Deep Microsoft Entra ID engineering, including Conditional Access policy design, phishing-resistant MFA, single sign-on, and federation across SAML, OIDC, and OAuth2, and verifying that enforcement takes effect across every access path, not only the expected one. Own access management, including Conditional Access, phishing-resistant MFA, and privileged access on a Zero Trust model, with least-privilege by default, just-in-time (JIT) elevation, and enforcement confirmed on every access path rather than only saved.