Microsoft Entra ID is the single identity authority. Every other authentication surface in the estate is a relying party, and any system that keeps its own username and password list is a migration item rather than an integration.
The platform issues and governs identity; it never carries business data. That separation is what lets it be a shared tenant-wide service without becoming a data-protection problem of its own.
Break-glass accounts are drawn in red on the first page rather than hidden in an appendix. Two permanently privileged accounts are an accepted, monitored exception to the zero-standing-access rule, not an oversight.
Scale assumed
45,000 employees, 8,000 contractors, 6,500 B2B guests, 1.2M customer identities, 3,400 workload identities across 900 applications and 22 subscriptions.
2.6M sign-ins per day, peaking near 420 per second at 09:00 CET. Identity is a control-plane service: this volume shapes logging cost far more than it shapes latency.
Every figure here is a stated exercise assumption. They drive log retention cost, review campaign size and the group model, so they are the first thing to confirm with the client.
Out of scope
Endpoint management and device compliance policy itself. The platform consumes Intune's compliance signal (view 12) but does not define it.
Physical access, HR process design, and the application-level roles each product team defines inside its own domain.
Customer consent and privacy preference management, which belongs with the customer data platform rather than with the identity provider.