Guide

Entra ID

Identity is the control plane that everything else in this library depends on. The Entra ID series walks the platform from tenant foundations to governance: how identities get in, how they authenticate, how risk is measured, how privilege is granted and reviewed, and how you watch all of it. Conditional Access follows as its own series, because the policy engine that decides every access request needs more room than a chapter inside another guide. Global Secure Access closes the page, where those same policies reach the network. Each series is written to be read in order.

Entra ID Deep Dive

12 articles
E 1Start here
Anchor

Entra ID in 2026: Getting Started and the Baseline You No Longer Set

Microsoft has moved the Entra ID security baseline from recommendations you implement to a floor it enforces. Getting started in 2026 is knowing what is already switched on, and deciding everything the floor does not: privilege, structure, break-glass done the new way, and access that expires.

E 2
Doctrine

Identities and How They Get There

Every account arrived from somewhere, and where it came from decides where you can change it. Source of authority, the three origins of an identity, the Connect-Sync-to-Cloud-Sync transition now underway, and the slow migration of authority to the cloud.

E 3
Doctrine

Tenant Foundations and the Shape of the Directory

The shape of a directory is decided before the first policy and ages badly when improvised. One tenant or several, the population-versus-entitlement group model, and the restricted management administrative unit that protects your core from your own administrators.

E 4
Doctrine

Authentication Methods and the Road to Passwordless

Authentication is becoming a ranking the system enforces, steering every user to their strongest credential and asking for the password only when nothing better exists. One policy, system-preferred authentication, registration as the real work, and retiring the weak on purpose.

E 5
Doctrine

Passkeys, WHfB, and Phishing-Resistant Credentials

A small portfolio of phishing-resistant credentials, held one device-bound and one portable, chosen deliberately.

E 6A calm operator at a watch desk with one amber signal lamp glowing among steady blue indicators.
Doctrine

Identity Protection: Risk as a Signal

A strong credential proves who is signing in; it cannot prove the sign-in is safe. Identity Protection is the sensor for that gap, and its value depends on being honest about what a risk engine can and cannot see.

E 7A vault clerk hands out a single time-limited key through a barred window beside an hourglass.
Doctrine

Privileged Identity Management in Depth

Privilege is the one thing you want people to have and not hold. PIM separates being entitled to a role from possessing it, so power is reached for deliberately, briefly, and on the record.

E 8Hands divide one large ring of keys into several smaller sets across a drafting table.
Doctrine

Roles, Custom Roles, and Delegated Administration

Delegation is giving people exactly the authority their job requires and not a scrap more, because the width of a role assignment is the width of a breach.

E 9A librarian presses a date stamp onto a borrowing card before a bank of catalog drawers.
Doctrine

Entitlement Management: Access as a Governed Object

Most access is granted by hand and never taken back. Entitlement management turns access into a governed object with a requester, an approver, a reason, and an expiry.

E 10A hand stamps a slow-turning carousel of access cards, keeping some and setting others aside.
Doctrine

Access Reviews and Lifecycle Workflows

Access is not an event, it is a lifespan. Access reviews and lifecycle workflows make provisioning, recertification, and deprovisioning something the platform runs rather than something people remember to do.

E 11A gatehouse keeper issues a visitor badge to a traveler who holds their own credentials from elsewhere.
Doctrine

External Identities: B2B, Cross-Tenant Access, and Direct Connect

Bringing an outsider into your directory is a trust decision wearing the clothes of a convenience feature. External identity is deciding how much of someone else's security posture you will inherit as your own.

E 12A night-watch operator reads a long scrolling ledger beside a steady amber health gauge.
Doctrine

Watching Identity: Sign-in Logs, Audit, and Health

Every control produces a record, and a control whose record no one keeps is one you are only assuming works. Watching identity turns the directory's exhaust into something you can alert on and answer questions with later.

Conditional Access

9 articles
CA 1Start here
Anchor

Conditional Access: The Real Control Plane

Why Conditional Access Matters More Than Any Single Policy

CA 2
Doctrine

Conditional Access Frameworks and Policy Design

Once you accept that Conditional Access is the real control plane, the next question is how to organize it, and this is where most…

CA 2.1
Build sheet

Testing Conditional Access: What-If Analysis and Safe Rollout

Two instruments make a Conditional Access change safe: What If for a single hypothetical, and report-only for the whole population. How to use both, read the four report-only results, and promote a policy to enforcement without locking anyone out.

CA 3
Doctrine

Named Locations, Risk Policies, and Identity Protection

Device compliance and authentication strength are the most common inputs to Conditional Access policies. They're not the only ones. Named locations, sign-in risk, user…

CA 4vcio-ca-framework
Doctrine

The VCIO CA Framework

Earlier this year I sat down and took apart the published Conditional Access baselines the way I'd audit a customer tenant. Every policy definition…

CA 4.1
Build sheet

Building the Framework: From Zip to Green Gate

The design paper made the case. This is the part where you actually stand up the framework in a tenant, and it is where…

CA 4.2
Build sheet

Enabling in Rings: An Order That Doesn’t Break Things

At the end of the build you have a tenant full of Conditional Access policies that do nothing. Every one of them is in…

CA 4.3
Build sheet

Day One: TAP, Autopilot, and Protecting the Bootstrap

Most of a Conditional Access deployment is about people who already exist. The harder problem, and the one baselines almost never address, is the…

CA 4.4
Build sheet

Operating the Framework: Exclusions, Reviews, and Drift

A Conditional Access framework is not a project you finish, it is a system you operate. The reviews, the break-glass test nobody wants to run, the monthly drift check, and the change discipline that keeps a snapshot true a year later.

Global Secure Access

4 articles