Who is Microsoft in the context of Identity & Governance?
Microsoft is one of the world’s leading technology providers and offers a comprehensive product family for identity and network access with Microsoft Entra. In the IAM space, Microsoft is particularly relevant through Microsoft Entra ID, the successor to Azure Active Directory.
Microsoft Entra bundles solutions for identity management, single sign-on, multi-factor authentication, Conditional Access, Identity Governance, external identities, decentralized identity credentials, and identity-centric network access. This allows Microsoft to address core requirements of modern enterprises: secure access, Zero Trust, hybrid work, cloud transformation, compliance, and the management of human and non-human identities.
For many organizations, Microsoft Entra is now a central component of the identity architecture. The platform is closely integrated with Microsoft 365, Azure, Microsoft Defender, Microsoft Purview, Microsoft Sentinel, and other Microsoft security services. At the same time, Microsoft Entra can also be integrated with third-party applications, SaaS services, on-premises systems, and existing IAM or IGA solutions.
Which Identity & Access Management solutions does the Microsoft portfolio include?
In the IAM context, Microsoft Entra is the main focus for Microsoft. The product family includes core solutions for identity management, authentication, single sign-on, multi-factor authentication, Conditional Access, Identity Governance, external identities, and decentralized identity credentials.
For IPG, Microsoft Entra ID, Microsoft Entra ID Governance, Microsoft Entra ID Protection, Microsoft Entra External ID, and Microsoft Entra Verified ID are particularly relevant. These building blocks help organizations manage identities centrally, secure access, control permissions, and make identity processes traceable.
- Microsoft Entra ID – central identity platform for enterprises
Microsoft Entra ID is the new name for Azure Active Directory and forms the central identity and access solution for Microsoft cloud and SaaS environments. Organizations use Entra ID for user management, authentication, single sign-on, multi-factor authentication, Conditional Access, and application security.
The solution is especially relevant for organizations using Microsoft 365, Azure, Teams, SharePoint, Exchange Online, or other cloud services. Entra ID serves as the central trust foundation for users, groups, devices, applications, and policies.
For organizations with hybrid landscapes, Entra ID also serves as the bridge between local infrastructure and the cloud. Identities from existing directory services can be connected and used for modern cloud access scenarios.
- Conditional Access – context-based access control
Conditional Access is a core security component of Microsoft Entra ID. It allows organizations to control access based on user, device, location, risk, application, and other contextual information.
This makes it possible to put Zero Trust principles into practice: access is not granted across the board but is checked based on context. Policies for multi-factor authentication, device compliance, risk-based sign-in, privileged accounts, and sensitive applications are especially relevant.
- Microsoft Entra ID Governance – lifecycle, access reviews, and entitlement management
Microsoft Entra ID Governance helps organizations manage identities and access across their entire lifecycle. This includes lifecycle workflows, access reviews, entitlement management, and functions for the privileged access lifecycle.
This enables organizations to further automate joiner, mover, and leaver processes, provide access packages, regularly review permissions, and ensure that users retain only the access they actually need. These functions are particularly relevant for Identity Governance & Administration, access reviews, recertifications, and compliance requirements.
- Microsoft Entra ID Protection – risk-based identity security
Microsoft Entra ID Protection detects identity-related risks and helps organizations more quickly identify compromised accounts, risky sign-ins, and unusual access patterns.
Combined with Conditional Access, risk-based policies can be implemented. For example, additional authentication requirements, password changes, or access restrictions can be triggered when an elevated risk is detected.
Microsoft Entra External ID supports scenarios involving external identities. This includes B2B collaboration with business partners, guest users, and external organizations, as well as CIAM scenarios for customer identities.
This allows organizations to securely integrate external users into applications and resources without having to build a classic internal identity for every external person. This is especially relevant for partner portals, supplier platforms, B2B collaboration, and customer-facing applications.
- Microsoft Entra Verified ID – verifiable digital identity credentials
Microsoft Entra Verified ID supports decentralized identity credentials and verifiable credentials. Organizations can use it to digitally issue, verify, and manage identity information or proof of qualification.
This is especially relevant for scenarios in which identity, qualification, affiliation, or authorization need to be verifiably and minimally disclosed. Examples include external staff, partners, certifications, training records, or onboarding processes.
When and in which scenarios does it make sense to use Microsoft Entra?
