Skip to content

Entra ID (Azure AD) — Identity Management

Basic Information

FieldValue
CategorySystem Tools
OwnerSergej Vdovičenko
DeputyArtem Ryzhkov
Management Level5
SLA24x7
LoginMicrosoft corporate account (admin role)
URLhttps://entra.microsoft.com

Description

Microsoft Entra ID (formerly Azure Active Directory) is the cloud service for managing digital identities and access. It serves as the central Identity Provider (IdP) for all Etnetera group companies.

Key features:

  • SSO (Single Sign-On): one login for all connected applications (Microsoft 365, Slack, Atlassian, Adobe…)
  • MFA: mandatory for all users (Microsoft Authenticator)
  • Conditional Access: device compliance, location, risk score policies
  • Lifecycle management: automatic account provisioning (SCIM) to apps
  • Groups and roles: access assignment to apps and resources
  • Sync with on-prem AD: via Entra Connect Sync

Access and Login

  • URL: entra.microsoft.com
  • Login: corporate Microsoft account (firstname.lastname@etnetera.cz) with Global Administrator or User Administrator role
  • MFA is mandatory

Warning

Global Administrator role grants unrestricted access to the entire tenant. Use only for necessary operations. For daily user management, use User Administrator role.

Procedure — Create New User

  1. Entra ID → Users → New user → Create new user
  2. Fill in: Display Name, User Principal Name (firstname.lastname@etnetera.cz)
  3. Set temporary password or send email invitation
  4. Assign Groups (determines app access)
  5. Assign Licenses (Microsoft 365 plan)
  6. Click Create

Procedure — Disable Account (Offboarding)

  1. Users → [user] → Properties → Edit
  2. Check Block sign in → Yes
  3. Remove from groups (automatically loses app access)
  4. Revoke active sessions: Users → [user] → Revoke sessions
  5. Remove licenses: Licenses → Remove

Procedure — Reset User Password

  1. Users → [user] → Reset password
  2. Choose: Auto-generated or manual
  3. Check Require this user to change their password
  4. Share password securely (via Passbolt or encrypted message)

Troubleshooting

ProblemSolution
User cannot sign inCheck: Block sign in / Locked out / Conditional Access; Sign-in logs for details
MFA not workingUsers → [user] → Authentication methods — reset or add method
SSO app not workingEnterprise applications → [app] → Sign-in logs; check SAML/OIDC config
Sync from AD not workingCheck Entra Connect status: Get-ADSyncScheduler; check Event Log on sync server

Contact

  • Owner: Sergej Vdovičenko — Slack @sergej / sergej.vdovicenko@etnetera.cz
  • Deputy: Artem Ryzhkov — Slack @artem
  • Urgent issues (login outage): Slack #it-alerts

Etnetera a.s. — IT Team