Entra ID & IdentityHow-To & HardeningRetrospectives

How to Map Entra Products to Your Identity Security Roadmap

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2022, written in 2026 with the benefit of hindsight.

Microsoft Entra now includes many products. Here is a practical way to map them to an identity security roadmap for a mid-sized organization.

Foundation (most organizations, Entra ID P1)

  • Entra ID: single sign-on, MFA, Conditional Access, self-service password reset, hybrid identity with Entra Connect or cloud sync.
  • Roadmap items: block legacy auth, MFA for all, Conditional Access baseline, SSO for major SaaS, break-glass accounts.

Risk-based protection (Entra ID P2)

  • Identity Protection: risk-based Conditional Access for users and sign-ins.
  • Privileged Identity Management: just-in-time admin access.
  • Access reviews (basic).
  • Roadmap items: risk policies, PIM for all admin roles.

Governance (Entra ID Governance)

  • Joiner-mover-leaver lifecycle workflows, entitlement management, advanced access reviews.
  • Roadmap items: automated onboarding/offboarding, access packages for projects and partners.

Workloads (Entra Workload ID)

  • Conditional Access and risk detection for service principals, workload identity federation.
  • Roadmap items: secretless workloads, policies for high-privilege apps.

Network access (Global Secure Access)

  • Entra Private Access: replace VPN with per-app access.
  • Entra Internet Access: secure web gateway with identity-aware policies.
  • Roadmap items: retire legacy VPN for internal apps.

External identities

  • Entra External ID for customers and partners.

Sequencing

Foundation first, then privileged access, then governance and workloads. Network access often follows a VPN renewal decision.

entra identity roadmapMicrosoft Entra brand2022

More on this story