Microsoft Entra is especially suitable for organizations that want to centralize and modernize their identity and access control. Typical use cases include single sign-on for applications, multi-factor authentication, Conditional Access, Identity Governance, access reviews, automated lifecycle processes, and the management of external identities.
Microsoft Entra also makes sense when existing Active Directory structures need to be connected with modern cloud identities.
Why is Microsoft Entra relevant for compliance and regulation?
Organizations must be able to demonstrate who is allowed to access which applications, data, and systems, how that access was approved, and whether permissions are reviewed regularly. Microsoft Entra supports these requirements through centralized identity management, Conditional Access, MFA, risk-based access control, access reviews, entitlement management, and audit functions.
Microsoft Entra ID Governance is especially important here. Organizations can use it to manage access packages, recertifications, lifecycle workflows, and privileged access scenarios in a more structured way. This makes it easier to better support compliance requirements from ISO 27001, DORA, NIS2, internal control systems, and industry-specific requirements.
How does Microsoft Entra differ from other providers?
Microsoft Entra stands out for its deep integration into existing Microsoft environments. For organizations using Microsoft 365 or Azure, Entra is often already a core part of the IAM architecture.
A key advantage lies in combining identity, access control, and governance functions within a single platform. Organizations can manage authentication, access, and governance consistently.
Another difference is the breadth of the IAM portfolio. Microsoft Entra covers both fundamental IAM functions such as SSO and MFA, as well as Identity Governance, external identities, and digital identity credentials.
However, it is important to note: Microsoft Entra does not automatically replace a specialized IGA, PAM, or CIEM solution in every organization. Especially in heterogeneous, highly regulated, or complex multi-vendor environments, a sound architecture decision is required. IPG helps organizations position Microsoft Entra sensibly within their existing IAM and security landscape.
How is the Microsoft Entra licensing model structured?
Microsoft Entra is licensed on a modular basis. Many basic functions are closely tied to Microsoft 365, Entra ID, and Azure. Advanced functions such as Conditional Access, Identity Protection, Identity Governance, External ID, Verified ID, Private Access, Internet Access, or the Microsoft Entra Suite depend on the respective licensing model and feature scope.
In practice, Microsoft Entra ID P1, Microsoft Entra ID P2, Microsoft Entra ID Governance, and the Microsoft Entra Suite often play a role. Which license makes sense depends on the desired features, user groups, governance requirements, Zero Trust goals, and existing Microsoft contracts.
IPG helps organizations evaluate their existing Microsoft licenses, identify the functions they need, and develop a licensing and architecture strategy that sensibly balances cost, security, and governance requirements.
Which operating models does Microsoft Entra support
Microsoft Entra is a cloud-based platform and is operated as a Microsoft cloud service. At the same time, Entra supports hybrid identity architectures in which local directory services, applications, and infrastructure are connected with cloud identities.
Organizations can integrate Entra ID with existing Active Directory environments, Microsoft 365, Azure, SaaS applications, on-premises applications, and third-party systems. Entra Private Access and Entra Internet Access extend this architecture with identity-centric access to private and internet-based resources.
This makes Microsoft Entra especially suitable for organizations that want to combine hybrid work, cloud transformation, Zero Trust, and modern IAM processes.
IPG is your Microsoft Identity specialist
IPG is not a classic Microsoft partner, but a focused identity expert with deep know-how in the Microsoft Identity stack. We advise on, implement, and operate Entra ID Governance in demanding environments – from analysis and process definition through technical integration to operation as part of a managed service.
We also bring our experience with hybrid IAM landscapes – particularly when combining Microsoft with third-party providers such as One Identity, BeyondTrust, or Ping Identity. This makes us the ideal partner for customers who use Microsoft strategically but don’t want to compromise on governance, integration depth, or process automation. For deeper Microsoft expertise, we draw on our sister company novaCapta.
Successful customer projects
IPG supports organizations with Microsoft Entra projects across different industries and starting points. Common focus areas include modernizing existing Active Directory and Azure AD structures, introducing Conditional Access and MFA, implementing access reviews, integrating SaaS applications, or securing external identities.
Customer projects often focus on making better use of existing Microsoft investments while building a sustainable governance structure. Organizations benefit from stronger access security, better control options, reduced risk from over-privileged accounts, and a stronger foundation for Zero Trust.
Learn more!
Do you want to use Microsoft Entra efficiently for Identity & Access Management in your organization?
IPG supports you with consulting, architecture, implementation, and operation of modern IAM solutions based on Microsoft Entra.