Lesson 4 / 25
Microsoft Entra ID
Describe users, groups, app registrations and service principals in Entra ID.
The directory behind every sign-in
Microsoft Entra ID (formerly Azure Active Directory) is Azure's cloud identity service. It stores users and groups, issues tokens using OAuth 2.0 and OpenID Connect, and enforces sign-in rules such as multi-factor authentication and Conditional Access (for example, block sign-ins from unmanaged devices). Applications get identities too. An app registration is the global definition of an app (its client ID, redirect URIs, secrets or certificates, and the permissions it asks for). A service principal is that app's instance in a particular tenant, and it is what you grant roles to. Entra ID is not the same as on-premises Active Directory Domain Services: it speaks web protocols, not LDAP and Kerberos, although the two are often synchronised.
Who is asking, and what may they do
Identity answers who (Entra ID). Authorisation answers what they may do (Azure RBAC).
Inspecting identities with the CLI
Useful commands when you need an object ID for a role assignment.
az ad signed-in-user show --query "{name:displayName, id:id}"
az ad group create --display-name shop-developers --mail-nickname shop-developers
az ad group member add --group shop-developers --member-id <user-object-id>
# an app registration and its service principal
az ad app create --display-name shop-api
az ad sp create --id <appId>Grant roles to groups, not people
Assigning roles to individual users becomes unmanageable quickly. Assign roles to Entra groups, and manage membership. When someone changes team, one membership change updates all their access.
Quick check: Which object do you grant Azure roles to when an application needs access in your tenant?
- The app registration's redirect URI
- The resource group tag
- The service principal
- The client secret
Answer
The service principal — The service principal is the app's identity inside your tenant; role assignments target it.