What it is

Entra ID (formerly Azure AD) is the identity plane for Microsoft cloud: users, groups, apps, guests, and Conditional Access. It is how people and workloads prove who they are.

Global Admin is the master key neighbourhood. Guest accounts are how partners get in. Both are useful. Both accumulate like office plants nobody waters.

AWS IAM is the cousin inside an AWS account. Entra often sits above Azure subscriptions and also gates M365. Bigger blast radius if you treat it casually.

Why it matters in the meeting

Identity is where most breaches start. A guest from a pilot in 2021. A Global Admin without MFA. An app registration with a secret in a repo.

When Bart asks how many Global Admins you have, he wants a number. "A handful" is not a number.

Real world

Privileged Identity Management lets people borrow admin for an hour. Standing admin is how standing incidents happen.

Guest cleanup and access reviews are boring. They are also how you avoid explaining a former vendor in your tenant to an auditor.

In plain terms

Entra is the front door for Microsoft cloud. Guests and Global Admins need a list, MFA, and an expiration date. Forever access is not hospitality. It is inventory you forgot.

What to ask

  • How many Global Administrators exist, named, with MFA?
  • How many guest accounts are older than 90 days with no sign-in?
  • Do we use PIM for standing admin, or is admin permanent?
  • Which app registrations still have client secrets instead of managed identities?

You just knew a little more Jack than you did five minutes ago.

All concepts