Entra ID tenants, users, groups, hybrid identity, dan integrasi cloud menjadi evolusi natural dari Active Directory ke era cloud computing

Setelah di episode 3 kita membahas Active Directory, pada episode ini kita beralih ke Entra ID (sebelumnya Azure AD) — layanan cloud directory dari Microsoft yang menjadi evolusi natural AD ke era cloud. Di tahun 2026, hampir semua organisasi hybrid memiliki Entra ID sebagai identitas cloud utama.
Mengapa Entra ID penting? Karena cloud computing menggeser workload dari on-premises ke cloud. Identity harus mengikuti — dan Entra ID adalah bridge antara AD on-premises dan dunia cloud.
| Aspek | Active Directory | Entra ID |
|---|---|---|
| Deployment | On-premises | Cloud (SaaS) |
| Protocol | LDAP, Kerberos | OAuth, OIDC, SAML |
| Database | NTDS.dit | Cloud database |
| Scalability | Terbatas hardware | Elastic cloud |
| Authentication | Kerberos tickets | Token-based (JWT) |
Tenant adalah unit administrasi di Entra ID — satu organisasi = satu tenant:
Tenant: contoso.onmicrosoft.com
├── Users (800)
├── Groups (50)
├── Applications (30)
├── Enterprise Applications (20)
└── Conditional Access Policies (15)# 1. Buka https://developer.microsoft.com/en-us/microsoft-365/dev-program
# 2. Sign up dengan Microsoft account
# 3. Pilih "Instant sandbox" untuk tenant trial
# 4. Tenant siap digunakan dalam 5 menitHybrid identity menghubungkan AD on-premises dengan Entra ID cloud:
On-Premises AD ←→ Entra Connect ←→ Entra ID (Cloud)
(NTDS.dit) (Sync) (Cloud DB)Entra Connect menyinkronkan objects dari AD ke Entra ID:
| Object | Disync? | Catatan |
|---|---|---|
| Users | Ya | Password hash sync atau pass-through |
| Groups | Ya | Security dan distribution groups |
| Contacts | Ya | External contacts |
| Service Accounts | Tidak | Tidak perlu sync |
| Computer | Ya | Untuk hybrid join |
Connect-MsolService
Get-MsolCompanyInformation | Select DirectorySynchronizationEnabled,LastSyncTime| Metode | Cara Kerja | Keamanan |
|---|---|---|
| PHS | Hash password disync ke cloud | Lebih cepat, tapi hash di cloud |
| PTA | Auth request diteruskan ke on-prem | Lebih aman, tapi butuh agent |
| Federation (ADFS) | Token dikeluarkan oleh ADFS | Paling aman, tapi kompleks |
Note
Microsoft merekomendasikan Password Hash Sync untuk sebagian besar organisasi karena fitur security extras-nya (leaked credential detection, risk-based sign-in). Federation hanya diperlukan untuk compliance ketat.
Entra ID bisa mengintegrasikan ribuan aplikasi SaaS:
Entra ID (IdP)
├── Microsoft 365 (built-in)
├── Salesforce (SAML)
├── Slack (OIDC)
├── Custom apps (OIDC/SAML)
└── 3000+ pre-integrated apps| Aspek | App Registration | Enterprise Application |
|---|---|---|
| Fungsi | Membuat aplikasi baru | Mengintegrasikan app yang ada |
| Control | Developer penuh | Admin mengelola akses |
| SSO | Konfigurasi oleh developer | Diaktifkan oleh admin |
| Feature | Fungsi |
|---|---|
| Conditional Access | Policy-based access control |
| Identity Protection | Risk detection & remediation |
| PIM (Privileged Identity Management) | Just-in-time admin access |
| Access Reviews | Periodic access certification |
| App Proxy | Remote access ke on-prem apps |
Inti yang harus dibawa pulang:
Di episode 5 selanjutnya kita akan membahas authentication protocols (OAuth/OIDC/SAML) — cara kerja, flow, dan implementasi masing-masing protokol. Siapkan pemahaman protocol kalian!