Concept and mechanism
An identity can represent a person or a workload. Microsoft Entra ID provides cloud identity capabilities; hybrid environments also connect on-premises and cloud identities. Federation enables trust in an identity provider without treating all permissions as equal. MFA strengthens proof of identity; Conditional Access connects signals to access controls and is evaluated after the first factor. It is not a barrier for absorbing volumetric attacks. Entra roles and Azure RBAC have different scopes: directory administration does not by default grant management of every VM. Before assigning a role, identify the necessary operation and the smallest scope permitting it.
Guided application
During a fictional L3 shift, PIM can support temporary activation of an eligible role with configured conditions. Ending activation removes access but does not undo changes made during the intervention. Access reviews help an owner confirm continued need for memberships and permissions; decisions must be applied. ID Protection supplies risk detections supporting investigation and policies. A detection is a signal to assess, not an automatic conclusion about intent. For compatible applications, managed identities reduce credentials maintained in code and still need destination authorization. Confirm licensing, administrative permissions, and operational readiness before promising a capability in a project plan.
Agent identities at handover
An AI agent accessing resources needs an identity distinguishable from its developers. In Entra Agent ID, a blueprint provides a template for creating agent identities. At handover of a batch-support pilot, identify the agent, technical owner, accountable sponsor, and permitted operations. Creating an identity does not automatically grant API access. Check logs and the need for each permission before RUN takes ownership. If the sponsor changes roles, confirm who oversees the service. The July objectives mention agent ID; the announced October wording uses workload identities. A terminology change does not justify teaching a shared human account as the operational solution.
The supplier finished the migration: MFA does not justify retaining every project privilege.
Common pitfalls
Eligible as active; MFA as business need; managed identity as universal access; directory role as Owner.
Related topics: Infrastructure protection · Posture, detection, and response
Choose identity, conditions, permissions, and lifecycle separately.
Reference: Identity and access concepts · SC-900 objectives 2026-07-28; October 2026 update announced