra deployment.
This article is for use by the delivery expert that plans on delivering the Microsoft Entra Suite Workshop to customers. It aims to provide delivery experts with a comprehensive overview of the tasks that is required to successfully deliver the Microsoft Entra Suite Workshop to customers. It's structured chronologically following the standard and typical flow of a workshop delivery. It outlines how to use the Microsoft Entra Suite Workshop to deploy all the components of the suite. It gives organizations and IT admins a detailed plan to design and deploy Microsoft Entra ID Governance, Microsoft Entra Private Access, Microsoft Entra Internet Access, and Microsoft Entra Verified ID.
Learn to harness AI-powered insights and automation and demonstrate the value of Security Copilot in Entra in your environment.
The Microsoft Authentication Library (MSAL) enables application developers to acquire tokens in order to call secured web APIs. These web APIs can be the Microsoft Graph, other Microsoft APIs, third-party web APIs, or your own web API. MSAL supports multiple application architectures and platforms.
Plan your single sign‑on deployment in Microsoft Entra ID. Streamline role assignments, certificate management, and licensing to ensure uninterrupted access.
Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
Resilience through developer best practices in Customer Identity and Access Management using Azure AD B2C
Resilience through monitoring and analytics using Azure AD B2C
Learn methods to build resilience in end-user experience with Azure AD B2C
Learn about methods to build resilient interfaces with external processes.
Learn about case studies to reduce your dependency on traditional on-premises Active Directory services.
Learn to plan your migration workstream of IAM from Active Directory Domain Services (AD DS) to Microsoft Entra ID.
Learn how to mitigate specific security challenges that Generative AI (Gen AI) poses to ensure organizational security with Microsoft Entra.
Learn about baselines, and how to monitor and alert on potential security issues with privileged accounts in Microsoft Entra ID.
The Microsoft Authentication Library (MSAL) enables application developers to acquire tokens in order to call secured web APIs. These web APIs can be Microsoft Graph, other Microsoft APIs, partner web APIs, or your own web API. MSAL supports multiple application architectures and platforms.
In this article, learn the steps you need to perform to integrate F5 with Microsoft Entra ID.
Plan your Conditional Access policies to balance security and productivity. Learn how to design and deploy effective policies for your organization.
- [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)
During the process of moving your app authentication to Microsoft Entra ID, test your apps and configuration. We recommend that you continue to use existing test environments for migration testing before you move to the production environment. If a test environment isn't currently available, you can set one up using [Azure App Service](https://azure.microsoft.com/services/app-service/) or [Azure Virtual Machines](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn), depending on the architecture of the application.
Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
|Certificate Based Authentication (CBA)|In most cases (depending on configuration) CBA will require a revocation check. This adds an external dependency on the CRL distribution point (CDP) |[Understanding the certificate revocation process](~/identity/authentication/concept-certificate-based-authentication-certificate-revocation-list.md#enforce-crl-validation-for-cas)|
This article describes common AI agent deployment patterns and how they map to Microsoft Entra Agent ID. The article starts with a review of key identity concepts, describes permisssions and trust boundaries, and then walks through common deployment patterns.
Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.
Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.
Enforce least privilege principles and apply the right access controls to keep your organization secure with [Conditional Access policies](../identity/conditional-access/plan-conditional-access.md). Think of Conditional Access policies as if-then statements where identities that meet certain criteria can only access resources if they meet specific requirements such as MFA or device compliance status.
- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.
Learn about the architecture, connectors, authentication methods, and security benefits of Microsoft Entra application proxy.
Learn about security considerations and architecture for using Microsoft Entra application proxy.
A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
- See, [Tutorial: Create an Azure Active Directory B2C tenant](/azure/active-directory-b2c/tutorial-create-tenant)
You assign users the role with the [least privileges necessary to perform their tasks](~/identity/role-based-access-control/delegate-by-task.md). This practice minimizes the number of Global Administrators and instead uses specific administrator roles for certain scenarios.
Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)
Learn foundational information to plan and design your solution
A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
Presents an overview of on-premises application provisioning architecture.
Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.
A Microsoft Entra documentation page was updated: Multi Tenant Common Considerations.
Learn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.
An end-to-end guide for planning the deployment of application proxy within your organization
A design pattern describing how to verify in helpdesk scenarios
Planning guide for a successful Lifecycle Workflow deployment.
Planning guide for a successful access reviews deployment.
Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.
Team members who need to create sensitivity labels require permissions to:
- [Microsoft Global Secure Access deployment guide for Microsoft Traffic](gsa-deployment-guide-microsoft-traffic.md)
A Microsoft Entra documentation page was updated: Road To The Cloud Ad Minimization.
|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |
The following are design considerations for all isolation configurations. Throughout this content, there are many links. We link to content, rather than duplicate it here, so you'll always have access to the most up-to-date information.
Follow these steps to create an Entitlement management catalog:
Follow these steps to create an Entitlement management catalog for the scenario.
A Log Analytics workspace is a data store to collect log data types from Azure and non-Azure resources and applications. We recommend you send all log data to one Log Analytics workspace.
Microsoft Entra introduces soft deletion and restoration for cloud security groups, allowing recovery within 30 days while preserving settings, ownership, and membership. Rollout begins in late October 2025 (preview) and February 2026 (general availability). Deleted groups remove access until restored; audit logs track actions.
To enhance its resilience posture, the backup authentication system can't perform fresh revocation checks. Instead, it relies on the state of the certificate revocation list (CRL) check that's performed when the session was last backed up. If you need to revoke before this backup expires, you should explicitly revoke the session instead of waiting for the CRL.
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
Conditional Access App Control uses a reverse proxy architecture and is uniquely integrated with Microsoft Entra Conditional Access. Microsoft Entra Conditional Access allows you to enforce access controls on your organization’s apps based on certain conditions. The conditions define what user or group of users, cloud apps, and locations and networks a Conditional Access policy applies to. After you determine the conditions, you can route users to Microsoft Defender for Cloud Apps where you can protect data with Conditional Access App Control by applying access and session controls.
When customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).
To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor Sign-in risk and User [risk policies](../id-protection/concept-identity-protection-policies.md) in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).
Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:
Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:
- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)
* [Microsoft Entra ID Governance](../id-governance/identity-governance-overview.md)