FinOps Academy · Architecture Explorer

Microsoft Entra Identity Architecture

Design workforce, workload and privileged identity services with resilient authentication and governed access.

Objective: Create an identity control plane that supports modern access while limiting privilege and recovery risk.

Practical guidance

Business context and requirements

01

Map workforce, partners, applications and non-human identities

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Define authentication assurance and lifecycle requirements

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Identify legacy protocols, tenant boundaries and recovery dependencies

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

Practical guidance

Architecture and design decisions

01

Design tenant structure, federation, conditional access and MFA

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Define groups, roles, PIM, access reviews and workload identities

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Integrate applications using modern authentication and managed identities

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

Practical guidance

Security, cost and operating model

01

Protect privileged roles, emergency accounts and audit evidence

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Model licensing and identity-operations capacity

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Establish joiner, mover, leaver and application-onboarding processes

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

Practical guidance

Validation, resilience and evolution

01

Test authentication, access revocation and emergency access

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Validate risky-user, token and privilege monitoring

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Exercise tenant recovery and key identity dependency scenarios

Apply this point to a real FinOps Academy design, delivery or operational scenario and record the evidence used to validate the outcome.