Microsoft 365

Microsoft Entra ID (Azure AD) Enterprise Usage and Configuration Guide

8 min read 1 August 2025

What Is Microsoft Entra ID?

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based Identity and Access Management (IAM) platform. Although it is positioned as the cloud counterpart of on-premises Active Directory, it has a far broader scope: it brings enterprise security functions such as SaaS application integration, conditional access, identity protection, and Privileged Identity Management (PIM) together under a single umbrella.

Core Concepts

ConceptDescription
TenantThe organization's Entra ID instance; hosts all users and resources
UserA directory record; the unit of authentication and authorization
GroupA collection of users and devices; used for policy assignment
App RegistrationThe representation of applications integrated with Entra ID
Service PrincipalThe identity of an application or automated process
Conditional AccessA policy engine that permits or blocks access based on specific conditions

License Tiers

  • Entra ID Free: Default with Microsoft 365 subscriptions; basic SSO and user management
  • Entra ID P1: Conditional access, group-based licensing, hybrid identity
  • Entra ID P2: Identity Protection, PIM, access reviews

For enterprise security, P1 is the minimum requirement; P2 is recommended for advanced threat protection.

User Management

Bulk User Creation (PowerShell)

# Microsoft Graph modülünü yükle
Install-Module Microsoft.Graph -Scope CurrentUser
Connect-MgGraph -Scopes "User.ReadWrite.All"

# Yeni kullanıcı oluşturma
$passwordProfile = @{
    Password = "Gecici@2025!"
    ForceChangePasswordNextSignIn = $true
}
New-MgUser -DisplayName "Ahmet Yılmaz" `
    -UserPrincipalName "ahmet.yilmaz@sirket.com" `
    -AccountEnabled `
    -PasswordProfile $passwordProfile `
    -UsageLocation "TR"

Creating Dynamic Groups

Dynamic groups provide automatic membership based on user attributes:

  • Example rule: (user.department -eq "IT") and (user.accountEnabled -eq true)
  • Used for policy assignment, license distribution, and application access.

Multi-Factor Authentication (MFA)

MFA Methods (Strongest to Weakest)

  1. FIDO2 security key (YubiKey, etc.)
  2. Microsoft Authenticator (passkey / passwordless)
  3. Microsoft Authenticator (approval notification)
  4. TOTP app (Google Authenticator, etc.)
  5. SMS / phone call (not recommended; SIM swap risk)

Enforcing MFA — Conditional Access Policy

Entra ID > Security > Conditional Access > New Policy

Politika Adı: MFA_Tüm_Kullanıcılar
Kapsam: Tüm kullanıcılar
Hedef kaynaklar: Tüm bulut uygulamaları
Erişim denetimi: MFA gerektir
Durum: Etkin

For rollout, first run in "Report-only" mode, perform impact analysis, then enable.

Single Sign-On (SSO) Integration

Gallery Applications

The Entra ID Application Gallery contains 4,000+ ready-made integrations (Salesforce, ServiceNow, Zoom, Jira, etc.):

  1. Select Enterprise Applications > New application
  2. Search for and add the application
  3. Configure Single sign-on > SAML
  4. Assign a user or group to the application

Custom Application — OIDC/OAuth2

Uygulama Kaydı > Yeni kayıt
Yeniden yönlendirme URI: https://uygulamaniz.com/auth/callback
Desteklenen hesap türleri: Yalnızca bu kuruluş

Verify the "accessTokenAcceptedVersion": 2 setting in the manifest.

Conditional Access Scenarios

Scenario 1: Block Non-Compliant Devices

Koşul: Cihaz uyumluluk durumu = Uyumsuz
Erişim denetimi: Erişimi engelle

Scenario 2: MFA for High-Risk Sessions

Koşul: Oturum açma riski = Yüksek (Identity Protection gerektirir)
Erişim denetimi: MFA gerektir + Parola sıfırlama

Scenario 3: Geographic Location Restriction

Koşul: Konumlar — Adlandırılmış konumlar dışındaki tüm lokasyonlar
Erişim denetimi: Erişimi engelle veya MFA gerektir

Privileged Identity Management (PIM)

PIM prevents highly privileged roles such as Global Admin from being permanently assigned:

  • Role assignments are made as eligible rather than permanent
  • The administrator activates the role on demand, with approval and justification
  • The activation duration is limited (e.g., 4 hours)
  • Every activation is logged and the administrator is notified
Entra ID > Kimlik İdaresi > Privileged Identity Management

Monitoring and Auditing

  • Sign-in logs: Sign-in history for the past 30 days, including location, device, and risk information
  • Audit logs: A record of changes to users, groups, and applications
  • Log Analytics integration: Forwarding logs to Azure Monitor is recommended for anomaly detection
  • Microsoft Sentinel: Advanced threat analysis for SIEM integration

Conclusion

Microsoft Entra ID is the cornerstone of modern enterprise identity infrastructure. When correctly configured, it blocks the vast majority of identity-based attacks, meets compliance requirements, and improves the user experience through SSO. As NRC Sistem, we support your organization with Entra ID licensing, deployment, and the design and implementation of MFA and Conditional Access policies.

All posts