Microsoft Entra ID
Microsoft Entra ID is the identity provider of an Azure tenant: every person, group, application and managed identity that signs in to Azure is an Entra principal. The Azure Enterprise Baseline gives people access only through Entra groups, sends Entra sign-in and audit logs to the audit workspace, and the blueprints authenticate to their data stores with Entra tokens instead of keys.
What it does
Entra ID holds users, groups, service principals (an application's identity in the tenant) and managed identities (service principals whose credentials Azure rotates). It issues the tokens that Azure Resource Manager and the data planes of storage, Key Vault, databases and caches accept. Groups can be cloud-only or synchronized from an external identity provider. Some features depend on the license: Entra ID P1 brings Conditional Access and sign-in logs, Entra ID P2 adds Privileged Identity Management and Identity Protection risk data. A diagnostic setting at tenant level streams Entra's own logs to a Log Analytics workspace or a storage account.
How BuiltForProd uses it
Groups for people. The entra-rbac unit in acme-core-identity works with 14 security groups: 13 role groups and a break-glass group, named with the prefix ACME_:
| Groups | Role in the access model |
|---|---|
ACME_PlatformLeads, ACME_PlatformEngineers | Own the landing zone |
ACME_DevOpsLeads, ACME_DevOpsEngineers | Run the stage subscriptions and clusters |
ACME_LeadAppDevelopers, ACME_AppDevelopers, ACME_LeadETLEngineers, ACME_ETLEngineers, ACME_LeadAIEngineers, ACME_AIEngineers | Build workloads in the lower stages |
ACME_AllEngineers | Read-only view of prod |
ACME_LeadSecurityAuditors, ACME_SecurityAuditors | Read security configuration everywhere |
ACME_BreakGlass | Emergency access, outside Conditional Access |
By default (create_groups = false) the identity provider or the tenant administrators own the groups and the unit only looks them up by display name. Tenants without an external identity provider set create_groups = true, and the unit creates cloud-only security groups. Membership is never managed in code. Each group is mapped to roles by Azure RBAC, and a guardrail policy denies any role assignment to an individual user, so a person's access is exactly the sum of their groups.
Entra logs as audit evidence. The entra-diagnostics unit (acme-core-root, tenant level) creates one diagnostic setting, acme-entra-to-audit, that sends the audit, interactive and non-interactive sign-in, service principal sign-in, managed identity sign-in and provisioning logs to the audit Log Analytics workspace and the immutable audit storage account in acme-core-audit. With include_identity_protection_logs = true (the default) it adds the four Identity Protection risk categories. It is switched by enable_entra_log_export in security.hcl, on by default, and costs the workspace ingestion (about $2.30 per GB, as the unit comment states). The SigninLogs and AuditLogs tables feed the KQL (Kusto Query Language) alerts on failed sign-ins, break-glass sign-ins and Conditional Access changes.
Entra tokens for data. The blueprints turn off key and password authentication wherever the service allows it. The Web App Blueprint's Cosmos DB for MongoDB vCore cluster accepts Microsoft Entra authentication only (the API signs in with MONGODB-OIDC), its Azure Managed Redis cache has access keys disabled, and the Data and ETL Blueprint's lake storage has shared keys turned off. Each workload signs in as its own managed identity.
Licenses. Conditional Access and the sign-in log export need Entra ID P1. PIM (enable_pim) and the risk categories need Entra ID P2 for the users involved.
Terms you will see
| Term | Meaning |
|---|---|
| Tenant | The Entra directory that owns the management groups and subscriptions. |
| Security group | An Entra group that can be assigned Azure roles; the only way people get access. |
create_groups | The switch that creates the ACME_* groups instead of looking them up. |
| Service principal | An application's identity in the tenant. |
| Diagnostic setting | The export of a resource's or the tenant's logs to a workspace or storage. |
| Entra ID P1, P2 | The license levels that unlock Conditional Access, PIM and risk data. |
Where to read more
- Azure Enterprise Baseline overview for the identity subscription and its units.
- Least privilege for the access model the groups implement.
- Azure RBAC and Conditional Access for what the groups are granted and how they sign in.