Memory hook: Identity lifecycle, access decision, app consent, review.
Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.
Scope/version: This path targets Microsoft’s published October 28, 2026 update. Check the outline for an earlier sitting. At review, the official page gives inconsistent percentage ranges for authentication/access in its overview and detailed heading, so this page does not present one as definitive.
Must remember by domain
| Domain | Rapid revision |
|---|---|
| Tenant/lifecycle | Entra roles differ from Azure RBAC. Administrative units scope supported administration, not full tenant isolation. Registration, Entra join, hybrid join and compliance are distinct device states. Verify domains, source authority, licenses and group-based grants. Custom security attributes have their own roles and visibility. |
| External/hybrid | External collaboration governs guests; cross-tenant access governs supported inbound/outbound trust; synchronization provisions identities without merging tenants. Password hash sync authenticates in cloud using derived hashes; pass-through authentication depends on on-premises agents; federation depends on the identity provider. Sync and authentication health are separate. |
| Authentication | Passkeys/FIDO2 and supported certificate/key-based methods improve phishing resistance. Temporary Access Pass bootstraps controlled recovery/enrollment. SSPR resets passwords; hybrid writeback needs prerequisites. Password Protection rejects weak patterns; MFA is independent factors, not two passwords. Emergency access must survive ordinary policy/dependency failure. |
| Access/risk | Conditional Access combines assignments, conditions, grant and session controls; applicable policies combine and a block can deny. Report-only observes without enforcing. User risk concerns identity compromise; sign-in risk concerns a particular attempt. Authentication context/protected actions enforce supported step-up requirements. CAE improves supported revocation but is not universal instant session termination. |
| Secure Access | Internet Access governs supported internet/SaaS traffic; Private Access connects supported private apps; Microsoft traffic profile covers supported Microsoft traffic. Client/connector routing and policy must align. Network reachability and application authorization remain separate. |
| Workload identities/apps | App registration defines the app; enterprise application/service principal represents it in a tenant. Delegated permissions use a signed-in user; application permissions are app-only. Consent, app assignment and provisioning differ. System-assigned identity follows resource lifecycle; user-assigned identity is reusable and independent. Application Proxy publishes supported on-premises apps; Cloud Apps adds discovery and supported session/OAuth controls. |
| Governance/evidence | Catalogs hold access packages; policies define approval/expiry; reviews verify continuing need. PIM eligible is not active; activation can require approval/MFA and expire. Sign-in logs show authentication/policy; audit shows changes; provisioning shows lifecycle delivery. Diagnostic settings export supported evidence for KQL and retention. |
Diagnostic order and traps
User/device/source state → authentication method → risk → Conditional Access result → application assignment/consent → downstream permission. For provisioning, inspect scope/mapping and target API errors instead of repeatedly resetting passwords. Review decisions only remove access when their configured application process runs. A user password reset does not revoke unrelated app-only credentials.
Last-pass self-check
1. Global Administrator automatically reads every Azure resource’s data?
No. Directory, management and data-plane authorization are distinct.
2. User sees app but target account is absent: investigate what?
Provisioning/assignment and target identity mapping, not only SSO.
3. What does a Conditional Access What If test provide?
Policy evaluation evidence for specified conditions; still validate the actual sign-in flow.
4. Managed identity exists but storage access fails: likely missing?
Correct data-role grant, actual selected identity or network/DNS permission.
5. What proves a PIM activation was used?
Correlate activation history with subsequent sign-in and audit/resource activity.
Sources
- Official exam scope and version
- entra · fundamentals · whatis
- entra · identity · role-based-access-control · administrative-units
- entra · external-id · cross-tenant-access-overview
- entra · identity · devices · overview
- entra · identity · hybrid · whatis-hybrid-identity
- entra · identity · hybrid · connect · whatis-azure-ad-connect
- entra · identity · hybrid · cloud-sync · what-is-cloud-sync
- entra · identity · hybrid · connect · choose-ad-authn
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Tenants, Administrative Scope and Identity Lifecycle
Memory hook: Directory role manages identity; Azure role manages a resource scope.
Must remember
A Microsoft Entra tenant is an identity directory boundary. Entra roles authorize directory administration; Azure RBAC roles authorize supported Azure resource operations. A subscription owner is not automatically a tenant Global Administrator, and directory administration does not automatically grant access to every subscription’s data.
Use groups, built-in/custom roles and administrative units to delegate appropriate administration. Administrative units scope supported role management; they are not isolated tenants and do not hide all directory objects from everyone. Evaluate effective grants, inherited/group-based access and privileged assignments rather than only one visible role.
Manage verified domains, user/group/device settings, company branding and lifecycle processes. Device registration, Entra join and hybrid join describe different relationships; registration alone does not prove device compliance. Licenses enable product capabilities and can be assigned directly or through supported group processes; troubleshoot assignment conflicts and capacity separately from sign-in.
External collaboration settings govern guest collaboration; cross-tenant access settings govern supported inbound/outbound trust and collaboration. Cross-tenant synchronization provisions supported identities; it does not merge tenants. External identity-provider federation can use supported SAML/WS-Fed arrangements. Review who may invite, what trust is accepted and how guests are removed.
