How to Map Entra Products to Your Identity Security Roadmap
Retrospective: this article looks back at events from May 2022, written in 2026 with the benefit of hindsight.
Microsoft Entra now includes many products. Here is a practical way to map them to an identity security roadmap for a mid-sized organization.
Foundation (most organizations, Entra ID P1)
- Entra ID: single sign-on, MFA, Conditional Access, self-service password reset, hybrid identity with Entra Connect or cloud sync.
- Roadmap items: block legacy auth, MFA for all, Conditional Access baseline, SSO for major SaaS, break-glass accounts.
Risk-based protection (Entra ID P2)
- Identity Protection: risk-based Conditional Access for users and sign-ins.
- Privileged Identity Management: just-in-time admin access.
- Access reviews (basic).
- Roadmap items: risk policies, PIM for all admin roles.
Governance (Entra ID Governance)
- Joiner-mover-leaver lifecycle workflows, entitlement management, advanced access reviews.
- Roadmap items: automated onboarding/offboarding, access packages for projects and partners.
Workloads (Entra Workload ID)
- Conditional Access and risk detection for service principals, workload identity federation.
- Roadmap items: secretless workloads, policies for high-privilege apps.
Network access (Global Secure Access)
- Entra Private Access: replace VPN with per-app access.
- Entra Internet Access: secure web gateway with identity-aware policies.
- Roadmap items: retire legacy VPN for internal apps.
External identities
- Entra External ID for customers and partners.
Sequencing
Foundation first, then privileged access, then governance and workloads. Network access often follows a VPN renewal decision.
- Microsoft Entra Launches (May 2022): Identity Becomes Its Own Product Family Platform Changes
- Identity Security Program Checklist for Mid-Market Companies How-To & Hardening
- CIO Brief: Identity Is the New Perimeter — Now It Has a Brand CIO Briefings