Skip to main content

Microsoft Entra ID

Microsoft Entra ID is the identity provider of an Azure tenant: every person, group, application and managed identity that signs in to Azure is an Entra principal. The Azure Enterprise Baseline gives people access only through Entra groups, sends Entra sign-in and audit logs to the audit workspace, and the blueprints authenticate to their data stores with Entra tokens instead of keys.

What it does​

Entra ID holds users, groups, service principals (an application's identity in the tenant) and managed identities (service principals whose credentials Azure rotates). It issues the tokens that Azure Resource Manager and the data planes of storage, Key Vault, databases and caches accept. Groups can be cloud-only or synchronized from an external identity provider. Some features depend on the license: Entra ID P1 brings Conditional Access and sign-in logs, Entra ID P2 adds Privileged Identity Management and Identity Protection risk data. A diagnostic setting at tenant level streams Entra's own logs to a Log Analytics workspace or a storage account.

How BuiltForProd uses it​

Groups for people. The entra-rbac unit in acme-core-identity works with 14 security groups: 13 role groups and a break-glass group, named with the prefix ACME_:

GroupsRole in the access model
ACME_PlatformLeads, ACME_PlatformEngineersOwn the landing zone
ACME_DevOpsLeads, ACME_DevOpsEngineersRun the stage subscriptions and clusters
ACME_LeadAppDevelopers, ACME_AppDevelopers, ACME_LeadETLEngineers, ACME_ETLEngineers, ACME_LeadAIEngineers, ACME_AIEngineersBuild workloads in the lower stages
ACME_AllEngineersRead-only view of prod
ACME_LeadSecurityAuditors, ACME_SecurityAuditorsRead security configuration everywhere
ACME_BreakGlassEmergency access, outside Conditional Access

By default (create_groups = false) the identity provider or the tenant administrators own the groups and the unit only looks them up by display name. Tenants without an external identity provider set create_groups = true, and the unit creates cloud-only security groups. Membership is never managed in code. Each group is mapped to roles by Azure RBAC, and a guardrail policy denies any role assignment to an individual user, so a person's access is exactly the sum of their groups.

Entra logs as audit evidence. The entra-diagnostics unit (acme-core-root, tenant level) creates one diagnostic setting, acme-entra-to-audit, that sends the audit, interactive and non-interactive sign-in, service principal sign-in, managed identity sign-in and provisioning logs to the audit Log Analytics workspace and the immutable audit storage account in acme-core-audit. With include_identity_protection_logs = true (the default) it adds the four Identity Protection risk categories. It is switched by enable_entra_log_export in security.hcl, on by default, and costs the workspace ingestion (about $2.30 per GB, as the unit comment states). The SigninLogs and AuditLogs tables feed the KQL (Kusto Query Language) alerts on failed sign-ins, break-glass sign-ins and Conditional Access changes.

Entra tokens for data. The blueprints turn off key and password authentication wherever the service allows it. The Web App Blueprint's Cosmos DB for MongoDB vCore cluster accepts Microsoft Entra authentication only (the API signs in with MONGODB-OIDC), its Azure Managed Redis cache has access keys disabled, and the Data and ETL Blueprint's lake storage has shared keys turned off. Each workload signs in as its own managed identity.

Licenses. Conditional Access and the sign-in log export need Entra ID P1. PIM (enable_pim) and the risk categories need Entra ID P2 for the users involved.

Terms you will see​

TermMeaning
TenantThe Entra directory that owns the management groups and subscriptions.
Security groupAn Entra group that can be assigned Azure roles; the only way people get access.
create_groupsThe switch that creates the ACME_* groups instead of looking them up.
Service principalAn application's identity in the tenant.
Diagnostic settingThe export of a resource's or the tenant's logs to a workspace or storage.
Entra ID P1, P2The license levels that unlock Conditional Access, PIM and risk data.

Where to read more​