icon icon

Microsoft Entra (formerly Azure Active Directory)

icon

Training process

Training needs analysis

If you have specific requirements regarding the training programme, we will carry out a training needs analysis for you. This will guide us on which aspects of the programme should receive greater emphasis, so that the training programme meets your specific needs.

What will you gain?

icon

Confident Entra rollout - You will understand how Microsoft Entra evolved from Azure AD and where it fits in the Microsoft ecosystem, so you can plan identity services in your organization with more confidence.

icon

Efficient user management - You will learn how to create users, configure groups and roles, and synchronize accounts from Active Directory, helping you organize access structures and reduce admin mistakes.

icon

Secure sign-in and SSO - You will configure MFA, SSO, federation, and SSPR, so you can strengthen sign-in security for users while making everyday access to apps and services much simpler.

icon

Stronger access protection - You will learn how to use RBAC, Conditional Access, and Identity Protection to reduce account takeover risk, enforce proper access rules, and respond to threats more effectively.

icon

App and protocol integration - You will master app registration and work with OAuth 2.0, OpenID Connect, and SAML, enabling you to integrate internal and SaaS applications with Microsoft Entra ID efficiently.

icon

Device and identity control - You will understand the differences between Entra Join, Hybrid Join, and Registration, and connect access decisions with device compliance and Intune for hybrid work scenarios.

icon

Effective monitoring and troubleshooting - You will learn how to analyze audit logs and sign-in logs and troubleshoot access issues, allowing you to resolve incidents faster and prepare more effectively for security reviews.

icon

Automation and best practices - You will explore Zero Trust and use PowerShell and Microsoft Graph API to automate admin tasks, standardize configurations, and scale access management across your environment.

Training programme

1. Microsoft Entra ID architecture and advanced identity management

  • Microsoft Entra ID architecture and the service's place in the Microsoft ecosystem,
  • tenant, subscriptions, directories and dependencies between services,
  • designing the identity model for cloud and hybrid environments,
  • best practices for administration and separation of privileges,
  • overview of Microsoft Entra services and their applications in the organization.

2. Identity synchronization – Microsoft Entra Cloud Sync and hybrid environments

  • Microsoft Entra Cloud Sync as a modern approach to identity synchronization,
  • differences between Microsoft Entra Cloud Sync and Microsoft Entra Connect Sync,
  • configuration and management of Cloud Sync agents,
  • synchronization of users, groups and selected attributes,
  • filtering the synchronization scope and attribute mapping,
  • diagnostics of synchronization errors and monitoring,
  • migration scenarios from existing synchronization mechanisms.

3. Advanced authentication and phishing-resistant methods

  • Multi-Factor Authentication – design and implementation,
  • Authentication Methods Policy,
  • passwordless authentication,
  • Windows Hello for Business,
  • FIDO2 Security Keys and passkeys,
  • Temporary Access Pass,
  • designing a secure authentication strategy for different user groups,
  • limiting the use of older and less secure authentication methods.

4. Conditional Access – designing advanced access policies

  • architecture and operating mechanism of Conditional Access,
  • designing policies for users, administrators, devices and applications,
  • use of conditions: location, device, application, risk level and sign-in context,
  • Authentication Strengths and enforcing specific authentication methods,
  • policies for privileged and administrative accounts,
  • blocking legacy authentication,
  • designing policies in accordance with the Zero Trust principle,
  • Report-only mode, testing and safe implementation of changes,
  • preventing administrator lockout and use of emergency accounts,
  • analysis of typical configuration errors and Conditional Access best practices.

5. Microsoft Entra ID Protection and identity risk management

  • User Risk and Sign-in Risk,
  • detection of suspicious sign-ins and compromised accounts,
  • automatic responses to high-risk events,
  • integration of Identity Protection with Conditional Access,
  • Risk-based Conditional Access,
  • analysis of alerts and security events,
  • incident response process related to identity,
  • best practices for reducing the risk of account compromise.

6. Microsoft Entra ID Governance – identity and access lifecycle management

  • Microsoft Entra ID Governance architecture,
  • Lifecycle Workflows – automation of Joiner, Mover, Leaver processes,
  • Entitlement Management and Access Packages,
  • resource catalogs and delegation of access management,
  • Access Reviews – periodic verification of access,
  • automatic expiration of unnecessary permissions,
  • management of external users and B2B access,
  • design of the process of granting, reviewing and revoking access,
  • use of Governance to fulfill audit and compliance requirements.

7. Privileged Identity Management and securing privileged accounts

  • Microsoft Entra Privileged Identity Management (PIM),
  • eligible and active roles,
  • Just-In-Time permission activation,
  • requiring MFA, justification and approval during role activation,
  • limiting the duration of possessing high privileges,
  • alerts regarding privileged roles,
  • Access Reviews for administrative accounts,
  • designing an administration model compliant with the least privilege principle,
  • best practices for securing Global Administrator and other critical roles.

8. Managing applications, Enterprise Applications and access to services

  • Application Registrations and Enterprise Applications,
  • differences between an application, Service Principal and Managed Identity,
  • OAuth 2.0, OpenID Connect and SAML in practice,
  • Single Sign-On configuration,
  • delegated and application API permissions,
  • admin consent and management of user consents,
  • limiting excessive application permissions,
  • Managed Identities for Azure resources,
  • risk analysis of applications with high permissions,
  • secure integration of applications with Microsoft Graph.

9. Devices, Intune and access compliant with the Zero Trust model

  • Microsoft Entra Join, Hybrid Join and Entra Registered,
  • device identity management,
  • integration of Microsoft Entra ID with Microsoft Intune,
  • Device Compliance as an element of Conditional Access policies,
  • access to resources exclusively from devices meeting the organization's requirements,
  • BYOD and corporate device scenarios,
  • designing user–device–application access policies,
  • application of Zero Trust principles in practical organizational scenarios.

10. Monitoring, troubleshooting, automation and security best practices

  • Sign-in Logs and Audit Logs – advanced event analysis,
  • diagnostics of issues with authentication, SSO and Conditional Access,
  • analysis of the operation of Conditional Access policies for a specific user,
  • monitoring of administrative changes and privileged operations,
  • use of Microsoft Graph and PowerShell for managing Microsoft Entra ID,
  • automation of bulk changes and reporting,
  • preparation of the environment for a security audit,
  • review of the most common configuration errors,
  • building a Microsoft Entra ID security checklist,
  • recommendations regarding environment hardening and further development of security policies.

What are the prerequisites for participating in the training?

icon

Basic IT administration - You should be comfortable with core system administration concepts and user account management so you can easily follow roles, permissions, and access-related processes.

icon

Microsoft environment familiarity - It will help if you know the basics of Microsoft 365, Azure, or Windows Server, because the training refers to services, directories, and integrations used in these environments.

icon

Networking and authentication basics - You should understand the basics of networking, sign-in, and access control so you can work more easily with topics such as SSO, MFA, identity federation, and Conditional Access.

icon

Experience with users and groups - It is useful if you have experience managing users, groups, or permissions in a business environment, because you will move from theory to practical configuration more quickly.