Microsoft Entra ID administration: privileged roles, apps and hybrid identity
For administrators who already know Entra ID basics (users, groups, licensing, MFA and Conditional Access). Delegate with least privileged built-in roles and administrative units, set up emergency access accounts the way Microsoft documents them, and use Privileged Identity Management (eligible versus active assignments, activation, approval) and access reviews. Then manage applications: application objects versus service principals, single sign-on options, user and group assignment, user consent, admin consent and the admin consent workflow, and reviewing granted permissions. Finally, hybrid identity: Microsoft Entra Connect Sync versus Cloud Sync, password hash synchronization, pass-through authentication, federation, and reading the audit log.
- Level
- Intermediate
- Length
- About 55 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- Microsoft Entra ID
Skills you'll practise
- Choose the least privileged built-in role and scope (tenant or administrative unit) for an administrative task
- Explain eligible, active, permanent and time-bound assignments in Privileged Identity Management and configure activation requirements safely
- Identify emergency access account settings that do or don't match Microsoft's guidance
- Distinguish an application object from a service principal and say where each is managed
- Evaluate an admin consent request and decide whether the requested permissions fit the app's purpose
- Choose between password hash synchronization, pass-through authentication and federation, and between Connect Sync and Cloud Sync, for a given requirement
- Find role, consent and application changes in the Microsoft Entra audit log
Course outline
- 1.Microsoft Entra ID administration: privileged roles, apps and hybrid identityVideo · 3 min
- 2.Least privilege, emergency access and Privileged Identity ManagementLesson · 20 min
- 3.Applications: registrations, service principals, SSO and consentLesson · 18 min
- 4.Hybrid identity and the audit logLesson · 17 min
- 5.Microsoft Entra ID administration: privileged roles, apps and hybrid identity: knowledge checkKnowledge check · 16 questions
- 6.Final exam11 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn docs: Best practices for Microsoft Entra roles
- Microsoft Learn docs: Microsoft Entra built-in roles
- Microsoft Learn docs: Least privileged roles by task in Microsoft Entra ID
- Microsoft Learn docs: Administrative units in Microsoft Entra ID
- Microsoft Learn docs: Manage emergency access admin accounts
- Microsoft Learn docs: What is Privileged Identity Management?
- Microsoft Learn docs: Configure Microsoft Entra role settings in PIM
- Microsoft Learn docs: What are access reviews?
- Microsoft Learn docs: Create an access review of groups and applications
- Microsoft Learn docs: Apps & service principals in Microsoft Entra ID
- Microsoft Learn docs: What is single sign-on in Microsoft Entra ID?
- Microsoft Learn docs: Manage users and groups assignment to an application
- Microsoft Learn docs: Overview of user and admin consent
- Microsoft Learn docs: Application consent management and evaluation of consent requests
- Microsoft Learn docs: Configure the admin consent workflow
And 7 more.
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.