Design modern access across workforce, external, workload, and agent identities using explicit trust, Conditional Access, continuous evaluation, and protected actions.
Treat identity as a control plane
Design Microsoft Entra ID for workforce, partner, application, hybrid, and multicloud access. Define authoritative identity sources, lifecycle events, authentication strength, recovery, and monitoring before assigning resource permissions.
Modernize authentication and authorization
Prefer phishing-resistant authentication for privileged and high-risk users. Conditional Access combines identity, device, location, application, and risk signals. Continuous access evaluation can react to critical events during a session. Protected actions add stronger policy to sensitive administrative operations.
Design external and decentralized identity
For B2B access, decide who can invite guests, which partner trust settings apply, how access is reviewed, and how it is removed. Decentralized identity can support verifiable claims, but resource authorization still belongs to the relying service.
Govern agent identities
Microsoft Entra Agent ID provides identities for agents. Separate an agent's identity from its human sponsor and from the identities of tools it invokes. Apply Conditional Access where supported, narrow permissions, short-lived credentials, owner accountability, and monitoring for unusual actions.
Harden legacy identity
Active Directory Domain Services still requires tiered administration, protected credentials, secure domain controllers, patching, monitoring, and recovery. Hybrid identity connects two control planes, so compromise paths must be evaluated in both directions.