Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.
6.2. Quick Reference
Decision tables compressing Phases 2–5. If a row surprises you, revisit its section.
License Tier Map
| Feature | Free | P1 | P2 | Governance add-on |
|---|---|---|---|---|
| MFA via security defaults | ✅ | ✅ | ✅ | — |
| Conditional Access | ❌ | ✅ | ✅ | — |
| Dynamic groups, group-based licensing | ❌ | ✅ | ✅ | — |
| SSPR with writeback, Connect Health, custom roles | ❌ | ✅ | ✅ | — |
| ID Protection (risk policies), PIM, access reviews | ❌ | ❌ | ✅ | — |
| Entitlement mgmt (full), lifecycle workflows | ❌ | ❌ | partial | ✅ |
| Workload identity CA / risk | ❌ | ❌ | ❌ | Workload ID Premium |
"Which feature?" Discriminators
| Requirement phrase | Answer | Not |
|---|---|---|
| Phishing-resistant MFA | Passkeys/FIDO2, WHfB, CBA via authentication strength | Authenticator push, SMS |
| Bootstrap passwordless / lost method | Temporary Access Pass | Password reset |
| Step-up for a sensitive resource/action | Authentication context (+ protected actions for directory ops) | New app-wide policy |
| Dry-run a CA policy | Report-only mode + What If | Pilot group enforcement |
| Sign-in risk remediation | Require MFA (risk-based CA) | Password change |
| User risk remediation | Secure password change (needs writeback if hybrid) | MFA alone |
| VPN replacement, any TCP/UDP, workforce | GSA Private Access (client + connectors) | App Proxy |
| Publish one on-prem web app, no client, partners | Application Proxy (Entra pre-auth) | Private Access |
| Corporate-network-only without IP lists | Compliant network check (GSA) | Named locations |
| Block sign-ins to foreign tenants | Tenant restrictions v2 (M365 profile) | Cross-tenant access settings |
| Delegate admin over one department | Administrative unit + scoped role | Custom role alone |
| Protect VIPs from broad helpdesk roles | Restricted management AU | Regular AU |
| Partner MFA honored, no double-prompt | Cross-tenant access trust settings | CA exclusion |
| Auto-provision users between owned tenants | Cross-tenant synchronization | Bulk invite |
| Immediate on-prem password policy at cloud sign-in | PTA | PHS |
| Sign-in survives on-prem outage | PHS | PTA, AD FS |
| Sync a disconnected forest, light footprint, HA | Cloud Sync | Connect Sync |
| Azure workload calls Azure/Graph, no secrets | Managed identity (user-assigned if shared/persistent) | Service principal + secret |
| External CI/CD calls Azure, no stored secrets | Workload identity federation | Client secret in vault |
| Daemon reads all mailboxes | Application permission + client credentials + admin consent | Delegated permission |
| Users request blocked-consent apps with approval | Admin consent workflow | Disable consent only |
| Unmanaged devices: browser-only, no downloads | CA session control → MDCA session policy (or app-enforced restrictions for SPO/EXO) | Block access |
| Requestable, expiring, approved access bundles | Access package (entitlement mgmt) | Direct group adds |
| Auto-delete guests when access ends | Entitlement mgmt external user lifecycle | Manual review |
| Recertify access periodically, auto-remove | Access reviews (auto-apply ON) | Entitlement mgmt |
| Just-in-time admin, approval, time-bound | PIM eligible + role settings | Standing assignment |
| One activation grants several roles | PIM for Groups + role-assignable group | Multiple activations |
| Retain logs years / query logs / feed Splunk | Storage account / Log Analytics / Event Hub | Portal retention |
| Posture recommendations and trend | Identity Secure Score | Sign-in logs |
Break-Glass Card
Two cloud-only accounts · permanent active Global Administrator (never eligible) · excluded from all CA policies · phishing-resistant credentials stored offline · sign-in alerting via Log Analytics alert rule · tested quarterly.
Written byAlvin Varughese
Founder•18 professional certifications