Use supported Microsoft Graph PowerShell or admin-center bulk operations with scoped permissions. Custom security attributes classify identities for supported policy/use cases and have their own administration/access considerations. Always preview the target population before a bulk lifecycle change.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Delegate support for one department | Administrative unit plus an appropriate scoped Entra role. |
| Grant VM management | Azure RBAC at the needed resource scope. |
| Collaborate with another company | External identity and cross-tenant policy design. |
Traps
- An administrative unit is not a separate tenant.
- Device join is not the same as compliance or trust for every application.
02 · Hybrid Identity and Authentication Paths
Memory hook: Synchronization moves identity data; authentication proves the sign-in.
Must remember
Microsoft Entra Connect Sync and Cloud Sync provide supported directory synchronization with different architectures and feature support. Choose from topology, objects/features, agent deployment and operational requirements. Synchronization success does not prove every sign-in path is healthy.
Password hash synchronization sends a derived representation for cloud authentication; it does not send the user’s plaintext password. Pass-through authentication validates through on-premises agents and depends on that path’s availability. Federation delegates authentication to a trusted identity provider such as AD FS, adding certificate, endpoint and operational dependencies.
Seamless SSO improves the experience for supported domain-connected scenarios; it does not replace MFA or authorization. Migrating from federation to managed authentication requires staged testing of identities, applications, claims, policies and recovery. Keep a documented rollback and emergency-access strategy.
Entra Connect Health helps observe supported hybrid identity components. Investigate synchronization scope, duplicate/conflicting attributes, source authority and provisioning errors when objects diverge. For authentication issues, trace the method actually selected, agent/provider reachability and relevant sign-in logs instead of re-running sync blindly.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Reduce dependency on on-premises sign-in infrastructure | Evaluate password hash synchronization for supported requirements. |
| Validate passwords through on-premises agents | Pass-through authentication. |
| External IdP must issue authentication claims | Federation with its operational dependencies. |
Traps
- Directory synchronization and authentication are separate processes.
- Federation is not automatically more secure than managed authentication.
03 · Authentication Methods, Recovery and Passwordless Access
Memory hook: Strong proof matters at enrollment, sign-in and recovery.
Must remember
Plan authentication methods around phishing resistance, user population, device support and recovery. Passkeys/FIDO2, certificate-based authentication, Microsoft Authenticator and Windows Hello for Business provide different supported experiences and assurance. MFA means independent factors, not two passwords. Protect method registration because an attacker who enrolls a factor may persist after a password change.
A Temporary Access Pass supports controlled bootstrap/recovery for supported passwordless methods. Limit its lifetime/use and verify the recipient. SSPR enables eligible users to reset passwords after configured verification; hybrid writeback requires the supported configuration. Authentication-method policy, registration campaigns and Conditional Access work together but have different purposes.
Password Protection blocks weak/banned patterns under supported cloud/on-premises deployment. Windows Hello for Business binds supported key-based credentials to device/user gestures; do not confuse it with a reusable password shared across devices. Entra Kerberos supports particular hybrid identity/resource scenarios with prerequisites and trust configuration.
When an account is compromised, disable/restrict it as appropriate, revoke sessions and investigate persistence, methods and app consent. Token/session revocation behavior differs across resources; it is not proof that every offline or application-local session instantly disappears. Keep monitored emergency access independent of common failure paths.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Bootstrap a passwordless method | Controlled Temporary Access Pass where supported. |
| Reduce phishing exposure | Appropriate phishing-resistant methods and policy. |
| Hybrid self-service password reset | SSPR with required writeback and verification configuration. |
Traps
- Two knowledge secrets are not two independent factors.
- Resetting a password alone may leave malicious authentication methods or app consent.
04 · Conditional Access, Risk and Global Secure Access
Memory hook: Evaluate signals, enforce controls, test before broad rollout.
Must remember
Conditional Access evaluates configured assignments/conditions and applies grant/session controls. Scope users, groups, workload identities where supported, target resources, locations, device state and risk carefully. Policies can combine; an applicable blocking policy can prevent access despite another allowing it. Report-only mode observes policy impact without enforcing its grant controls.
Use authentication strengths, compliant-device requirements and appropriate session controls to meet the actual requirement. Authentication context can request stronger checks for sensitive application actions; protected actions apply supported Conditional Access requirements to privileged operations. Test with sign-in logs and What If analysis, then a controlled user group, preserving monitored emergency access.
Identity Protection distinguishes user risk (likelihood an identity is compromised) from sign-in risk (risk in a particular authentication attempt). Investigate and remediate based on evidence; dismissing a detection is not the same as fixing a compromised account. Workload identity risk needs service-principal context and different remediation from a human password reset.
Continuous access evaluation enables supported resources to react to important changes more promptly, but it is not a universal instant revocation mechanism. Session lifetime, application-enforced restrictions and Defender for Cloud Apps session controls operate at different layers.
