IT Glossary
Microsoft Entra ID, formerly Azure AD, is Microsoft's cloud identity service. Learn how it works and where SaaS access still escapes its policies.
August 7, 2026
Microsoft Entra ID is Microsoft's cloud identity and access management service, renamed from Azure Active Directory in July 2023. It authenticates users to Microsoft 365 and to any application connected through SAML, OpenID Connect, or SCIM, and it enforces Conditional Access policies based on user, device, location, and sign-in risk.
Entra ID governs the applications you have connected to it. In a typical mid-market stack of 100 to 200 SaaS tools, only a fraction are federated. Every app bought on a company card, every local password, and every OAuth grant an employee approved sits outside those policies, invisible to Conditional Access and absent from the access review.
A 180-person scale-up runs Entra ID P1 with single sign-on on 22 applications. An ISO 27001 audit asks for evidence of access review across every system holding company data. The 22 federated apps produce clean reports. The 90 other tools, surfaced later through expense data and OAuth grants, produce nothing at all. The practical fix is to keep Entra ID as the identity source and layer SaaS discovery and access governance on top of it, which is the role Corma plays alongside the identity provider.
Yes. Entra ID is the current name of Azure Active Directory, changed in July 2023. The service, the APIs, and the licenses carried over unchanged, only the product name and portal branding moved.
Active Directory is on-premises, uses Kerberos and LDAP, and manages Windows domain resources. Entra ID is cloud-native, uses SAML, OAuth 2.0, and OpenID Connect, and manages access to cloud applications.
No. It covers applications explicitly connected to it. Tools with local accounts or unmanaged signups stay outside its policies and outside its access reviews.
Microsoft offers EU Data Boundary commitments for European tenants, but the exact scope depends on the service and the license tier. Verify the terms per workload before treating it as a compliance answer.