Identity Management (or Identity and Access Management) is a fundamental aspect of modern IT security. It involves the processes and technologies used to manage and verify the identity of users accessing IT resources. A key IAM solution is Active Directory, a product by Microsoft that is widely recognized for its robustness and versatility in managing on-premises user identities.
Active Directory (AD) centralizes user and computer authentication and authorization, allowing IT administrators to control user access to various network resources effectively. This is especially crucial for large organizations with complex structures and lots of users, where maintaining individual user accounts wouldn’t be practical. Active Directory streamlines management by providing a single, unified platform for identity management, enhancing security and operational efficiency.
Expanding the principles of Identity and Access Management to the cloud, Microsoft introduced 'Microsoft Entra ID' (formerly Azure Active Directory). It is a solution designed to simplify and secure the management of user identities for cloud-native applications.
Entra ID extends beyond the traditional boundaries of on-premises networks, embracing cloud services and mobile applications. Microsoft Entra ID offers enhanced features like multi-factor authentication (MFA), conditional access policies, and integrated identity governance capabilities.
Microsoft Entra ID is the IAM used by Microsoft 365. Entra ID can also be used in conjunction with on-premises Windows Server Active Directory, giving organizations the ability to extend their existing directory service to the cloud.
Last Update: Sep 04, 2024
Microsoft Entra ID – previously called Azure Active Directory (Azure AD) – is Microsoft’s cloud-based identity and access management (IAM) cloud service. Azure AD is generally seen as a move from on-premises IAM to the cloud. Learn more about Azure AD here. What is Microsoft Entra ID (Azure Active Directory)? Microsoft Entra ID (Azure AD,…
Last Update: Mar 13, 2024
Active Directory is Microsoft’s on-premises identity and access management (IAM) service. In this article, learn how Active Directory (AD) makes it easier for IT to manage an organization’s IT resources. Active Directory is especially useful for companies that have to manage lots of endpoints and servers. What is Active Directory and why is it used?…
Last Update: Nov 19, 2024
In this Ask the Admin, learn how ADFS can be used for sharing identity information between business partners.
Last Update: Jun 03, 2024
For any modern enterprise that uses Microsoft Entra ID (previously Azure Active Directory) to manage user and service access to cloud resources, it’s hard to escape the term Zero Trust (ZT), which implies that your organization must have a layered approach to security. In this article, you’ll learn about five Microsoft Zero Trust tactics for…
You are woken by a call at 7am to find out your Active Directory (AD) infrastructure has been hit by ransomware. The helpdesk is overwhelmed by calls from users who can’t log in and management is already demanding to know how long it will take to restore. You break into a cold sweat realizing IT…
Last Update: Sep 20, 2024
As an IT Pro in the Microsoft online landscape, you’ve certainly been seeing ‘Microsoft Entra ID‘ more often. What is this? Is there a difference between Entra ID vs Azure AD? It’s actually very simple. Read on to find out more! Entra ID vs Azure AD So, what is Microsoft Entra ID? Well, it’s very…
In this article, I’ll show you how to list Active Directory users with PowerShell. While you can also list Active Directory (AD) users in Active Directory Users and Computers, PowerShell provides a much faster way. Check out how to list Active Directory Users with ADUC on Petri if you would prefer to perform this action…
Last Update: Mar 14, 2025
Azure Virtual Desktop (AVD) is a Platform-as-a-Service (PaaS) to provide access to Windows 10 and Windows 11 desktops and applications virtually anywhere. It’s a solution hosted by Microsoft, which makes it secure by design, even though there is a lot of responsibility on the customer to ensure services are secure. In this article, I will…
Last Update: Sep 04, 2024
Before you perform an AAD domain join, you should understand the difference between an AAD domain-joined device and one that is registered with AAD.
Microsoft is about to implement a hardening update for Entra Connect Sync. The company urges all organizations to upgrade to the required minimum version by April 7, 2025. Microsoft released a new version of its Entra Connect Sync solution in October 2024. These updates include a back-end service change aimed at further improving the security…
Navigating Group Policy issues can be challenging in an Active Directory environment, but the gpresult command is a powerful tool for diagnosing and resolving these problems. This article helps you to effectively use gpresult to troubleshoot Group Policy information, ensuring your system configurations are applied correctly and efficiently. Using GPResult for Basic Troubleshooting Let me…
Microsoft is preparing to retire the event alerts feature in its Purview Audit solution. The company announced on the Microsoft 365 Admin Center that this change will take effect in March 2025. Microsoft Purview Audit is an auditing solution designed to support organizations in conducting forensic and compliance investigations. It provides high-bandwidth access to audit…
Group Policy WMI Filtering is a powerful feature that allows administrators to apply Group Policy Objects (GPOs) and Group Policy preferences based on specific attributes of target computers, servers, and users. By leveraging Windows Management Instrumentation (WMI) queries, IT professionals can create highly targeted and dynamic GPOs that respond to the unique needs of their…
Security researchers have discovered a sophisticated phishing campaign targeting organizations that rely on Active Directory Federation Services (ADFS) for secure access. This attack has already compromised over 150 organizations across critical sectors, including healthcare, education, government, and technology. Active Directory Federation Services (ADFS) is a software component that gives users sign-on (SSO) access to systems…
Microsoft has recently rolled out a new update (version 2.4.129.0) of its Entra Connect Sync service. The latest release brings new auditing capabilities, enhancements, as well as bug fixes to improve user experience and boost the overall stability of the system. What is Microsoft Entra Connect Sync? Microsoft Entra Connect Sync enables organizations to synchronize…
Microsoft is about to add a new People administrator role in Microsoft Entra, allowing organizations to securely delegate people-related tasks. This update helps streamline user management while minimizing security risks associated with high-level admin roles. In Microsoft Entra ID, built-in roles offer pre-defined permissions for efficient access control, but they don’t always match common user…
Microsoft has detailed key security recommendations for enterprises in 2025, emphasizing a proactive approach to data protection. The company urges businesses to strengthen their defenses against AI-driven attacks and phishing threats by adopting advanced security measures. “Reactive security isn’t enough to safeguard your environment. Our guidance for 2025 is to always start at the highest…
Microsoft has announced the general availability of new Identity Secure Score recommendations in Microsoft Entra. These recommendations are designed to help administrators strengthen their security posture and provide actionable insights to detect and mitigate security risks within the organization. Microsoft first announced the Entra Identity Secure Score recommendations feature in April 2024. It provides recommendations…
Microsoft is moving forward with the phased retirement of its Azure AD Graph API service, which began in September 2024. The company has confirmed that starting February 1, 2025, existing applications will no longer be able to send requests to the Azure AD Graph API. Azure AD Graph API was a service that allowed developers…
Last Update: Jan 14, 2025
In this guide about Active Directory (AD) security, we’re going to detail five steps that IT admins need to follow to secure Active Directory environments in an organization. There are many best practices you’ll need to be familiar with to ensure Active Directory security, including restricting the use of privileged accounts, monitoring Windows Event Log…
Microsoft Entra ID has introduced support for issuing Temporary Access Passes (TAPs) for internal guest users. These passcodes are time-limited and help onboard and recover accounts without relying on traditional passwords. What is a Temporary Access Pass (TAP)? A Temporary Access Pass (TAP) in Microsoft Entra ID is a time-limited passcode designed to help users…