The one-sentence version
Microsoft 365 is what you use. Entra ID is who you are. Intune is what manages your device. Defender is what's watching for trouble. Everything else in this entire learning hub is a deeper dive into one of those four ideas.
CLUSTER 0.10
Four names get thrown around constantly in any Microsoft shop: Microsoft 365, Entra ID, Intune, and Defender. This cluster is the ten-minute answer to "wait, what do those actually do?" — before any of the technical domains below assume you already know.
Microsoft 365 is what you use. Entra ID is who you are. Intune is what manages your device. Defender is what's watching for trouble. Everything else in this entire learning hub is a deeper dive into one of those four ideas.
Drag to rotate · click a node to jump to that pillar
Think of it as: the office building itself
Outlook, Word, Excel, Teams, SharePoint — the actual apps people open every day to do their jobs. When someone says "I sent it on Teams" or "check the shared drive," this is the layer they're standing in. It's the what you use layer.
Think of it as: the ID badge that gets you through every door
Every time you type your work email and password, Entra ID (formerly Azure Active Directory) is the thing checking "is this really them, and what are they allowed to open?" No app in Microsoft 365 works without it quietly running underneath. It's the who you are layer.
Think of it as: the IT department's remote hands
Intune is how a company sets up a new laptop before it even reaches you, pushes out required apps, enforces a passcode on your phone, and can wipe company data if a device is lost — without someone physically touching it. It's the what manages your device layer.
Think of it as: the security guard who never sleeps
Defender is the family of tools scanning email for phishing, watching devices for malware, and flagging when a sign-in looks suspicious (like a login from a country you've never visited). Most of the time you never see it working — that's the point. It's the what's watching for trouble layer.
These aren't four separate products bolted together — they're layered, and each one leans on the one before it:
REAL-WORLD SCENARIO
Priya starts a new job on Monday. Here's what actually happens, mapped to the four pillars above:
8:45am — IT hands her a laptop that was never physically configured by a person. It was Intune-enrolled before it left the box; the moment she connects to Wi-Fi, her required apps start installing themselves.
8:52am — She signs in with the email and temporary password HR gave her. Entra ID verifies it's really her, and because it's her first login, it prompts her to set up multi-factor authentication.
9:10am — She opens Outlook and Teams for the first time — Microsoft 365 — and finds she's already been added to her team's channels and given access to the shared files she needs.
2:30pm — She clicks a link in a slightly-off-looking email. Defender has already scanned it, flags it as phishing, and blocks the page before it loads — she never even sees what would have happened.
Priya never thinks about any of this by name. That's the entire point — when it's working, these four pillars are invisible. You only notice them when one breaks.
Every technical domain in this hub is really just one of these four pillars, taken much further. Identity & Security is Entra ID in depth. Hybrid, Endpoint & Workplace is Intune in depth. Security Operations is Defender in depth. If none of those feel ready yet, the rest of The Stack Floor covers the general IT fundamentals underneath all of them.