Entra says who. B5 says what they may do.
Entra ID is authoritative for identity, group membership, application roles, privileged assignments and risk signals. None of those is an authorization decision at a business method. This page documents how B5 consumes them and where its own responsibility begins.
This capability is a Q4 2026 roadmap extension. The sections below describe the planned shape and evidence; production availability has not yet been declared. The status above is rendered from the Product Truth Registry.
1. What this enforces
Nothing in Entra. B5 normalises what Entra asserts — users, groups, app roles, PIM assignments, workload identities and risk context — into the principal and context that an in-process decision is made against.
2. Where it enforces
At the B5 enforcement point. The Entra assertion arrives with the request; the decision happens where the action executes.
3. What evidence it produces
Which Entra claims were present, which were used, and which were absent. A decision that relied on a risk signal reads differently in an audit from one that did not have it.
4. Why you cannot assemble this from what you already own
Entra answers who is calling and how much the organisation trusts the session. It does not know that this caller may adjust this record but not that one, and it is not present at the method where the adjustment happens. Conditional Access gates the session; B5 gates the action.
5. What Q4 2026 adds
First-Class Microsoft Entra Mapping
Opinionated mapping for users, groups, app roles, service principals, managed identities, workload identities, PIM, CA and risk context.
6. Acceptance criteria
These are the conditions the capability must satisfy to be considered complete. They are quoted from the specification rather than paraphrased, because an acceptance criterion that has been reworded is no longer the criterion.
- Microsoft Entra principals normalize into one B5 principal model. MF-013
- Conditional Access and risk context are available to policy evaluation without trusting arbitrary client claims. MF-013
- Managed identity and service principal scenarios are covered by integration tests. MF-013
7. Dependencies
Beyond the platform baseline every extension depends on — the B5 security context, the evidence pipeline, configuration, the tenant model and the release registry — this capability also depends on:
- Microsoft Entra and Azure integration packages.
8. What is still open
The following are genuinely undecided rather than merely undocumented, and each one changes what the capability is:
- Which PIM states are treated as elevation and whether elevation is required to be recent as well as present.
- How risk context participates: as an input to policy, or as a hard gate.
- Whether group membership is read at decision time or projected, and the staleness bound that follows from that choice.
Every Q4 2026 extension is also held to four platform-wide requirements, six test classes and four release gates. They are published once, on the Q4 2026 roadmap, rather than repeated on every page.