Entra decides who, and now what.
Microsoft Entra is the directory of record in a large share of enterprises, which makes it the thing an Atlassian estate has to obey. Our work is Entra as the directory of record, agent identity, and Azure DevOps as a migration source.
We work across Azure where Entra is the directory of record. Agent identity arrived here early, which makes it one of the few places the lifecycle question is already answerable.
What it is
Microsoft Entra is the directory of record in a large share of enterprises, which makes it the thing an Atlassian estate has to obey. Entra Agent ID extended that model to non-human identities earlier than most, so the lifecycle question has a real answer here rather than a roadmap.
We work across Azure rather than reselling it. Most engagements meet it at the identity boundary, and a good number meet it at Azure DevOps, which is usually a source rather than a destination.
Where it fits
Azure touches three layers. L1 is Entra ID and Entra Agent ID, the directory for people and for agents. L2 is the platform, including Azure DevOps, which in our engagements is generally the system being migrated away from. L3 is Azure Policy, where guardrails are enforced rather than described. L4 is Foundry, where models reach production and inherit whatever identity boundary exists.
What we do with it
Entra as the single directory
Atlassian and the wider estate resolving access through one directory rather than maintaining a second list.
Agent identity lifecycle
Non-human identities issued, scoped, reviewed, and retired on the same terms as people.
Azure DevOps as a migration source
Work and pipelines moved into the governed estate, with the access model designed rather than copied.
Policy and evidence
Guardrails that are enforced and produce a record, not a document describing intent.