ChatGPT:
Microsoft Entra ID(以前叫 Azure Active Directory / Azure AD)主要分 Free、P1、P2 三個級別。簡單講:
-
Free:適合個人、小型自建系統、基本登入保護
-
P1:企業身份管理 + Conditional Access(最常用升級)
-
P2:高安全企業(風險偵測、PIM、治理)
| 功能 | Entra ID Free | Entra ID P1 | Entra ID P2 |
|---|---|---|---|
| Microsoft 帳戶目錄(Users / Groups) | ✅ | ✅ | ✅ |
| SSO 單一登入 | ✅ | ✅ | ✅ |
| Microsoft Authenticator MFA | ✅ | ✅ | ✅ |
| Security Defaults MFA | ✅ | ✅ | ✅ |
| 自助重設密碼 SSPR | ✅ | ✅ | ✅ |
| Conditional Access(條件式存取) | ❌ | ✅ | ✅ |
| Dynamic Groups(動態群組) | ❌ | ✅ | ✅ |
| Application Proxy(發布內網 App) | ❌ | ✅ | ✅ |
| 混合 AD(On-prem AD)整合 | ❌ | ✅ | ✅ |
| Identity Protection(登入風險分析) | ❌ | ❌ | ✅ |
| Risk-based Conditional Access | ❌ | ❌ | ✅ |
| Privileged Identity Management (PIM) | ❌ | ❌ | ✅ |
| Access Reviews(存取審查) | ❌ | 部分 | ✅ |
1. Entra ID Free(免費版)
其實功能已經不少:
✅ 建立使用者 ✅ OAuth / OpenID Connect 登入 ✅ Microsoft Graph API ✅ MFA ✅ Passkey / FIDO2 支援(部分情況) ✅ Security Defaults
適合:
-
個人 Microsoft Login
-
小型網站 OAuth
-
n8n / OpenWebUI / 自建 SaaS 登入
-
Docker 私人服務 SSO
例如你的環境:
Cloudflare Tunnel
|
|
Authentik / Entra ID
|
|
n8n
Nextcloud
OpenWebUI
Vaultwarden
Free 已經可以做到基本身份驗證。
2. Entra ID P1(最值得升級)
P1 最大賣點:
Conditional Access(條件式存取)
例如:
「只有香港 IP 可以登入」
IF:
使用者登入 n8n
AND:
不是香港 IP
THEN:
要求 MFA
或拒絕
又例如:
Windows Hello
↓
Entra ID
↓
允許登入
可以設定:
-
必須 MFA
-
必須符合裝置要求
-
阻止舊式登入
-
地區限制
這是企業最常用功能。learn.microsoft.com
Dynamic Groups
例如:
自動建立:
所有 Android 使用者
所有管理員
所有香港員工
所有 Windows 11 裝置
不用手動加人。
Application Proxy
可以把內網服務發布出去:
例如:
公司內部 ERP
|
Entra Application Proxy
|
外網安全登入
不用開 Port。
3. Entra ID P2(安全專家級)
P2 主要增加:
Identity Protection
Microsoft 會分析:
-
登入位置
-
IP 信譽
-
異常行為
-
被盜帳戶可能性
例如:
平時:
香港登入
突然:
俄羅斯 IP
+
新裝置
+
大量失敗登入
Entra 判定高風險。
可以:
要求重新 MFA
或者
封鎖登入
Privileged Identity Management (PIM)
非常適合管理員:
平時:
Ben = 普通 User
需要管理 Azure:
啟用 Global Admin
↓
30分鐘後自動失效
避免永久 Admin 帳戶被盜。
以你的 Docker / Cloudflare 架構,我會這樣建議
你的環境:
-
Oracle Cloud VPS
-
Cloudflare Tunnel
-
n8n
-
Nextcloud
-
Authentik
-
OpenWebUI
-
Infisical
-
多個 Docker Web App
其實:
最佳組合:
免費方案
Entra ID Free
