<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: daniel ugot</title>
    <description>The latest articles on DEV Community by daniel ugot (@daniel_ugot_8f1e5c3cc3f3c).</description>
    <link>https://dev.to/daniel_ugot_8f1e5c3cc3f3c</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1795432%2F105dd9cd-60f0-4ff4-bdc2-7e28cb0be1dc.jpg</url>
      <title>DEV Community: daniel ugot</title>
      <link>https://dev.to/daniel_ugot_8f1e5c3cc3f3c</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/daniel_ugot_8f1e5c3cc3f3c"/>
    <language>en</language>
    <item>
      <title>Mastering Azure Entra ID: A Hands-On Guide to User Management and Privileged Roles</title>
      <dc:creator>daniel ugot</dc:creator>
      <pubDate>Thu, 28 May 2026 00:13:29 +0000</pubDate>
      <link>https://dev.to/daniel_ugot_8f1e5c3cc3f3c/mastering-azure-entra-id-a-hands-on-guide-to-user-management-and-privileged-roles-pb8</link>
      <guid>https://dev.to/daniel_ugot_8f1e5c3cc3f3c/mastering-azure-entra-id-a-hands-on-guide-to-user-management-and-privileged-roles-pb8</guid>
      <description>&lt;p&gt;Cloud identity management sits at the center of modern IT operations. Whether you are managing a startup environment or a large enterprise infrastructure, controlling who has access to cloud resources is vital. In Microsoft Azure, this responsibility is handled through Microsoft Entra ID.&lt;/p&gt;

&lt;p&gt;In this hands-on guide, you’ll learn how to create users, assign administrative privileges, and apply the principle of least privilege by removing elevated permissions when they are no longer needed. These are foundational tasks every Azure cloud administrator should understand.&lt;/p&gt;

&lt;p&gt;By the end of this walkthrough, you will know how to:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Create users in Azure Entra ID&lt;/li&gt;
&lt;li&gt;Sign in with newly created accounts&lt;/li&gt;
&lt;li&gt;Assign the Global Administrator role&lt;/li&gt;
&lt;li&gt;Delegate administrative tasks securely&lt;/li&gt;
&lt;li&gt;Revoke elevated access after task completion&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  &lt;strong&gt;What is Microsoft Entra ID?&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Microsoft Entra ID is Microsoft’s cloud-based identity and access management service. It allows organizations to manage users, authentication, permissions, and secure access to applications and cloud resources.&lt;/p&gt;

&lt;p&gt;Today, Entra ID plays a major role in:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Identity governance&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Zero Trust security models&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Multi-factor authentication (MFA)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Role-based access control (RBAC)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Single Sign-On (SSO)&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Organizations use Entra ID to ensure that only authorized users can access critical systems and data.&lt;/p&gt;




&lt;h2&gt;
  
  
  &lt;strong&gt;Prerequisites&lt;/strong&gt;
&lt;/h2&gt;

&lt;p&gt;Before starting this hands-on lab, ensure you have:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;An active Microsoft Azure subscription&lt;/li&gt;
&lt;li&gt;Access to the Microsoft Azure Portal&lt;/li&gt;
&lt;li&gt;A user account with Global Administrator privileges&lt;/li&gt;
&lt;li&gt;Permission to create and manage users&lt;/li&gt;
&lt;/ol&gt;




&lt;p&gt;&lt;strong&gt;Step 1: Create a New User in Azure Entra ID&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Every employee, administrator, developer, or service account in Azure needs an identity. User creation is one of the most common administrative tasks in any cloud environment.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Sign in to the Azure Portal&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Search for and open Microsoft Entra ID&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fd2erxwlb5sec5kowbpwa.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fd2erxwlb5sec5kowbpwa.JPG" alt=" " width="485" height="280"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Click on ADD, select Users and select Create New User&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3c00l2gqole8uqc2ol45.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3c00l2gqole8uqc2ol45.jpg" alt=" " width="652" height="297"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A window with a form to fill in unique information for your user opens
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;user principal name:ricky.george@xxxxxxx
Display Name: Ricky George
Password: xxxxxxxxx (uncheck the auto-generate option to enter your password)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Click on Next: properties
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;First Name: Ricky
Last Name: George
User type: Member
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Click Next &amp;gt;&amp;gt; Next: Review + Create &amp;gt;&amp;gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Click Create&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Back to Entra ID, on the left pane, select Manage &amp;gt;&amp;gt; User&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5l0qaj3f03sskkqb2o4x.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5l0qaj3f03sskkqb2o4x.JPG" alt=" " width="270" height="452"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2rlyl99aep1bsy6jdctv.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2rlyl99aep1bsy6jdctv.JPG" alt=" " width="797" height="62"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Step 2: Sign In with the Newly Created User Account&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Now that the account exists, the next step is testing access by signing in. In real-world environments, administrators often validate accounts before handing them over to employees or team members.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Open a private/incognito browser window&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Navigate to the Microsoft Azure Portal&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Sign in using the new credentials&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Change the password if prompted&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9hixzwmxlycpt1ycouh9.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9hixzwmxlycpt1ycouh9.JPG" alt=" " width="800" height="306"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;At this stage, the new user has very limited permissions.&lt;/p&gt;

