What Is Microsoft Entra ID?
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based Identity and Access Management (IAM) platform. Although it is positioned as the cloud counterpart of on-premises Active Directory, it has a far broader scope: it brings enterprise security functions such as SaaS application integration, conditional access, identity protection, and Privileged Identity Management (PIM) together under a single umbrella.
Core Concepts
| Concept | Description |
|---|---|
| Tenant | The organization's Entra ID instance; hosts all users and resources |
| User | A directory record; the unit of authentication and authorization |
| Group | A collection of users and devices; used for policy assignment |
| App Registration | The representation of applications integrated with Entra ID |
| Service Principal | The identity of an application or automated process |
| Conditional Access | A policy engine that permits or blocks access based on specific conditions |
License Tiers
- Entra ID Free: Default with Microsoft 365 subscriptions; basic SSO and user management
- Entra ID P1: Conditional access, group-based licensing, hybrid identity
- Entra ID P2: Identity Protection, PIM, access reviews
For enterprise security, P1 is the minimum requirement; P2 is recommended for advanced threat protection.
User Management
Bulk User Creation (PowerShell)
# Microsoft Graph modülünü yükle
Install-Module Microsoft.Graph -Scope CurrentUser
Connect-MgGraph -Scopes "User.ReadWrite.All"
# Yeni kullanıcı oluşturma
$passwordProfile = @{
Password = "Gecici@2025!"
ForceChangePasswordNextSignIn = $true
}
New-MgUser -DisplayName "Ahmet Yılmaz" `
-UserPrincipalName "ahmet.yilmaz@sirket.com" `
-AccountEnabled `
-PasswordProfile $passwordProfile `
-UsageLocation "TR"
Creating Dynamic Groups
Dynamic groups provide automatic membership based on user attributes:
- Example rule:
(user.department -eq "IT") and (user.accountEnabled -eq true) - Used for policy assignment, license distribution, and application access.
Multi-Factor Authentication (MFA)
MFA Methods (Strongest to Weakest)
- FIDO2 security key (YubiKey, etc.)
- Microsoft Authenticator (passkey / passwordless)
- Microsoft Authenticator (approval notification)
- TOTP app (Google Authenticator, etc.)
- SMS / phone call (not recommended; SIM swap risk)
Enforcing MFA — Conditional Access Policy
Entra ID > Security > Conditional Access > New Policy
Politika Adı: MFA_Tüm_Kullanıcılar
Kapsam: Tüm kullanıcılar
Hedef kaynaklar: Tüm bulut uygulamaları
Erişim denetimi: MFA gerektir
Durum: Etkin
For rollout, first run in "Report-only" mode, perform impact analysis, then enable.
Single Sign-On (SSO) Integration
Gallery Applications
The Entra ID Application Gallery contains 4,000+ ready-made integrations (Salesforce, ServiceNow, Zoom, Jira, etc.):
- Select Enterprise Applications > New application
- Search for and add the application
- Configure Single sign-on > SAML
- Assign a user or group to the application
Custom Application — OIDC/OAuth2
Uygulama Kaydı > Yeni kayıt
Yeniden yönlendirme URI: https://uygulamaniz.com/auth/callback
Desteklenen hesap türleri: Yalnızca bu kuruluş
Verify the "accessTokenAcceptedVersion": 2 setting in the manifest.
Conditional Access Scenarios
Scenario 1: Block Non-Compliant Devices
Koşul: Cihaz uyumluluk durumu = Uyumsuz
Erişim denetimi: Erişimi engelle
Scenario 2: MFA for High-Risk Sessions
Koşul: Oturum açma riski = Yüksek (Identity Protection gerektirir)
Erişim denetimi: MFA gerektir + Parola sıfırlama
Scenario 3: Geographic Location Restriction
Koşul: Konumlar — Adlandırılmış konumlar dışındaki tüm lokasyonlar
Erişim denetimi: Erişimi engelle veya MFA gerektir
Privileged Identity Management (PIM)
PIM prevents highly privileged roles such as Global Admin from being permanently assigned:
- Role assignments are made as eligible rather than permanent
- The administrator activates the role on demand, with approval and justification
- The activation duration is limited (e.g., 4 hours)
- Every activation is logged and the administrator is notified
Entra ID > Kimlik İdaresi > Privileged Identity Management
Monitoring and Auditing
- Sign-in logs: Sign-in history for the past 30 days, including location, device, and risk information
- Audit logs: A record of changes to users, groups, and applications
- Log Analytics integration: Forwarding logs to Azure Monitor is recommended for anomaly detection
- Microsoft Sentinel: Advanced threat analysis for SIEM integration
Conclusion
Microsoft Entra ID is the cornerstone of modern enterprise identity infrastructure. When correctly configured, it blocks the vast majority of identity-based attacks, meets compliance requirements, and improves the user experience through SSO. As NRC Sistem, we support your organization with Entra ID licensing, deployment, and the design and implementation of MFA and Conditional Access policies.