Global Secure Access includes Entra Internet Access and Private Access, with supported clients/connectors and traffic profiles. Private Access provides identity-aware access to private resources; Internet Access governs internet/SaaS traffic; the Microsoft traffic profile addresses supported Microsoft service traffic. Routing, enrollment and Conditional Access must align, or a policy may never see the intended traffic.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Assess new policy impact safely | Report-only, What If and controlled pilot evidence. |
| One suspicious login | Investigate sign-in risk and associated user activity. |
| Identity-aware access to a private app | Entra Private Access or appropriate Application Proxy scenario. |
Traps
- Report-only does not enforce the intended block.
- A trusted named location alone is not a complete Zero Trust decision.
05 · Application Registrations, Consent and Workload Identities
Memory hook: Registration defines the app; service principal represents it in a tenant.
Must remember
An app registration defines an application’s identity/configuration; a service principal is its tenant-local representation, commonly managed under enterprise applications. A multitenant app can have service principals in several tenants. Configure redirect URIs, supported accounts, credentials and API permissions deliberately.
Delegated permissions act with a signed-in user under applicable limits; application permissions support app-only access. Consent authorizes requested permissions under tenant policy; admin consent may be required for sensitive scopes. App roles and user/group assignment govern supported application access and should not be confused with directory administrator roles.
Managed identities give supported Azure workloads service identities without application-managed secrets. System-assigned lifecycle follows its resource; user-assigned identities have an independent reusable lifecycle. Use the correct identity and grant downstream access explicitly. A managed identity’s existence does not automatically authorize reading Key Vault or storage.
Enterprise-app integration includes SaaS SSO, provisioning and supported on-premises publishing through Application Proxy connectors. Authentication and provisioning are different: successful SSO does not automatically create all required application entitlements. Collections help organize user-facing applications; lifecycle and assignment remain governed.
Defender for Cloud Apps discovers cloud usage, integrates connected apps and supports access/session/OAuth-app policies. Conditional Access app control can enforce supported session restrictions through its proxy path. Investigate excessive consent, unused credentials and suspicious app behavior; revoke/rotate the actual affected service credentials or grants rather than a random user password.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Azure workload calls a supported service | Managed identity plus least-privilege target permissions. |
| Daemon acts without a user | Application permissions with appropriate consent. |
| Publish supported on-premises web app | Application Proxy with connectors and access policy. |
Traps
- App registration and enterprise application are related but different objects.
- SSO and user provisioning are not the same function.
06 · Entitlements, Access Reviews and Privileged Elevation
Memory hook: Grant for a reason, expire on purpose, review with evidence.
Must remember
Entitlement management groups resources into access packages within catalogs. Policies define who can request, who approves, duration and lifecycle behavior. Connected organizations and terms of use support governed external collaboration. An approval workflow without expiry or owner review can leave access indefinitely.
Access reviews periodically ask accountable reviewers to confirm continuing need. Configure population, recurrence, recommendations and what happens to unreviewed/denied access. Review completion is not enough if removal decisions are never applied. Guests who leave a partner organization may still have local resource assignments unless lifecycle processes handle them.
Privileged Identity Management distinguishes eligible assignments from active access. Activation can require justification, MFA, approval and limited duration according to configuration. PIM manages supported Entra roles, Azure resource roles and group membership/ownership scenarios. Eligibility is not identical to an always-active role.
Monitor request/approval history and privileged actions. Protect emergency accounts outside common lockout paths, with strong credentials, tightly controlled use and alerting. Do not leave permanent broad privilege merely to make support convenient; also do not make recovery impossible by putting every administrator behind one fragile dependency.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Partner needs temporary access to several resources | Access package with approval and expiry. |
| Administrator occasionally needs a powerful role | Eligible PIM assignment with controlled activation. |
| Confirm existing access still justified | Access review with applied decisions. |
Traps
- An approved request does not justify access forever.
- PIM eligibility does not automatically mean the role is active now.
07 · Identity Logs, KQL and Operational Investigation
Memory hook: Find the actual actor, resource and policy result.
Must remember
Sign-in logs explain authentication/resource access attempts and Conditional Access evaluation. Audit logs describe directory/configuration changes. Provisioning logs track identity synchronization into applications/services. Choose the log matching the failed operation before changing policy.
Diagnostic settings route supported logs to Log Analytics, storage or Event Hubs for analysis, retention or external processing. Availability, retention and licensing vary by log/capability. Protect access because logs can contain personal and security-sensitive information. A destination configured today does not reconstruct every historical event.
Use KQL to filter a time range, correlate identity/application/correlation IDs and summarize failure trends. Workbooks visualize reusable analysis; Identity Secure Score highlights improvement recommendations rather than certifying that the tenant is safe. Investigate a sudden score change in context.
For a failed app login, trace user/device state, authentication method, risk, policy result, application assignment and consent. For provisioning failure, inspect mapping/scope and target API responses. For privileged activity, correlate PIM activation with subsequent audit events. Preserve evidence and distinguish an expected administrative action from misuse.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| User cannot authenticate | Sign-in logs and policy details. |
| User authenticates but app account missing | Provisioning logs and assignment/mapping. |
| Role unexpectedly changed | Directory audit logs and PIM history. |
Traps
- A Secure Score recommendation is not proof of an incident.
- Changing Conditional Access will not necessarily repair a provisioning error.