+
Cloudflare Zero Trust
+
Authentik
已經很強。
如果想做 Production Grade:
升級:
Entra ID P1
+
Cloudflare Zero Trust
+
Authentik
原因:
你可以做到:
登入 n8n
↓
Entra Conditional Access
↓
要求 Passkey / Windows Hello
↓
Cloudflare Access
↓
Docker Service
安全程度接近企業。
P2 對你目前用途
我覺得暫時沒有必要。
P2 比較適合:
-
50人以上公司
-
金融
-
IT 管理團隊
-
高權限 Azure 環境
我的建議排名(以你的情況)
| 方案 | 推薦 |
|---|---|
| Entra ID Free | ⭐⭐⭐⭐⭐ 先用 |
| Entra ID P1 | ⭐⭐⭐⭐⭐ 未來最佳升級 |
| Entra ID P2 | ⭐⭐ 暫時浪費 |
你目前其實更值得研究的是:
Entra ID Free + Cloudflare Zero Trust + Passkey + Authentik 的整合架構。
這套可以把你的 Oracle VPS Docker 平台做到類似企業 Zero Trust 架構。
User
Entra ID Free + Cloudflare Zero Trust + Passkey + Authentik 的整合架構。
ChatGPT:
以你目前的架構(Oracle Cloud VPS + Cloudflare Tunnel + Docker + Authentik + n8n/Nextcloud/OpenWebUI 等),Entra ID Free + Cloudflare Zero Trust + Passkey + Authentik 可以設計成一個接近企業級 Zero Trust 的身份架構。
整體概念:
6
使用者
|
Windows Hello / Face ID / 指紋
|
Passkey (FIDO2)
|
▼
Microsoft Entra ID Free
(Identity Provider)
|
OpenID Connect / OAuth2
|
▼
Cloudflare Zero Trust Access
(Policy Enforcement Point)
|
Cloudflare Tunnel
|
▼
Docker Private Network
cf_network
|
┌──────────────┼──────────────┐
│ │ │
Authentik n8n Nextcloud
│
OpenWebUI
│
Vaultwarden
角色分工
1. Microsoft Entra ID Free = 身份來源(Identity Provider)
負責:
✅ 誰是你 ✅ MFA ✅ Passkey ✅ Windows Hello ✅ iPhone Face ID ✅ Android 指紋
例如:
你登入:
https://n8n.benhoweb.com
Cloudflare 問:
你是誰?
跳去:
login.microsoftonline.com
Microsoft:
Passkey?
↓
Windows Hello
↓
成功
返回:
Ben 已驗證
2. Cloudflare Zero Trust = 門口保安
Cloudflare Access 做:
Authentication
確認:
Ben @ outlook.com
是真的。
Authorization
決定:
誰可以進:
例如:
n8n:
Allow:
ben@outlook.com
Deny:
everyone else
Nextcloud:
Allow:
ben@outlook.com
family@example.com
Policy 例子
n8n
Application:
n8n
Policy:
Allow
Include:
Email:
ben@example.com
Require:
Login Method:
Passkey
3. Authentik = 內部 IAM
你已經在用 Authentik。
它適合管理:
-
Docker App
-
LDAP
-
OAuth Provider
-
SAML
-
群組權限
例如:
Cloudflare
|
|
Entra ID
|
|
Authentik
|
|
-----------------
| | |
n8n OpenWebUI Nextcloud
為什麼不用 Entra 直接管理全部?
