Azure Active Directory (Entra ID) as primary identity provider. - Hybrid configuration with on-premises Active Directory (financeforward.local) synchronized via Azure AD Connect. - Conditional Access policies enforce MFA for all cloud application access from external networks. - Privileged Access Ma