AD / Entra Terminology Decoder Fast answers for working admins
Managed identity
Answer: A managed identity gives a supported Azure resource a Microsoft Entra service principal whose credentials are managed by Azure, avoiding application secrets in code or configuration.
Administrator playbook

Decide, verify, and document

Use the curated answer as a starting point, then prove the outcome against the target tenant or device.

1

What it means

  • System-assigned identity lifecycle follows one Azure resource
  • User-assigned identities are reusable Azure resources
  • The identity still appears in Entra as a service principal and must receive resource access
2

What to check next

  1. Choose system-assigned versus user-assigned based on lifecycle and reuse
  2. Grant only the required Azure role or application permission
  3. Confirm the application requests tokens for the intended resource
3

Verify success

  1. Confirm the object type and identifier in the authoritative tenant.
  2. Compare the portal value with Microsoft Graph or the local device state.
  3. Use IDs—not display names—when proving that two references point to the same object.
4

Escalate when

  • Two portals or APIs return conflicting identifiers for the same expected object.
  • The issue crosses tenant or cloud boundaries.
  • A production authorization decision depends on the object relationship.
Copyable admin briefAnswer, next checks, source, and review date
Inspect Microsoft Graph context
Get-MgContext | Select-Object ClientId,TenantId,Account,AuthType,Scopes

Read-only. Useful when a term or identifier is being interpreted in the wrong tenant.

Evidence to preserve

Credential owner
Azure
Directory object
Service principal
Types
System-assigned and user-assigned
  • Tenant ID and cloud
  • Object type and object ID
  • User, app, or device context
  • Where the value was observed