&lt;p&gt;If the user attempts administrative actions, Azure will deny access because no elevated role has been assigned yet.&lt;/p&gt;

&lt;p&gt;This demonstrates Azure’s default security posture: users receive only minimal access until roles are explicitly assigned to them.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Step 3: Grant the User Global Administrator Access&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Next, you will elevate the user’s privileges by assigning the Global Administrator role. The Global Administrator role is the highest privileged role in Entra ID.&lt;/p&gt;

&lt;p&gt;A Global Administrator can:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Manage all users&lt;/li&gt;
&lt;li&gt;Reset passwords&lt;/li&gt;
&lt;li&gt;Assign roles&lt;/li&gt;
&lt;li&gt;Configure security settings&lt;/li&gt;
&lt;li&gt;Manage subscriptions and services&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Because of its power, organizations should grant this role carefully and temporarily whenever possible.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Sign back in using your original administrator account&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Open Microsoft Entra ID &amp;gt;&amp;gt; Manage &amp;gt;&amp;gt; Users&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Select the User we have just created (Ricky George)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Under the user, in the left pane, select Assign Roles &lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ffsq7l9w8966fibg7s1jn.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ffsq7l9w8966fibg7s1jn.JPG" alt=" " width="256" height="482"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Click on Add assignments&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpagvd5tavermnykqfvlz.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpagvd5tavermnykqfvlz.jpg" alt=" " width="581" height="137"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Search for Global Administrator and select the role.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Click ADD at the bottom to apply the role to the selected User.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;strong&gt;Step 4: Create Another User Using the Newly Promoted Account&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Using the newly promoted Global Administrator account, create another user.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;While signed in as the promoted administrator&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Open Microsoft Entra ID &amp;gt;&amp;gt; Manage&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Navigate to ADD &amp;gt;&amp;gt; Users &amp;gt;&amp;gt; Create new Users&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fuxxl632f92vhnhs7lu04.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fuxxl632f92vhnhs7lu04.jpg" alt=" " width="642" height="248"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Fill out the necessary information for a new user and click Create.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fuzq6qhwngdbeguirqv7w.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fuzq6qhwngdbeguirqv7w.JPG" alt=" " width="481" height="218"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This confirms the promoted account has administrative privileges.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Step 5: Revoke Global Administrator Access from the First User&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Once the administrative task is complete, remove elevated privileges.&lt;br&gt;
One of the biggest security risks in cloud environments is excessive privileged access.&lt;/p&gt;

&lt;p&gt;Leaving Global Administrator rights permanently assigned can increase exposure to:&lt;/p&gt;

&lt;p&gt;a. Credential theft&lt;br&gt;
b. Insider threats&lt;br&gt;
c. Accidental misconfigurations&lt;br&gt;
d. Unauthorized access&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Sign in using your original administrator account&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Open Microsoft Entra ID&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Navigate to Manage &amp;gt;&amp;gt; Users &amp;gt;&amp;gt; select the New User account&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;On the left pane, select Assign Roles. You will see the assigned role to the User. Select the Global Administrator Role, then click Remove Assignment.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvskoossuia03ri06lbsa.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvskoossuia03ri06lbsa.JPG" alt=" " width="800" height="263"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvgc2hn74ehp6lj48hpuz.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvgc2hn74ehp6lj48hpuz.JPG" alt=" " width="800" height="272"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4fpny1g0jevapg8w553s.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4fpny1g0jevapg8w553s.JPG" alt=" " width="485" height="208"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Sign back in using the first user account. Try accessing administrative settings again. You should notice that administrative capabilities are no longer available.&lt;/p&gt;

&lt;p&gt;This confirms the role removal was successful.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Closing Thoughts&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Managing identities and permissions is one of the most important responsibilities in cloud administration. In this hands-on, we have learned how to:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Create users in Azure Entra ID&lt;/li&gt;
&lt;li&gt;Test account access&lt;/li&gt;
&lt;li&gt;Assign Global Administrator privileges&lt;/li&gt;
&lt;li&gt;Delegate administrative tasks&lt;/li&gt;
&lt;li&gt;Revoke elevated permissions securely&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;These tasks mirror real-world identity management workflows used across enterprise Azure environments today.&lt;/p&gt;

</description>
      <category>cloudnative</category>
      <category>azure</category>
      <category>cloud</category>
      <category>devops</category>
    </item>
  </channel>
</rss>
