Microsoft Entra ID is Microsoft’s cloud-native identity and access management (IAM) platform. Formerly known as Azure Active Directory (Azure AD), Entra ID delivers authentication, policy enforcement, and centralized access control for users, devices, and applications across cloud and hybrid environments. It is not a direct replacement for legacy, on-premises Active Directory; instead, it defines a modern, protocol-divergent perimeter for cloud-first identity management.
What Is Microsoft Entra ID in Practice?
Microsoft Entra ID is a multi-tenant, cloud-based directory service underpinning authentication and authorization for Microsoft 365, Azure, and thousands of third-party SaaS integrations. Every Microsoft 365 or Azure subscription creates a dedicated “tenant,” which represents an administrative and security boundary for user accounts, groups, devices, applications, and identity policies.
Entra ID’s architecture and protocols differ fundamentally from classic Active Directory (AD). While AD was architected for on-prem, Windows-centric networks using LDAP and Kerberos, Entra ID is built for the cloud, exposed via modern authentication protocols such as OAuth 2.0, OpenID Connect, and SAML. Most crucially, Entra ID does not natively provide LDAP/Kerberos endpoints.
Concrete example:
A SaaS company provisions user accounts for its workforce in an Entra ID tenant. Employees use single sign-on (SSO) and multi-factor authentication (MFA) for Microsoft 365, Azure resources, ServiceNow, and Salesforce—all managed centrally from the Entra ID tenant.
Entra ID’s Core Capabilities: The Modern IAM Baseline
Entra ID provides a suite of core IAM capabilities by default:
- User and Device Authentication: Supports cloud and some hybrid device authentication using cloud-first protocols.
- Single Sign-On (SSO): Enables users to access Microsoft 365, Azure, and thousands of compatible SaaS and enterprise apps after a single authentication.
- Multi-Factor Authentication (MFA): Adds a second factor for identity verification, configurable by policy.
- Conditional Access: Policy framework that enforces contextual access controls (e.g., require MFA for logins from new locations).
- Role-Based Access Control (RBAC): Assigns granular permissions to users and groups for apps and resources.
- Identity Governance: Automates access reviews, lifecycle management, and compliance reporting.
Which features are available depends on licensing tier—Free, P1, or P2—but the architectural fundamentals of authentication and SSO are present in every Entra ID tenant.
Technical scenario:
An IT admin configures a Conditional Access policy to require MFA for users logging in from outside the corporate network. This policy is enforced by Entra ID before granting access to company SaaS applications.
Understanding Entra ID Tenants: Boundaries and Structure
A Microsoft Entra ID “tenant” is a logically isolated and administratively distinct instance of Entra ID. Tenants are the primary security and operational boundary in Entra ID:
- What’s in a tenant: Users, groups, service principals, app registrations, policies, and sometimes devices.
- Purpose: Each tenant represents one organization, subsidiary, or sandbox. Tenants prevent accidental cross-pollination of users or admin control.
- Lifecycle: Tenants are created on Microsoft cloud subscription, can persist through mergers/divestitures, and are typically tied to specific domain namespaces.
Practical boundaries:
A holding company spins up separate Entra ID tenants for each subsidiary for legal and operational separation. A startup uses a single tenant for all workforce management, application registration, policy, and branding.
Microsoft Entra ID vs. Classic Active Directory: Protocols and Architecture
Key differences:
Protocol support:
- Active Directory uses LDAP and Kerberos as native protocols—core for Windows domain joins, legacy app authentication, and directory synchronization.
- Entra ID does not natively support LDAP/Kerberos/domain join. Instead, it employs OAuth 2.0, OpenID Connect, and SAML, making it suitable for web and SaaS integrations but not for legacy Windows domain-joined environments.
Deployment model:
- Active Directory is on-premises, controlled by domain controllers, and managed in a single or multi-forest topology.
- Entra ID is fully cloud-delivered, multi-tenant, regionally resilient, and has no concept of direct server management.
Identity scope:
- Active Directory serves as a local credential authority and policy store for Windows-based organizational units.
- Entra ID is designed to be perimeterless, supporting hybrid and global access from any device, anywhere, with a focus on SaaS and identity governance.
Integration scenarios:
A modern app integrates with Entra ID directly using OpenID Connect or OAuth. A legacy app requiring LDAP must not point directly to Entra ID; it can only use LDAP if Entra Domain Services is deployed.
Extending Entra ID: Entra Domain Services for LDAP and Kerberos
LDAP requires a separate managed service
Microsoft Entra ID does not expose LDAP or Kerberos endpoints directly. Entra Domain Services is a separately deployed managed service that can provide those protocols for compatible legacy applications.
How it works:
- Entra Domain Services creates a managed domain inside Azure.
- Identities and groups from Entra ID are synchronized to this managed domain.
- LDAP and Kerberos protocols become available for legacy applications, printers, or systems lacking support for modern cloud authentication.
Scenario:
A company’s legacy intranet authenticates users via LDAP. With Entra Domain Services, Entra ID manages user lifecycle, and users can authenticate to the intranet without rewriting the legacy app’s authentication stack.
Trade-offs:
Entra Domain Services is a separate, managed resource (with additional cost and operational boundaries) and does not fully replicate all classic AD features or schema extensions.
What Changed? From Azure AD to Entra ID
In 2023, Microsoft rebranded Azure Active Directory to Microsoft Entra ID. This was a naming and branding change only:
- All technical functionality, login URLs, APIs, and authentication endpoints remain unchanged.
- No migration, reconfiguration, or code changes are required for existing integrations.
- New documentation and Microsoft portals now refer to “Entra ID” in place of Azure AD.
If you see “Entra ID” in your applications or Microsoft’s docs:
This is simply the updated name for the same service previously called Azure AD.
When Entra ID Fits—and When Alternatives Matter
Use Entra ID when:
- Managing corporate/workforce identity across Microsoft 365, Azure, and SaaS apps.
- Implementing SSO, MFA, or Conditional Access for cloud or hybrid workforces.
- Needing secure collaboration with external partners through tenant federation and B2B features.
- Running legacy apps that can tolerate connecting via Entra Domain Services for LDAP/Kerberos.
Entra ID is not always fit when:
- You need consumer/customer identity and access management (CIAM) tailored for public customers, branded portals, or B2C user experiences—Entra ID B2C is a related but distinct product.
- Deep customization is required for non-Microsoft stacks, white-labeling, or proprietary extensibility—third-party platforms like Okta or Auth0 may be preferable.
- Your organization runs entirely on-premises or with legacy software incompatible with modern authentication protocols, and you cannot shift to managed cloud directories.
Architectural Positioning for Practitioners
For practitioners experienced in LDAP and on-prem AD, Microsoft Entra ID represents a paradigm shift:
- It is not a drop-in, protocol-compatible replacement for classic Active Directory.
- It is a cloud-native, SaaS-scale identity perimeter, securing Azure, Microsoft 365, and modern SaaS for both workforce and hybrid environments.
- Administrative boundaries are defined by tenants, which are critical for security, policy, and collaboration.
- LDAP and Kerberos compatibility require deployment of Entra Domain Services—never assume direct LDAP answers from Entra ID itself.
- Azure AD’s rename to Entra ID is cosmetic and does not break existing integrations.
With this mental model, practitioners can accurately map Entra ID’s capabilities and boundaries to real-world directory integration, migration, and modernization scenarios.