← Back to catalog
πŸ“š Series

Azure - Manage Identities and Governance

Who exists in an Azure tenant, what they are allowed to do, and how an estate stays organized, compliant and within budget. Work through the series to gain the judgement to grant the right access at the right scope, and to keep a growing estate under control.

Episodes (11)

  1. 1 Episode 1 β€” The Lay of the Land β€” Tenants, Subscriptions, and the Four Levels of Scope Two planes of administration (the Microsoft Entra tenant vs ARM resources), the four levels of scope and how inheritance flows down them, and how an account, a subscription, and a tenant relate. The map every later episode builds on.
  2. 2 Episode 2 β€” Managing Users in Microsoft Entra ID Microsoft Entra user types (member/guest Γ— internal/external) and how each authenticates; creating, inviting, deleting, and restoring users; profile and bulk management; and the least-privilege role each move requires.
  3. 3 Episode 3 β€” Groups β€” Types, Membership, and Access Security vs Microsoft 365 groups, assigned vs dynamic membership, and group nesting with its opposite behaviors in Microsoft Entra versus Azure RBAC β€” plus the four patterns for granting access through groups.
  4. 4 Episode 4 β€” Licensing β€” Editions and Group-Based Licensing The four Microsoft Entra ID licensing options (Free/P1/P2/Suite) and how each is acquired, which admin features need P1 or P2, and how group-based licensing works β€” with the usage-location, nested-group, and user-move pitfalls.
  5. 5 Episode 5 β€” External Collaboration β€” Microsoft Entra B2B Microsoft Entra B2B collaboration: how guest invitations and redemption work, what the #EXT# guest object really is, and the crucial difference between cross-tenant access settings and external collaboration settings β€” including which one wins.
  6. 6 Episode 6 β€” Self-Service Password Reset (SSPR) Self-service password reset end to end: the reset-flow gates, authentication methods and one-vs-two-method policies, registration and reconfirmation, notifications, on-premises writeback and its licensing, and the separate, stricter administrator policy.
  7. 7 Episode 7 β€” Azure RBAC β€” The Authorization Model The Azure RBAC model: security principal + role definition + scope = role assignment; the permissions math (Actions/NotActions, DataActions), the additive model and group transitivity, deny assignments, and ARM's nine-step evaluation flow.
  8. 8 Episode 8 β€” Azure RBAC in Practice β€” Assigning and Interpreting Access Azure RBAC in practice: assigning roles in the portal (IAM), the five fundamental roles, PIM assignment types (eligible/active, permanent/time-bound), interpreting inherited assignments and Check access, and Azure vs Microsoft Entra vs classic roles.
  9. 9 Episode 9 β€” Organizing the Estate β€” Management Groups, Subscriptions, Resource Groups, and Tags Organizing the estate: the management-group hierarchy and its limits, the root management group, creating subscriptions, the resource-group lifecycle rules, and a tagging taxonomy that respects the real limits, casing rules, and no-inheritance behavior.
  10. 10 Episode 10 β€” Enforcing Standards β€” Azure Policy and Resource Locks Enforcing standards with Azure Policy (definitions, initiatives, effects, evaluation triggers, remediation, compliance) and resource locks (CanNotDelete/ReadOnly, inheritance, control-plane-only gotchas) β€” plus how RBAC, Policy, and locks combine.
  11. 11 Episode 11 β€” Controlling Spend β€” Cost Management, Budgets, Alerts, and Advisor Controlling spend: how charges flow through Cost Management, budgets and their actual/forecasted alert thresholds, the cost alert types (budget, credit, department quota, anomaly), and Azure Advisor's five recommendation categories. Closes the module.