Identity architecture design

Microsoft Entra ID
Microsoft Entra External ID

Identity and access management (IAM) architectures provide frameworks for protecting data and resources. Internal networks establish security boundaries in on-premises systems. In cloud environments, perimeter networks and firewalls aren't sufficient for managing access to apps and data. Instead, public cloud systems rely on identity solutions for boundary security.

An identity solution controls access to an organization's apps and data. Users, devices, and applications have identities. IAM components support the authentication and authorization of these and other identities. The process of authentication controls who or what uses an account. Authorization controls what that user can do in applications.

Whether you're just starting to evaluate identity solutions or looking to expand your current implementation, Azure offers many options. One example is Microsoft Entra ID, a cloud service that provides identity management and access control capabilities. To decide on a solution, start by learning about this service and other Azure components, tools, and reference architectures.

Architecture diagram that shows Microsoft Entra ID in a cloud environment. Connections to apps, devices, and other components are also visible.

Introduction to identity on Azure

If you're new to IAM, the best place to start is Microsoft Learn. This free online platform offers videos, tutorials, and hands-on training for various products and services.

The following resources can help you learn the core concepts of IAM.

Learning paths


Path to production

After you've covered the fundamentals of identity management, the next step is to develop your solution.


To explore options for identity solutions, consult these resources:


When you've decided on an approach, implementation comes next. For deployment recommendations, see these resources:

Best practices

Suite of baseline implementations

These reference architectures provide baseline implementations for various scenarios:

Stay current with identity

Microsoft Entra ID receives improvements on an ongoing basis.

Additional resources

The following resources provide practical recommendations and information for specific scenarios.

Microsoft Entra ID in educational environments

Information for Amazon Web Services (AWS) and Google Cloud professionals