← cd ~/learn
// glossary
Glossary
54 terms in plain English. In posts, terms with a dotted underline show their definition when you hover over or tap them.
- AADSTS error (AADSTS)
- The prefix for Entra ID sign-in error codes, such as AADSTS50105. Look them up with this site's AADSTS tool.
- Access review
- An Entra ID Governance feature that asks reviewers to confirm whether people still need access to a group, app or role, and can remove them automatically. Read more →
- App registration
- The definition of an application in Entra ID: its ID, redirect URIs, credentials and the permissions it asks for.
- Authentication context
- A label (such as c1) that an app or service like PIM can request at a sensitive moment. A Conditional Access policy targeting the label sets what the user must prove. Read more →
- Authentication strength
- A Conditional Access grant control that requires specific sign-in methods, such as phishing-resistant MFA, rather than any MFA method. Read more →
- Azure Policy
- Rules that evaluate Azure resources and can audit, deny or automatically fix them, assigned at management group, subscription or resource group. Read more →
- B2B collaboration (B2B)
- Inviting people from other organisations as guest users, who sign in with their own home identity.
- Break-glass account
- An emergency cloud-only Global Administrator account, excluded from normal policies and closely monitored, used only when normal admin access fails. Read more →
- Compliance policy
- Intune rules a device must meet, such as encryption or a minimum OS version. Conditional Access can require a compliant device. Read more →
- Conditional Access
- Entra ID's policy engine. Each policy says: if these users sign in to these apps under these conditions, then require (or block) something, such as MFA or a compliant device. Read more →
- CSPM
- Cloud security posture management: continuously assessing cloud resources for misconfigurations. Defender for Cloud includes a free and a paid CSPM plan. Read more →
- DDM
- Declarative device management: Apple's newer management model where the device applies and reports on declared settings itself.
- DeployIfNotExists (DINE)
- An Azure Policy effect that deploys a related resource or setting, such as diagnostic settings, when it's missing. Existing resources need a remediation task.
- Entra Cloud Sync
- Microsoft's lightweight agent-based service for syncing users and groups from Active Directory to Entra ID, configured in the cloud. Read more →
- Entra Connect Sync
- The traditional server-based tool that syncs Active Directory objects to Entra ID, with configuration held on the server. Read more →
- Entra join
- A corporate Windows device joined directly to Entra ID, with no on-premises domain membership needed.
- Entra registered
- A personal device where the user has added a work account. The device gets an identity in the tenant, but the user keeps control of it. Read more →
- Federated credential
- A trust that lets an app sign in with a token from an external identity provider, such as GitHub Actions, instead of a secret or certificate. Read more →
- FIDO2
- The open standard behind passkeys and security keys, combining WebAuthn in the browser with CTAP for authenticators.
- Hybrid join
- A Windows device joined to on-premises Active Directory and also registered in Entra ID, so it can use device-based Conditional Access. Read more →
- JWT
- JSON Web Token: a signed, base64url-encoded token carrying claims such as audience, issuer and permissions. Entra access and ID tokens are JWTs.
- Kerberos
- The ticket-based authentication protocol used by Active Directory. Entra ID can issue Kerberos tickets for some on-premises scenarios.
- Key Vault
- Azure's service for storing secrets, keys and certificates, with access controlled by Azure RBAC or legacy access policies. Read more →
- KQL
- Kusto Query Language: the query language for Log Analytics, Microsoft Sentinel, Defender and Azure Resource Graph. Read more →
- Lifecycle Workflows
- Entra ID Governance automation for joiner, mover and leaver tasks, such as issuing a Temporary Access Pass or removing group memberships.
- Log Analytics workspace
- Azure Monitor's log store. Entra sign-in and audit logs can be sent there with diagnostic settings and queried with KQL.
- MAM
- Mobile application management: protecting work data inside apps (copy, save and PIN rules) without managing the whole device.
- Managed identity
- An identity for an Azure resource whose credentials Azure creates and rotates for you, so code can reach other services without any stored secret. Read more →
- Management group
- A container above subscriptions, used to apply policy and access to many subscriptions at once.
- MDM
- Mobile device management: enrolling a device so policies, apps and settings can be managed on the whole device.
- MFA
- Multifactor authentication: proving who you are with more than one factor, such as something you know, something you have, or something you are.
- Microsoft Graph
- The single API for Microsoft 365, Entra ID and Intune data, also used by the Microsoft Graph PowerShell SDK.
- Named location
- A set of IP ranges or countries saved in Entra ID so Conditional Access policies can include or exclude them. Read more →
- OpenID Connect (OIDC)
- An identity layer on top of OAuth 2.0 that adds sign-in, using JSON Web Tokens (ID tokens) to describe the user.
- Passkey
- A FIDO2 credential made of a key pair. The private key stays on the device or in a password manager and only signs in to the site it was created for. Read more →
- Phishing-resistant MFA
- Sign-in methods bound to the real site, so they can't be relayed by a fake one: passkeys (FIDO2), Windows Hello for Business and multifactor certificate-based authentication. Read more →
- PIM
- Privileged Identity Management: users are made eligible for admin roles and activate them only when needed, for a limited time, with justification and checks. Read more →
- Private endpoint
- A network interface with a private IP in your virtual network that connects to a PaaS service, such as Storage or Key Vault, over Azure's backbone. Read more →
- RBAC
- Role-based access control: permissions granted by assigning roles to users, groups or identities at a scope.
- Remediations
- Intune script packages: a detection script checks for a problem, and a remediation script fixes it when found. Read more →
- Report-only mode
- A Conditional Access policy state that evaluates the policy at every sign-in and logs the result, without enforcing it. Used to test impact before switching a policy on. Read more →
- Resource lock
- A CanNotDelete or ReadOnly setting on an Azure resource, resource group or subscription that applies to everyone, including Owners. Read more →
- SAML
- Security Assertion Markup Language: an XML-based single sign-on standard where Entra ID sends a signed assertion about the user to the app. Read more →
- SCIM
- System for Cross-domain Identity Management: a standard API that Entra ID uses to create, update and remove users and groups in other apps. Read more →
- Service principal
- An app's identity inside one tenant. An app registration is the global definition; the service principal is the local instance that gets permissions and signs in. Read more →
- Source of Authority
- Which directory owns an object's attributes. Converting a synced user's source of authority makes it managed in the cloud instead of in AD. Read more →
- SSO
- Single sign-on: signing in once with your work account and getting into other apps without another password.
- Temporary Access Pass (TAP)
- A time-limited passcode issued by an admin, used to sign in and register passwordless methods without ever having a password. Read more →
- What If
- A Conditional Access tool that shows which policies would apply to a given user, app and set of conditions, without anyone having to sign in. Read more →
- Win32 app
- A traditional Windows app packaged as an .intunewin file so Intune can install it with detection rules, dependencies and return codes. Read more →
- Windows Autopilot
- A way to set up new Windows devices straight from the box: the device joins Entra ID, enrols in Intune and gets its apps and policies.
- Windows Hello for Business
- Phishing-resistant sign-in to Windows using a PIN or biometrics, backed by a key held in the device's TPM.
- Windows LAPS (LAPS)
- Local Administrator Password Solution: Windows sets a unique, rotating local admin password on each device and backs it up to Entra ID or AD. Read more →
- Workload identity
- Any non-human identity, such as an app, service principal or managed identity, that signs in to access resources.
A
B
C
D
E
F
H
J
K
L
M
N
O
P
R
S
T
W
No terms match.