What is Microsoft Entra ID?
Microsoft Entra ID is a cloud-based identity and access management service that your employees can use to access external resources. Example resources include Microsoft 365, the Azure portal, and thousands of other SaaS applications.
Microsoft Entra ID also helps them access internal resources like apps on your corporate intranet, and any cloud apps developed for your own organization. To learn how to create a tenant, see Quickstart: Create a new tenant in Microsoft Entra ID.
To learn the differences between Active Directory and Microsoft Entra ID, see Compare Active Directory to Microsoft Entra ID. You can also refer to Microsoft Cloud for Enterprise Architects Series posters to better understand the core identity services in Azure like Microsoft Entra ID and Microsoft-365.
Who uses Microsoft Entra ID?
Microsoft Entra ID provides different benefits to members of your organization based on their role:
IT admins use Microsoft Entra ID to control access to apps and app resources, based on business requirements. For example, as an IT admin, you can use Microsoft Entra ID to require multifactor authentication when accessing important organizational resources. You could also use Microsoft Entra ID to automate user provisioning between your existing Windows Server AD and your cloud apps, including Microsoft 365. Finally, Microsoft Entra ID gives you powerful tools to automatically help protect user identities and credentials and to meet your access governance requirements.
App developers can use Microsoft Entra ID as a standards-based authentication provider that helps them add single sign-on (SSO) to apps that works with a user's existing credentials. Developers can also use Microsoft Entra APIs to build personalized experiences using organizational data. To get started, sign up for a free 30-day Microsoft Entra ID P1 or P2 trial. For more information, you can also see Microsoft Entra ID for developers.
Microsoft 365, Office 365, Azure, or Dynamics CRM Online subscribers already use Microsoft Entra ID as every Microsoft 365, Office 365, Azure, and Dynamics CRM Online tenant is automatically a Microsoft Entra tenant. You can immediately start managing access to your integrated cloud apps.
What are the Microsoft Entra ID licenses?
Microsoft Online business services, such as Microsoft 365 or Azure, use Microsoft Entra ID for sign-in activities and to help protect your identities. If you subscribe to any Microsoft Online business service, you automatically get access to Microsoft Entra ID Free.
To enhance your Microsoft Entra implementation, you can also add paid features by upgrading to Microsoft Entra ID P1 or P2 licenses, or adding on licenses for products such as Microsoft Entra ID Governance. You can also license Microsoft Entra paid licenses are built on top of your existing free directory. The licenses provide self-service, enhanced monitoring, security reporting, and secure access for your mobile users.
Note
For the pricing options of these licenses, see Microsoft Entra pricing.
For more information about Microsoft Entra pricing, contact the Microsoft Entra Forum.
Microsoft Entra ID Free. Provides user and group management, on-premises directory synchronization, basic reports, self-service password change for cloud users, and single sign-on across Azure, Microsoft 365, and many popular SaaS apps.
Microsoft Entra ID P1. In addition to the Free features, P1 also lets your hybrid users access both on-premises and cloud resources. It also supports advanced administration, such as dynamic membership groups, self-service group management, Microsoft Identity Manager, and cloud write-back capabilities, which allow self-service password reset for your on-premises users.
Microsoft Entra ID P2. In addition to the Free and P1 features, P2 also offers Privileged Identity Management to help discover, restrict, and monitor administrators and their access to resources and to provide just-in-time access when needed.
In addition to Microsoft Entra ID licenses, you can enable additional identity management capabilities with licenses for other Microsoft Entra products, including:
Microsoft Entra ID Governance. Microsoft Entra ID Governance is an advanced set of identity governance capabilities for Microsoft Entra ID P1 and P2 customers.
"Pay as you go" feature licenses. You can also get licenses for features such as Microsoft Entra Domain Services, and Microsoft Entra Business-to-Customer (B2C). B2C can help you provide identity and access management solutions for your customer-facing apps. For more information, see Azure Active Directory B2C documentation.
For more information on the Microsoft Entra product family, see Microsoft Entra.
For more information about associating an Azure subscription to Microsoft Entra ID, see Associate or add an Azure subscription to Microsoft Entra ID. For more information about assigning licenses to your users, see How to: Assign or remove Microsoft Entra ID licenses.
Terminology
To better understand Microsoft Entra ID and its documentation, we recommend reviewing the following terms.
Term or concept | Description |
---|---|
Identity | A thing that can get authenticated. An identity can be a user with a username and password. Identities also include applications or other servers that might require authentication through secret keys or certificates. |
Account | An identity that has data associated with it. You can’t have an account without an identity. |
Microsoft Entra account | An identity created through Microsoft Entra ID or another Azure cloud service, such as Microsoft 365. Identities are stored in Microsoft Entra ID and accessible to your organization's cloud service subscriptions. This account is also sometimes called a Work or school account. |
Account Administrator | This classic subscription administrator role is conceptually the billing owner of a subscription. This role enables you to manage all subscriptions in an account. For more information, see Azure roles, Microsoft Entra roles, and classic subscription administrator roles. |
Service Administrator | This classic subscription administrator role enables you to manage all Azure resources, including access. This role has the equivalent access of a user who is assigned the Owner role at the subscription scope. For more information, see Azure roles, Microsoft Entra roles, and classic subscription administrator roles. |
Owner | This role helps you manage all Azure resources, including access. This role is built on a newer authorization system called Azure role-based access control (Azure RBAC) that provides fine-grained access management to Azure resources. For more information, see Azure roles, Microsoft Entra roles, and classic subscription administrator roles. |
Microsoft Entra Global Administrator | This administrator role is automatically assigned to whomever created the Microsoft Entra tenant. You can have multiple accounts with this role, but anyone with at least Privileged Role Administrator can assign administrator roles to users. For more information about the various administrator roles, see Administrator role permissions in Microsoft Entra ID. |
Azure subscription | Used to pay for Azure cloud services. You can have many subscriptions and they're linked to a credit card. |
Tenant | A dedicated and trusted instance of Microsoft Entra ID. The tenant is automatically created when your organization signs up for a Azure cloud service subscription. These subscriptions include Azure, Microsoft Intune, or Microsoft 365. This tenant represents a single organization and is intended for managing your employees, business apps, and other internal resources. For this reason, it's considered a workforce tenant configuration. |
Single tenant | Azure tenants that access other services in a dedicated environment are considered single tenant. |
Multitenant | Azure tenants that access other services in a shared environment, across multiple organizations, are considered multitenant. |
Microsoft Entra directory | Each Azure tenant has a dedicated and trusted Microsoft Entra directory. The Microsoft Entra directory includes the tenant's users, groups, and apps and is used to perform identity and access management functions for tenant resources. |
Custom domain | Every new Microsoft Entra directory comes with an initial domain name, for example domainname.partner.onmschina.cn . In addition to that initial name, you can also add your organization's domain names. Your organization's domain names include the names you use to do business and your users use to access your organization's resources, to the list. Adding custom domain names helps you to create user names that are familiar to your users, such as alain@contoso.com. |