Microsoft-Services · Glossar

Microsoft Entra ID

Der neue Name (seit 2023) für Azure Active Directory — Microsofts Cloud-basierter Identity-Provider. Die Grundlage für jede moderne Microsoft-Umgebung: SSO, MFA, Conditional Access, Device Identity.

Auf einen Blick
2023
Rebranding von Azure AD
Cloud IdP
SAML, OIDC, OAuth 2.0
SSO
Für 10.000+ SaaS-Apps
Free bis P2
Editions

Was ist Microsoft Entra ID?

Microsoft Entra ID ist Microsofts Cloud-basierter Identity- und Access-Management-Service (IAM). Er verwaltet Benutzer, Gruppen, Rollen, Gerätezuordnungen und die Authentifizierung gegen tausende Cloud- und On-Prem-Anwendungen.

Entra ID ist das Fundament jeder modernen Microsoft-Umgebung. Microsoft 365, Azure, Dynamics, aber auch Drittanbieter-Apps wie Salesforce, Workday, Zoom nutzen Entra ID für Login und Autorisierung.

Nicht verwechseln: Entra ID ist nicht dasselbe wie klassisches on-prem Active Directory (AD DS). Es nutzt andere Protokolle (SAML/OAuth statt Kerberos/LDAP) und ist von Grund auf cloud-nativ. Die beiden können aber synchronisiert werden (Entra Connect).

Entra ID Editionen

EditionWas ist drinIn welchen Lizenzen
Entra ID FreeBasic SSO, Security DefaultsM365 Apps for Business
Entra ID P1Conditional Access, MFA, Group-based App AccessM365 E3, A3, Business Premium
Entra ID P2Identity Protection, PIM, Risk-based PoliciesM365 E5, A5
Entra ID GovernanceAccess Reviews, Entitlement ManagementAdd-on, auch zu E5
External ID (B2B/B2C)Gastzugänge, Partner-Integration, Custom AppsSeparate Lizenzierung

Die 3 Wege, wie Geräte zu Entra ID joinen

Join-TypWannBedeutung
Entra RegisteredBYOD, persönliche GeräteGerät kennt Entra, aber User-Login bleibt lokal
Hybrid Entra JoinedKlassische on-prem AD + EntraGerät in beiden Verzeichnissen
Entra JoinedModerner Workplace, Cloud-firstNur Entra — kein on-prem AD nötig

Entra Joined ist die Zukunft

Microsoft empfiehlt für neue Setups klar Entra Joined. Alle Features wie Windows Hello, Autopilot, Intune, Conditional Access funktionieren nativ. On-Prem AD wird nur noch für Legacy-Anwendungen (Kerberos-Apps, Fileserver) gebraucht.

Für AVD relevant: Seit 2023 können AVD Session Hosts Entra-Joined sein. Das bedeutet: kein on-prem AD mehr nötig, keine Hybrid-Setup-Komplexität. Das vereinfacht AVD-Deployments massiv.

Hybrid-Szenarien: Entra Connect

Die meisten Unternehmen haben noch klassisches Active Directory on-prem. Die Brücke zu Entra ID schlägt Microsoft Entra Connect (früher „Azure AD Connect“):

  • Password Hash Sync — Passwörter werden aus on-prem AD gehasht nach Entra synchronisiert
  • Pass-Through Authentication — Login wird in Echtzeit gegen on-prem AD geprüft
  • Federation mit ADFS — für komplexe Policies (zunehmend deprecated)

Entra Connect Sync läuft alle 30 Minuten — Änderungen in on-prem AD sind also zeitnah in Entra sichtbar. Neu seit 2023: Entra Cloud Sync als Cloud-gehostete Alternative ohne lokalen Sync-Server.

Entra ID in der DaaS-Welt

Windows 365

Windows 365 Cloud-PCs müssen in Entra ID (oder Hybrid) sein. Ohne Entra geht Windows 365 gar nicht.

Azure Virtual Desktop

AVD unterstützt alle 3 Join-Typen:

  • Hybrid AD DS — klassisch, Domain-Controller on-prem oder Azure AD DS
  • Entra Joined — modern, nur Cloud-Identitäten, seit 2023
  • Gemischt — unterschiedliche Host Pools mit verschiedenen Join-Typen

Identitäts-Features für DaaS

  • Single Sign-On (SSO) — ein Login für AVD, W365, M365, und alle verbundenen Apps
  • MFA — zusätzliche Absicherung der Sessions
  • Conditional Access — z.B. „AVD nur aus Deutschland, ohne gejailbreakte Geräte“
  • Windows Hello for Business — passwortloser Login in Cloud-PCs

Entra-ID-Patterns in DaaS Maps

Die DaaS Maps zeigen Entra-ID-Integration-Patterns für moderne DaaS-Setups. Für Diskussionen zu Identity-Strategien im Microsoft-Umfeld trefft ihr mich auf LinkedIn.