Skip to content

Compcode1/microsoft-entra-control-plane-capability-index

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

Microsoft Entra Control Plane Capability Index

An Architectural Taxonomy & Service Coverage Map for Enterprise Identity Engineering

Authored by Steven Tuschman | Identity Security Engineer


Architectural Overview

This repository establishes a comprehensive control plane capability matrix across the Microsoft Entra ID ecosystem. Derived from the Microsoft SC-300 engineering surface area, this index categorizes 35 core identity services and administrative engines into six functional security domains.

Rather than treating identity tools as isolated portal features, this taxonomy maps each capability to its specific Control Plane Scope and operational Deployment Depth, serving as a design blueprint for Zero Trust access enforcement, identity governance, and workload hardening.


Control Plane Surface Area Matrix

Domain 1: Directory Foundations & Administrative Boundaries

Governs core directory schema, boundary scoping, device posture, and RBAC isolation mechanisms.

Capability / Service Control Plane Scope Deployment Depth
Tenant Configuration & Global Settings Tenant properties, user/group global configurations, and corporate branding Policy & Tenant Standard
Built-In & Custom Roles (RBAC) Role definitions, administrative permissions, and directory scopes Deployed & Verified
Administrative Units (AUs) Scoped management boundaries, including restricted management behavior Deployed & Verified
Directory Objects User and group object lifecycle configurations Deployed & Verified
Custom Security Attributes Key-value pairs for metadata-driven access control Architecture Reference
Device Management Device join, registration, and global device policy settings Deployed & Verified

Domain 2: Zero Trust Access Control & Context Engines

Houses the core policy evaluation engines that determine context-aware access decisions in real time.

Capability / Service Control Plane Scope Deployment Depth
Conditional Access (CA) Engine Central context-based access evaluation and policy enforcement Production Standard
CA Authentication Context Step-up security triggers for granular high-value application targets Architecture Reference
Protected Actions CA policy gates protecting high-privilege directory permissions Architecture Reference
Microsoft Entra ID Protection User, sign-in, and workload identity risk evaluation engines Policy & Tenant Standard
Global Secure Access (GSA / SSE) Internet Access, Private Access, and M365 traffic client profiles Architecture Reference

Domain 3: Credential Security & Authentication Infrastructure

Defines passwordless authentication flows, credential remediation, and strong authentication policies.

Capability / Service Control Plane Scope Deployment Depth
Authentication Methods FIDO2, Passkeys, Authenticator app, TAP, and CBA Production Standard
MFA Settings & Registration Campaigns Global MFA enforcement mechanisms and nudge campaigns Deployed & Verified
Self-Service Password Reset (SSPR) User-led credential remediation and writeback workflows Deployed & Verified
Entra Password Protection Smart lockout and custom banned password dictionary evaluation Deployed & Verified
Windows Hello for Business (WHfB) Device-bound cryptographic passwordless deployments Architecture Reference
Microsoft Entra Kerberos Cloud identity authentication to on-premises storage and resources Architecture Reference

Domain 4: External Identities & Multi-Tenant Governance

Manages B2B collaboration perimeters, cross-tenant trust boundaries, and external federation.

Capability / Service Control Plane Scope Deployment Depth
External Collaboration Settings (B2B) Guest invitation policies and user access restrictions Policy & Tenant Standard
Cross-Tenant Access Settings (XTAS) Inbound/outbound multi-tenant trust and compliance controls Architecture Reference
Cross-Tenant Synchronization (CTS) Automated cross-tenant identity provisioning engines Architecture Reference
External IdP Federation Direct SAML / WS-Fed federation configurations Architecture Reference

Domain 5: Application Management & Workload Identity Control

Governs non-human identities, application registration objects, and secure application publishing pathways.

Capability / Service Control Plane Scope Deployment Depth
App Registrations & Service Principals Application definitions, manifest tokens, and API permissions Production Spec (Ref: ACPHF)
Managed Identities for Azure Resources System-assigned and user-assigned secretless machine credentials Production Spec (Ref: ACPHF)
Enterprise Applications Management Tenant-level application settings, user assignments, and consent gates Deployed & Verified
Microsoft Entra Application Proxy On-premises web application publishing architecture Architecture Reference
Defender for Cloud Apps (MDCA) Proxy Conditional Access App Control session and access policies Architecture Reference

Domain 6: Identity Governance & Privileged Elevation

Enforces lifecycle automation, access attestation, and just-in-time administrative elevation.

Capability / Service Control Plane Scope Deployment Depth
Privileged Identity Management (PIM) Just-In-Time elevation for Entra roles, Azure resources, and PIM for Groups Deployed & Verified
Entra Entitlement Management Catalogs, Access Packages, and connected organization structures Architecture Reference
Access Reviews Attestation schedules for automated group and role verification Architecture Reference
Lifecycle Workflows (LCW) Automated Joiner-Mover-Leaver (JML) lifecycle task sequences Architecture Reference
Terms of Use (ToU) Enforceable legal and compliance acceptance gates Deployed & Verified

Domain 7: Hybrid Identity & Telemetry Engines

Monitors directory health, logs identity transactions, and synchronizes legacy on-premises assets.

Capability / Service Control Plane Scope Deployment Depth
Hybrid Identity Engines Connect Sync, Cloud Sync, Password Hash Sync, and PTA Architecture Reference
Seamless Single Sign-On (SSO) Kerberos-backed hybrid desktop Single Sign-On Architecture Reference
Microsoft Entra Connect Health Hybrid identity infrastructure monitoring agents Architecture Reference
Monitoring & Log Analytics Diagnostic streams, KQL Log Analytics workspaces, and Sentinel integration Telemetry Active (Sentinel Eng. Deployed)

Architectural Alignment with ACPHF

Capabilities marked as Production Spec directly instantiate the security patterns established in the AI and Cloud Pipeline Hardening Framework (ACPHF).

While this index maps the breadth of the Microsoft Entra control plane, the ACPHF repository provides the deep-dive implementation spec for zero-trust passwordless federation, data-plane isolation, and non-human identity hardening.

About

An architectural taxonomy and control plane capability index mapping 35 Microsoft Entra ID services across zero trust, governance, and workload identity domains. Categorizes core administrative surface area into functional security domains with defined deployment depths.

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors