← Identity & access
Lesson 1 of 39 min

Entra ID: users, groups, roles

Identity is the perimeter. Everything else — files, mail, apps — hangs off the account.

Microsoft Entra ID (formerly Azure Active Directory) holds users, groups, roles, devices and application registrations. In a small business it is the single most valuable thing you administer: compromise the identity and every cloud service falls with it, regardless of how good the firewall is.

Use groups for everything. Security groups drive file permissions, application access and licence assignment. Microsoft 365 groups add a mailbox and site. Dynamic groups can populate from attributes such as department, which is powerful once your user data is clean — and misleading before then.

Roles must be scarce. Global Administrator should be held by two accounts, both dedicated admin accounts, neither used for daily email. Give day-to-day work the least privileged role that fits: User Administrator, Exchange Administrator, Helpdesk Administrator. The owner running their whole business from a Global Admin account is the single most common small-business identity finding.

Break-glass accounts matter: one cloud-only account with a long stored password, excluded from conditional access, used only when normal admin access fails. Without it, a bad policy can lock you out of the tenant you are responsible for.

Key takeaways

Areas to show initiative · +15 XP each

Next: MFA and conditional access that people accept →