There are three main types of user accounts in Microsoft Entra ID.

  • Cloud identity user accounts: users created directly within Entra ID.
  • Directory synchronised identity user accounts: users in defined in Windows Server Active Directory.
  • Guest user accounts: users invited from outside Azure.

Group Accounts/User Groups

There Distribution groups for sending email notifications are two types of user groups you can create in Azure, Security groups and Microsoft 365 groups.

With Security groups you can give permissions to all the members of a group instead of doing it individually. So it is important to group users security wise.

Microsoft 365 Groups is for collaboration and access to Microsoft SaaS apps like Teams, Outlook, etc.,

Administrative Unit (AU) this is used to restrict permissions in a role specific portions of your organisation. For example, you can create an administrative unit for a regional support team and assign specific roles to manage users only within that region. AUs can only be managed by Global Admin or Privileged Role Admin.  

Some Roles and Administrators in Azure

Administrative roles are used for granting access for privileged actions in Microsoft Entra ID.