Learning path
Microsoft Entra - External ID and Customer Identity (CIAM)
Skill Level
Fundamentals
Duration 8 minutes
Updated Sep 27, 2026
About this learning path
Customer-facing apps need their own front door, separate from your workforce identities. This Byte covers Microsoft Entra External ID for customers: standing up an external tenant, configuring a branded user flow with the sign-up methods your customers expect, and keeping that tenant structurally isolated from your employee directory, so customer and workforce identities never collide, no matter how the app grows.
Your instructors
Prerequisites
- Microsoft SC-300 — Identity and Access Administrator
What you'll learn
- The difference between Microsoft Entra External ID for customers (CIAM) and the workforce/B2B side of External ID — and why the two are separate audiences entirely.
- The three building blocks behind any CIAM setup: tenant (a dedicated external directory for customers), flow (the configured sign-up/sign-in steps), and brand (making the experience look like yours, not Microsoft's)
- The end-to-end customer journey: new vs. returning customer, and how both land in the same branded, authenticated session
- Why customer and employee identities must never share a tenant, and what goes wrong if they do
- How to stand up a Microsoft Entra external tenant, kept structurally isolated from the workforce tenant.