因為:
Entra 強項:
✅ Windows ✅ Microsoft 生態 ✅ MFA ✅ Conditional Access
Authentik 強項:
✅ 自建服務 ✅ Docker ✅ OAuth ✅ LDAP ✅ 群組管理
兩者互補。
推薦你的實際架構
外部入口
所有網址:
n8n.benhoweb.com
next.benhoweb.com
ai.benhoweb.com
vault.benhoweb.com
全部:
Cloudflare Tunnel
不要:
Port 80
Port 443
直接暴露 VPS。
登入流程
例如登入 n8n:
Step 1
打開:
https://n8n.benhoweb.com
Step 2
Cloudflare Access:
需要登入
Step 3
跳 Microsoft:
Sign in with Microsoft
Step 4
Passkey:
Windows:
Windows Hello
↓
Face / PIN / 指紋
手機:
Face ID
↓
完成
Step 5
Cloudflare 發 Access JWT:
CF-Access-JWT-Assertion
Step 6
放行:
n8n Docker container
Passkey 設定建議
你的裝置:
Windows
啟用:
Windows Hello
Microsoft Entra:
Authentication Methods
Enable:
FIDO2 Security Key
Passkey
iPhone 16
加入:
iCloud Keychain Passkey
Samsung A53
使用:
Google Password Manager Passkey
Docker 層安全
你的 compose 建議:
所有服務:
networks:
cf_network:
external: true
不要:
ports:
- 5678:5678
改:
expose:
- 5678
只有:
cloudflared
可以接觸。
Authentik + Entra ID 整合方式
有兩種:
方法 A(推薦)
Entra → Cloudflare
Authentik 獨立
Internet
|
Cloudflare Access
|
Entra Passkey
|
Docker
簡單、安全。
方法 B(更企業)
Entra 作 Authentik 上游:
Entra ID
|
OIDC
|
Authentik
|
OAuth
|
Apps
流程:
登入任何 Docker App
↓
Authentik
↓
要求 Entra 驗證
↓
Passkey
↓
登入
優點:
所有 App 統一登入。
我會建議你的最終架構
以你的 Oracle VPS:
Passkey
|
Entra ID Free
|
|
Cloudflare Access
|
Cloudflare Tunnel
|
cf_network
|
┌───────────┼───────────┐
│ │ │
Authentik n8n Nextcloud
│
OpenWebUI
│
Vaultwarden
升級路線:
現在:
Entra Free
+
Cloudflare Zero Trust Free
+
Authentik
已經非常強。
未來:
Entra P1
+
Conditional Access
+
Device Compliance
就是企業級。
以你的情況,我下一步會建議做:
「Cloudflare Zero Trust + Entra ID Free + Passkey 實際設定教學(Dashboard 最新介面)」
因為你之前已經在設定 Cloudflare Passkey-only,但 Cloudflare Dashboard 改版後比較難找位置。
User
Cloudflare Zero Trust + Entra ID Free + Passkey 實際設定教學(Dashboard 最新介面
ChatGPT:
下面以你的實際環境設計:
-
Oracle Cloud VPS(無 Public IP)
-
Cloudflare Tunnel
-
Docker
cf_network -
n8n / Nextcloud / OpenWebUI / Authentik
-
Windows + iPhone 16 + Android
目標:
不用密碼,只用 Windows Hello / Face ID / 指紋登入你的 Docker 服務
架構:
Windows Hello
iPhone Face ID
Android Fingerprint
|
|
Passkey
|
▼
Microsoft Entra ID Free
(身份驗證中心)
|
|
OpenID Connect / OAuth
|
▼
Cloudflare Zero Trust Access
(入口保護)
|
|
Cloudflare Tunnel
|
|
Docker cf_network
|
┌──────────────┼──────────────┐
│ │ │
n8n Nextcloud Authentik
Entra ID Free 已支援 Passkey (FIDO2),不需要 P1/P2 才能使用。learn.microsoft.com
第一部分:Microsoft Entra ID Free 設定
1. 建立 Entra Tenant
進入:
登入你的 Microsoft 帳號。
進入:
Microsoft Entra ID
↓
Overview
↓
Tenant information
記錄:
Tenant ID
Primary domain
例如:
xxxx.onmicrosoft.com
2. 建立你的管理帳號
位置:
Entra ID
↓
Users
↓
New user
建立:
ben
例如:
ben@yourtenant.onmicrosoft.com
3. 開啟 Passkey
