Video
•
4:47
•
September 27, 2026
Microsoft Entra External ID and Customer Identity (CIAM)
This ATC Byte covers Microsoft Entra External ID for customers: standing up an external tenant, configuring a branded user flow with the sign-up methods your customers expect, and keeping that tenant structurally isolated from your employee directory, so customer and workforce identities never collide, no matter how the app grows.
What You Learn
- The difference between Microsoft Entra External ID for customers (CIAM) and the workforce/B2B side of External ID — and why the two are separate audiences entirely
- The three building blocks behind any CIAM setup: tenant (a dedicated external directory for customers), flow (the configured sign-up/sign-in steps), and brand (making the experience look like yours, not Microsoft's)
- How to configure a user flow with sign-up methods customers actually expect — email/password, one-time passcodes, or social identity providers like Google
- How to apply Company branding (logo, colors, background) so the sign-up experience matches the product, not a generic Microsoft page
- How to register an application and link it to a user flow (and that one flow can serve multiple apps)
- The end-to-end customer journey: new vs. returning customer, and how both land in the same branded, authenticated session
- Why customer and employee identities must never share a tenant, and what goes wrong if they do
- How to stand up a Microsoft Entra external tenant, kept structurally isolated from the workforce tenant
Certify Your Knowledge
- Microsoft SC-300 — Identity and Access Administrator Associate