entra-id
Microsoft Entra ID — identity platform & detection
This skill encodes the identity-platform tribal knowledge for Microsoft Entra ID (formerly Azure AD) — the central identity provider for Microsoft 365, Azure, and thousands of SaaS applications. It covers the platform's architecture, telemetry surfaces, security features, and attack detection patterns.
Use this skill when working with:
- Authentication telemetry — sign-in logs, audit logs, risk detections
- Identity attacks — password spray, AiTM, MFA fatigue, token theft, OAuth abuse
- Directory security — role assignments, Conditional Access, PIM, app registrations
- Cross-tenant scenarios — B2B guest access, cross-tenant synchronisation, external identities
- Workload identities — service principals, managed identities, federated credentials
Naming: "Azure AD" was renamed to "Microsoft Entra ID" in July 2023. The diagnostic log categories retain the legacy names (
SigninLogs,AADNonInteractiveUserSignInLogs,AuditLogs). These names are used by Sentinel, but the same data is available in any SIEM via Event Hubs, Graph API, or diagnostic settings — field names and schemas are identical regardless of destination. This skill uses "Entra ID" for the product and the canonical log category names throughout.
0. Entra ID architecture overview
Entra ID is a multi-tenant, cloud-based identity and access management service. Every Microsoft 365 and Azure subscription has an Entra ID tenant. Key concepts: