Microsoft Entra ID (formerly Azure Active Directory, or Azure AD) is the cloud identity service behind every Azure subscription. Every person who signs in to the Azure portal, and every group you use to grant access, lives in an Entra tenant: a dedicated instance of the directory that belongs to your organization. As an Azure administrator you will spend a lot of time creating users and groups, because good group design is what keeps access manageable. You grant permissions to groups once, then add and remove people from those groups as their jobs change, instead of editing dozens of individual permissions every time someone joins or leaves.
You can create a user in the portal (Microsoft Entra ID > Users > New user > Create new user), with the Azure CLI (az ad user create --display-name "Ana Silva" --user-principal-name ana@contoso.com --password <initial-password>), with Microsoft Graph PowerShell (New-MgUser), or by inviting an external user as a guest. A cloud user needs a display name, a user principal name (UPN) such as ana@contoso.com whose domain suffix is a verified domain in the tenant (or the default onmicrosoft.com domain), and an initial password that the user is usually forced to change at first sign-in. Users synchronized from on-premises Active Directory Domain Services (AD DS) with Microsoft Entra Connect or Cloud Sync are sourced on-premises, so you change most of their properties there, not in the portal.
For many users at once, use Bulk operations > Bulk create on the Users page. You download a CSV (comma-separated values) template, fill in one row per user with the display name, UPN, initial password and any optional properties such as department or job title, upload the file, and the portal runs the job in the background. When it finishes you can open Bulk operation results and download a file showing which rows succeeded and which failed and why, typically a duplicate UPN or an unverified domain. The same menu offers bulk invite for guests and bulk delete, and groups have bulk import and bulk remove of members from a CSV file.
Entra ID has two group types, and the exam expects you to choose between them. A security group is used to grant access to resources: Azure role-based access control (RBAC) role assignments, enterprise app assignments, licenses and Conditional Access policies. Its members can be users, devices, service principals and other groups (nesting). A Microsoft 365 group is a collaboration group: it comes with a shared mailbox, calendar, SharePoint site and can back a Microsoft Teams team. Its members can only be users, it cannot contain other groups, and it always has its own email address. If a question is about granting Azure permissions to a set of administrators or targeting devices, the answer is a security group; if it mentions shared email, calendars or Teams, it is a Microsoft 365 group.
Each group also has a membership type. Assigned means an administrator or group owner adds and removes members by hand. Dynamic user means Entra ID evaluates a rule against user attributes and keeps membership current automatically, for example (user.department -eq "Sales") -and (user.country -eq "US"). Dynamic device does the same with device attributes such as device.deviceOSType -eq "Windows", and it is only available for security groups. A single group cannot mix user and device rules. You cannot add or remove members of a dynamic group by hand; you change the rule or the user's attributes instead. Dynamic membership requires Microsoft Entra ID P1 licensing (or a product that includes it) for users who are members of dynamic groups. You can switch a group between assigned and dynamic, but switching to dynamic replaces the existing members with whoever the rule matches, and rule processing is not instant, so a new hire can take a while to appear.
Consider a worked example. Contoso hires 40 seasonal support agents. You download the bulk create template, fill in 40 rows with each agent's name, UPN, temporary password and department set to Support, and upload it. The results file shows 39 successes and one failure caused by a typo in the domain suffix, which you fix and re-upload as a single row. A dynamic user security group called Support-Agents already exists with the rule user.department -eq "Support", and that group holds the Reader role on the support resource group. Within a short time the 40 new accounts appear in the group and inherit access, with no individual role assignments. When the season ends and HR changes their department, they drop out of the group automatically.
Common mistakes: trying to put devices or nested groups into a Microsoft 365 group; creating a dynamic device rule on a Microsoft 365 group; expecting to add a single person manually to a dynamic group; forgetting the P1 license requirement for dynamic membership; and editing a synchronized user's department in the portal, only to find the change is blocked or overwritten by the next sync.
Exam questions usually hide the answer in a clue word. 'Automatically', 'based on department' or 'based on attribute' points to dynamic membership. 'Devices', 'nested group' or 'assign an Azure role' points to a security group. 'Shared mailbox', 'Teams' or 'collaboration' points to a Microsoft 365 group. 'Hundreds of users from a spreadsheet' points to bulk create with the CSV template. 'User is managed on-premises' means change the attribute in AD DS, not in Entra ID.
Key terms
- User principal name (UPN)
- The sign-in name of an Entra user in email-address format, whose suffix must be a verified domain of the tenant.
- Security group
- An Entra group used to grant access to resources; it can contain users, devices, service principals and other groups.
- Microsoft 365 group
- A collaboration group with a shared mailbox, calendar, SharePoint site and optional Teams team; members can only be users.
- Assigned membership
- Group membership that an administrator or group owner maintains by adding and removing members by hand.
- Dynamic membership
- Group membership calculated automatically from a rule on user or device attributes; it requires Entra ID P1.
- Bulk create
- A portal operation that creates many users from an uploaded CSV template and reports per-row results.
- Microsoft Entra Connect
- The tool that synchronizes users and groups from on-premises AD DS into Entra ID, keeping on-premises as the source of authority.
A company hires 40 seasonal support agents. The administrator fills in the bulk create CSV template to create the accounts in one upload, sets each user's department to Support, and relies on a dynamic user security group with the rule user.department -eq Support that already holds the Reader role on the support resource group. The new agents get access without any further steps, and they lose it automatically when HR changes their department at the end of the season.
Check yourself
You need a group that automatically contains every Windows device in the tenant. Which group type and membership type do you choose?
A security group with dynamic device membership. Microsoft 365 groups cannot contain devices, and dynamic device rules are only supported on security groups.
A group has dynamic user membership, and a manager asks you to add one extra person by hand. What happens?
You cannot add members by hand to a dynamic group. Either change the user's attributes so the rule matches, change the rule, or use a separate assigned group.
What is the fastest portal method to create 200 cloud users?
Bulk create on the Users page: download the CSV template, fill in one row per user, upload it and review the results file for failed rows.
A team needs a shared mailbox, a calendar and a Teams workspace. Which group type fits?
A Microsoft 365 group, because it provisions collaboration resources; a security group is for granting access, not collaboration.