Azure Administration¶
Administering Microsoft Azure and Entra ID (formerly Azure AD).
Why It Matters¶
Most Windows environments now extend into Azure and Entra ID for identity, so cloud administration sits alongside on-prem work. The identity plane in particular (sign-ins, conditional access, privileged roles) is where a lot of security now lives.
Reference¶
Tooling¶
| Tool | Use |
|---|---|
| Azure portal | GUI administration |
Azure CLI (az) |
Cross-platform command line |
| Microsoft Graph PowerShell SDK | The current PowerShell module for Entra ID and Microsoft 365 |
| Microsoft Entra admin center | Identity administration |
Microsoft Graph PowerShell¶
Install-Module Microsoft.Graph -Scope CurrentUser
Connect-MgGraph -Scopes "User.Read.All","Directory.Read.All"
Get-MgUser -Top 10
Get-MgUser -Filter "accountEnabled eq false" # disabled accounts
Identity Security¶
| Control | Purpose |
|---|---|
| Conditional Access | Enforce conditions (MFA, device, location) on sign-in |
| MFA | Require a second factor |
| Privileged Identity Management (PIM) | Just-in-time privileged role activation |
| Sign-in and audit logs | Monitor authentication and directory changes |
How I Use It¶
I manage Entra ID with the Microsoft Graph PowerShell SDK (the Azure AD and MSOnline modules are retired), and I treat Conditional Access and MFA as the baseline for identity security. The Get-AzureUserInfo script wraps common cloud user reporting.