azureblog.co.uk
← cd ~/learn
// glossary

Glossary

54 terms in plain English. In posts, terms with a dotted underline show their definition when you hover over or tap them.

A
AADSTS error (AADSTS)
The prefix for Entra ID sign-in error codes, such as AADSTS50105. Look them up with this site's AADSTS tool.
Access review
An Entra ID Governance feature that asks reviewers to confirm whether people still need access to a group, app or role, and can remove them automatically. Read more →
App registration
The definition of an application in Entra ID: its ID, redirect URIs, credentials and the permissions it asks for.
Authentication context
A label (such as c1) that an app or service like PIM can request at a sensitive moment. A Conditional Access policy targeting the label sets what the user must prove. Read more →
Authentication strength
A Conditional Access grant control that requires specific sign-in methods, such as phishing-resistant MFA, rather than any MFA method. Read more →
Azure Policy
Rules that evaluate Azure resources and can audit, deny or automatically fix them, assigned at management group, subscription or resource group. Read more →
B
B2B collaboration (B2B)
Inviting people from other organisations as guest users, who sign in with their own home identity.
Break-glass account
An emergency cloud-only Global Administrator account, excluded from normal policies and closely monitored, used only when normal admin access fails. Read more →
C
Compliance policy
Intune rules a device must meet, such as encryption or a minimum OS version. Conditional Access can require a compliant device. Read more →
Conditional Access
Entra ID's policy engine. Each policy says: if these users sign in to these apps under these conditions, then require (or block) something, such as MFA or a compliant device. Read more →
CSPM
Cloud security posture management: continuously assessing cloud resources for misconfigurations. Defender for Cloud includes a free and a paid CSPM plan. Read more →
D
DDM
Declarative device management: Apple's newer management model where the device applies and reports on declared settings itself.
DeployIfNotExists (DINE)
An Azure Policy effect that deploys a related resource or setting, such as diagnostic settings, when it's missing. Existing resources need a remediation task.
E
Entra Cloud Sync
Microsoft's lightweight agent-based service for syncing users and groups from Active Directory to Entra ID, configured in the cloud. Read more →
Entra Connect Sync
The traditional server-based tool that syncs Active Directory objects to Entra ID, with configuration held on the server. Read more →
Entra join
A corporate Windows device joined directly to Entra ID, with no on-premises domain membership needed.
Entra registered
A personal device where the user has added a work account. The device gets an identity in the tenant, but the user keeps control of it. Read more →
F
Federated credential
A trust that lets an app sign in with a token from an external identity provider, such as GitHub Actions, instead of a secret or certificate. Read more →
FIDO2
The open standard behind passkeys and security keys, combining WebAuthn in the browser with CTAP for authenticators.
H
Hybrid join
A Windows device joined to on-premises Active Directory and also registered in Entra ID, so it can use device-based Conditional Access. Read more →
J
JWT
JSON Web Token: a signed, base64url-encoded token carrying claims such as audience, issuer and permissions. Entra access and ID tokens are JWTs.
K
Kerberos
The ticket-based authentication protocol used by Active Directory. Entra ID can issue Kerberos tickets for some on-premises scenarios.
Key Vault
Azure's service for storing secrets, keys and certificates, with access controlled by Azure RBAC or legacy access policies. Read more →
KQL
Kusto Query Language: the query language for Log Analytics, Microsoft Sentinel, Defender and Azure Resource Graph. Read more →
L
Lifecycle Workflows
Entra ID Governance automation for joiner, mover and leaver tasks, such as issuing a Temporary Access Pass or removing group memberships.
Log Analytics workspace
Azure Monitor's log store. Entra sign-in and audit logs can be sent there with diagnostic settings and queried with KQL.
M
MAM
Mobile application management: protecting work data inside apps (copy, save and PIN rules) without managing the whole device.
Managed identity
An identity for an Azure resource whose credentials Azure creates and rotates for you, so code can reach other services without any stored secret. Read more →
Management group
A container above subscriptions, used to apply policy and access to many subscriptions at once.
MDM
Mobile device management: enrolling a device so policies, apps and settings can be managed on the whole device.
MFA
Multifactor authentication: proving who you are with more than one factor, such as something you know, something you have, or something you are.
Microsoft Graph
The single API for Microsoft 365, Entra ID and Intune data, also used by the Microsoft Graph PowerShell SDK.
N
Named location
A set of IP ranges or countries saved in Entra ID so Conditional Access policies can include or exclude them. Read more →
O
OpenID Connect (OIDC)
An identity layer on top of OAuth 2.0 that adds sign-in, using JSON Web Tokens (ID tokens) to describe the user.
P
Passkey
A FIDO2 credential made of a key pair. The private key stays on the device or in a password manager and only signs in to the site it was created for. Read more →
Phishing-resistant MFA
Sign-in methods bound to the real site, so they can't be relayed by a fake one: passkeys (FIDO2), Windows Hello for Business and multifactor certificate-based authentication. Read more →
PIM
Privileged Identity Management: users are made eligible for admin roles and activate them only when needed, for a limited time, with justification and checks. Read more →
Private endpoint
A network interface with a private IP in your virtual network that connects to a PaaS service, such as Storage or Key Vault, over Azure's backbone. Read more →
R
RBAC
Role-based access control: permissions granted by assigning roles to users, groups or identities at a scope.
Remediations
Intune script packages: a detection script checks for a problem, and a remediation script fixes it when found. Read more →
Report-only mode
A Conditional Access policy state that evaluates the policy at every sign-in and logs the result, without enforcing it. Used to test impact before switching a policy on. Read more →
Resource lock
A CanNotDelete or ReadOnly setting on an Azure resource, resource group or subscription that applies to everyone, including Owners. Read more →
S
SAML
Security Assertion Markup Language: an XML-based single sign-on standard where Entra ID sends a signed assertion about the user to the app. Read more →
SCIM
System for Cross-domain Identity Management: a standard API that Entra ID uses to create, update and remove users and groups in other apps. Read more →
Service principal
An app's identity inside one tenant. An app registration is the global definition; the service principal is the local instance that gets permissions and signs in. Read more →
Source of Authority
Which directory owns an object's attributes. Converting a synced user's source of authority makes it managed in the cloud instead of in AD. Read more →
SSO
Single sign-on: signing in once with your work account and getting into other apps without another password.
T
Temporary Access Pass (TAP)
A time-limited passcode issued by an admin, used to sign in and register passwordless methods without ever having a password. Read more →
W
What If
A Conditional Access tool that shows which policies would apply to a given user, app and set of conditions, without anyone having to sign in. Read more →
Win32 app
A traditional Windows app packaged as an .intunewin file so Intune can install it with detection rules, dependencies and return codes. Read more →
Windows Autopilot
A way to set up new Windows devices straight from the box: the device joins Entra ID, enrols in Intune and gets its apps and policies.
Windows Hello for Business
Phishing-resistant sign-in to Windows using a PIN or biometrics, backed by a key held in the device's TPM.
Windows LAPS (LAPS)
Local Administrator Password Solution: Windows sets a unique, rotating local admin password on each device and backs it up to Entra ID or AD. Read more →
Workload identity
Any non-human identity, such as an app, service principal or managed identity, that signs in to access resources.