位置:
Entra ID
↓
Protection
↓
Authentication methods
↓
Policies
找到:
Passkey (FIDO2)
開啟:
Enable:
YES
Target:
All users
儲存。
Microsoft 官方目前流程也是在 Authentication methods → Policies 開啟 Passkey。learn.microsoft.com
4. 加入你的 Passkey
登入:
https://mysignins.microsoft.com/security-info
選:
Add sign-in method
選:
Passkey
然後:
Windows:
Windows Hello
↓
Face / PIN / Fingerprint
iPhone:
Face ID
↓
Save Passkey
Android:
Fingerprint
↓
Google Password Manager
完成後你會看到:
Passkey
Windows Hello
iPhone
Microsoft 的註冊流程也是從 Security info → Add sign-in method → Passkey。learn.microsoft.com
第二部分:Cloudflare Zero Trust 設定
登入:
Cloudflare Zero Trust Dashboard
1. 加入 Microsoft 作 Identity Provider
位置:
Settings
↓
Authentication
↓
Login methods
找到:
Microsoft
按:
Add
Cloudflare 會要求:
Application ID
Client Secret
第三部分:建立 Azure App Registration
回 Entra:
Entra ID
↓
App registrations
↓
New registration
名稱:
Cloudflare Access
Supported account:
選:
Accounts in this organizational directory only
Redirect URI:
Cloudflare 會提供,例如:
https://your.cloudflareaccess.com/cdn-cgi/access/callback
建立。
得到:
Application (client) ID
保存。
建立 Secret:
Certificates & secrets
↓
New client secret
保存:
Client Secret Value
⚠️ 只會顯示一次。
回 Cloudflare:
填入:
Client ID
Client Secret
Tenant ID
Save。
第四部分:建立 Cloudflare Access Application
例如保護 n8n:
位置:
Zero Trust
↓
Access
↓
Applications
↓
Add application
選:
Self-hosted
填:
Application name:
n8n
Domain:
n8n.benhoweb.com
Policy:
建立:
Allow
條件:
Selector:
Emails
Value:
你的 Entra Email
例如:
ben@xxxx.onmicrosoft.com
Authentication:
選:
Microsoft
完成。
第五部分:強制 Passkey-only
這一步最重要。
Cloudflare:
Access
↓
Authentication
↓
Policies
新增:
Require
設定:
Login method:
Microsoft
然後 Entra:
Authentication strengths
建立:
Passkey Only
允許:
FIDO2 Passkey
結果:
登入流程:
打開:
n8n.benhoweb.com
Cloudflare:
登入
Microsoft:
選帳號
Windows Hello:
😀 Face
成功
完全不用輸入密碼。
第六部分:你的 Docker 配置
保持:
networks:
cf_network:
external: true
例如:
n8n:
services:
n8n:
image: n8nio/n8n
networks:
- cf_network
不要:
ports:
- 5678:5678
因為:
Cloudflare Tunnel → Docker
已經足夠。
第七部分:推薦你的最終安全策略
管理服務
例如:
dockhand.benhoweb.com
n8n.benhoweb.com
infisical.benhoweb.com
設定:
Entra Passkey
+
Cloudflare Access
普通服務
例如:
music.benhoweb.com
nextcloud.benhoweb.com
可以:
Authentik OAuth
最終效果
你的登入安全等級:
| 層 | 技術 |
|---|---|
| 網絡入口 | Cloudflare Tunnel |
| 防火牆 | Cloudflare Access |
| 身份 | Entra ID Free |
| MFA | Passkey |
| 設備驗證 | Windows Hello / Face ID |
| 內部 SSO | Authentik |
| Secrets | Infisical |
其實已經接近小型企業 Zero Trust 架構。
下一步我建議做:
「Cloudflare Access + Entra ID + Authentik 三層 SSO 架構設計」
因為你的 Docker 服務很多,如果全部直接接 Entra,後期管理會比較亂。你現在最適合的是: Cloudflare 管入口,Entra 管身份,Authentik 管 Docker 應用權限。