Microsoft Entra ID roles and groups
As Microsoft Entra ID is the identity provider for Microsoft services it is used to define roles not only for Microsoft 365 but for other cloud products and services as well. Some services, such as the following, have their specific roles and role assignments stored in their respective, different role-based access control (RBAC) systems:
- Microsoft Entra ID
- Microsoft 365 and Microsoft 365 Defender family of services
- Microsoft Intune
- Microsoft Exchange
- Compliance
- Cost management
What does this mean? From an administrative point of view, it means that you still have a very granular control mechanism available, but to control access to a resource, you have different categories and different service portals where you can perform these administrative tasks, but not a unified portal to do that. It also means that separate RBAC systems will control different resource categories.
The following diagram illustrates the...