Azure · Identity & access
One directory.Every sign-in.Access you control.
From the tenant that holds your identities to the roles that permit an action: accounts, groups, partners, sign-in methods and day-to-day account support.
Who is Contoso?
Contoso is the fictional company Microsoft uses across its official documentation and training, so examples stay consistent from one article to the next. It is not a real organization, and no name, value or resource here belongs to one. These lessons follow a small retail part of it.
- Contoso RetailThe online shop these lessons build and run
- MayaWorks in Contoso Operations and needs access to do her job
- AlexWorks for a partner company and collaborates from outside
Tenant, Identity and Azure Access
Maya signs in but cannot read shop-vm configuration. In this example, no other roles or deny assignments apply.
Start here7 stepsUsers and Groups
Maya joins Contoso Operations. Her onboarding request is ready, but the directory does not contain her user yet.
Open explainer6 stepsExternal Identities
Alex works for Partner and already has a sign-in. Contoso needs Alex to review shop-vm configuration without creating a shared account.
Open explainer6 stepsAuthentication and Access
Maya opens the orders app and Azure management. Separate sign-in prompts interrupt her work; a successful sign-in still does not answer what she may do.
Open explainer6 stepsIdentity Administration
Maya needs account support. Contoso must distinguish a help-desk password reset, license assignment and management of her authentication methods.
Open explainer6 stepsGo deeper on Microsoft Learn
Each explainer is grounded in official documentation. Open the source for any stop.