Microsoft Entra ID for Beginners: Users, Roles and Access

Microsoft Entra ID helps an organisation decide who can sign in and which applications they can use. For an Azure beginner, the most useful starting point is a simple access question: how can a learner inspect a training resource group without being allowed to change it? Answering that question connects identities, groups, roles and scope.

This guide explains those concepts through a proposed practice lab. You need an authorised training tenant, an Azure subscription and an administrator who can create the required identities and role assignments. Use separate test accounts and non-production resources.

What is Microsoft Entra ID?

Microsoft Entra ID, formerly Azure Active Directory, is Microsoft’s cloud identity and access management service. A tenant is an organisation’s directory boundary. Users and applications have identities within that directory; an Azure subscription is associated with a directory but serves a different purpose in organising resources and billing. Entra ID is part of a wider product family, so a feature carrying the Entra name is not automatically included in every licence. See the Microsoft Entra overview.

Authentication and authorisation are different checks

Authentication establishes who is signing in. Authorisation determines what that identity can do. A successful portal login does not mean that the person can create a virtual machine, view blob contents or assign permissions.

Imagine two learners signing into the same tenant. One needs to inspect a network diagram; another needs to configure the lab. Their login experience can look similar even though their allowed actions differ. Write the required actions first, then select access that supports them.

Microsoft Entra roles versus Azure RBAC roles

Microsoft Entra roles manage directory resources, such as users and groups. Azure role-based access control, or RBAC, manages Azure resources at scopes such as a subscription, resource group or individual resource. A directory administrator is not automatically an administrator of every Azure resource. Microsoft’s role comparison explains this separation.

  • Reader: inspect Azure resource configuration without changing it.
  • Contributor: manage Azure resources, but cannot assign Azure RBAC roles.
  • Owner: manage resources and assign Azure RBAC access at the assigned scope.

A role assignment combines an identity, a role and a scope. A broad subscription assignment may affect far more than a single exercise. Group assignments can simplify access reviews when several learners need the same access. Microsoft’s role assignment guide covers the required permission and portal workflow.

Practice lab: give a learner read-only access

  1. Define the boundary. Use a dedicated resource group such as rg-identity-practice. Record the subscription and tenant so you can recognise a wrong-directory login later.
  2. Prepare the identity. Ask the authorised administrator to create a test learner and a security group named azure-lab-readers, then add the learner to that group.
  3. Assign the role. At the resource group’s Access control (IAM) screen, assign Reader to the test group. Review the group name and scope before saving.
  4. Verify as the learner. Use a separate browser profile. Confirm the learner can inspect an existing lab resource and cannot save an attempted resource change.
  5. Record both outcomes. Note the identity, action, scope, expected result and observed result. An expected denial is evidence that the boundary works.
  6. Clean up deliberately. Remove the test assignment when the exercise finishes. Recheck the learner’s effective access rather than assuming one removed assignment removes every access path.

This is a suggested exercise, not a report of a completed deployment. Your notes should distinguish what you planned from what you actually observed. If a learner can still edit resources, investigate another assignment inherited from a broader scope before adding or removing unrelated roles.

MFA protects sign-in; it does not grant permissions

Multifactor authentication adds another verification factor to sign-in. It does not replace RBAC or turn a Reader into a Contributor. Follow your training tenant’s configured authentication requirements. More advanced policy controls depend on the features and licences available. Microsoft’s MFA overview explains the mechanisms.

Troubleshoot access in a useful order

  • No subscription is visible: confirm the selected tenant, subscription filter and whether the identity has any relevant Azure assignment.
  • The role exists but an action fails: inspect the exact identity and scope, allow for propagation, then refresh the session before retesting.
  • A storage account opens but blobs do not: management access and data access differ. Continue with the Azure Storage guide.
  • An application cannot reach a service: separate identity errors from connectivity errors using the VNet and NSG tutorial.

Build on the lab

Keep an access matrix with four columns: identity, required action, assigned role and scope. Explain why a read-only learner does not need Owner. Next, study how a deployment workflow gets its own identity in the Azure Pipelines and GitHub Actions comparison.

For a broader learning sequence covering identity, networking and administration, review the syllabus on Softenant’s Azure training in Vizag page. Compare the course topics with the specific skills you still need to practise.