An Architectural Taxonomy & Service Coverage Map for Enterprise Identity Engineering
Authored by Steven Tuschman | Identity Security Engineer
This repository establishes a comprehensive control plane capability matrix across the Microsoft Entra ID ecosystem. Derived from the Microsoft SC-300 engineering surface area, this index categorizes 35 core identity services and administrative engines into six functional security domains.
Rather than treating identity tools as isolated portal features, this taxonomy maps each capability to its specific Control Plane Scope and operational Deployment Depth, serving as a design blueprint for Zero Trust access enforcement, identity governance, and workload hardening.
Governs core directory schema, boundary scoping, device posture, and RBAC isolation mechanisms.
| Capability / Service | Control Plane Scope | Deployment Depth |
|---|---|---|
| Tenant Configuration & Global Settings | Tenant properties, user/group global configurations, and corporate branding | Policy & Tenant Standard |
| Built-In & Custom Roles (RBAC) | Role definitions, administrative permissions, and directory scopes | Deployed & Verified |
| Administrative Units (AUs) | Scoped management boundaries, including restricted management behavior | Deployed & Verified |
| Directory Objects | User and group object lifecycle configurations | Deployed & Verified |
| Custom Security Attributes | Key-value pairs for metadata-driven access control | Architecture Reference |
| Device Management | Device join, registration, and global device policy settings | Deployed & Verified |
Houses the core policy evaluation engines that determine context-aware access decisions in real time.
| Capability / Service | Control Plane Scope | Deployment Depth |
|---|---|---|
| Conditional Access (CA) Engine | Central context-based access evaluation and policy enforcement | Production Standard |
| CA Authentication Context | Step-up security triggers for granular high-value application targets | Architecture Reference |
| Protected Actions | CA policy gates protecting high-privilege directory permissions | Architecture Reference |
| Microsoft Entra ID Protection | User, sign-in, and workload identity risk evaluation engines | Policy & Tenant Standard |
| Global Secure Access (GSA / SSE) | Internet Access, Private Access, and M365 traffic client profiles | Architecture Reference |
Defines passwordless authentication flows, credential remediation, and strong authentication policies.
| Capability / Service | Control Plane Scope | Deployment Depth |
|---|---|---|
| Authentication Methods | FIDO2, Passkeys, Authenticator app, TAP, and CBA | Production Standard |
| MFA Settings & Registration Campaigns | Global MFA enforcement mechanisms and nudge campaigns | Deployed & Verified |
| Self-Service Password Reset (SSPR) | User-led credential remediation and writeback workflows | Deployed & Verified |
| Entra Password Protection | Smart lockout and custom banned password dictionary evaluation | Deployed & Verified |
| Windows Hello for Business (WHfB) | Device-bound cryptographic passwordless deployments | Architecture Reference |
| Microsoft Entra Kerberos | Cloud identity authentication to on-premises storage and resources | Architecture Reference |
Manages B2B collaboration perimeters, cross-tenant trust boundaries, and external federation.
| Capability / Service | Control Plane Scope | Deployment Depth |
|---|---|---|
| External Collaboration Settings (B2B) | Guest invitation policies and user access restrictions | Policy & Tenant Standard |
| Cross-Tenant Access Settings (XTAS) | Inbound/outbound multi-tenant trust and compliance controls | Architecture Reference |
| Cross-Tenant Synchronization (CTS) | Automated cross-tenant identity provisioning engines | Architecture Reference |
| External IdP Federation | Direct SAML / WS-Fed federation configurations | Architecture Reference |
Governs non-human identities, application registration objects, and secure application publishing pathways.
| Capability / Service | Control Plane Scope | Deployment Depth |
|---|---|---|
| App Registrations & Service Principals | Application definitions, manifest tokens, and API permissions | Production Spec (Ref: ACPHF) |
| Managed Identities for Azure Resources | System-assigned and user-assigned secretless machine credentials | Production Spec (Ref: ACPHF) |
| Enterprise Applications Management | Tenant-level application settings, user assignments, and consent gates | Deployed & Verified |
| Microsoft Entra Application Proxy | On-premises web application publishing architecture | Architecture Reference |
| Defender for Cloud Apps (MDCA) Proxy | Conditional Access App Control session and access policies | Architecture Reference |
Enforces lifecycle automation, access attestation, and just-in-time administrative elevation.
| Capability / Service | Control Plane Scope | Deployment Depth |
|---|---|---|
| Privileged Identity Management (PIM) | Just-In-Time elevation for Entra roles, Azure resources, and PIM for Groups | Deployed & Verified |
| Entra Entitlement Management | Catalogs, Access Packages, and connected organization structures | Architecture Reference |
| Access Reviews | Attestation schedules for automated group and role verification | Architecture Reference |
| Lifecycle Workflows (LCW) | Automated Joiner-Mover-Leaver (JML) lifecycle task sequences | Architecture Reference |
| Terms of Use (ToU) | Enforceable legal and compliance acceptance gates | Deployed & Verified |
Monitors directory health, logs identity transactions, and synchronizes legacy on-premises assets.
| Capability / Service | Control Plane Scope | Deployment Depth |
|---|---|---|
| Hybrid Identity Engines | Connect Sync, Cloud Sync, Password Hash Sync, and PTA | Architecture Reference |
| Seamless Single Sign-On (SSO) | Kerberos-backed hybrid desktop Single Sign-On | Architecture Reference |
| Microsoft Entra Connect Health | Hybrid identity infrastructure monitoring agents | Architecture Reference |
| Monitoring & Log Analytics | Diagnostic streams, KQL Log Analytics workspaces, and Sentinel integration | Telemetry Active (Sentinel Eng. Deployed) |
Capabilities marked as Production Spec directly instantiate the security patterns established in the AI and Cloud Pipeline Hardening Framework (ACPHF).
While this index maps the breadth of the Microsoft Entra control plane, the ACPHF repository provides the deep-dive implementation spec for zero-trust passwordless federation, data-plane isolation, and non-human identity hardening.