Microsoft Entra ID (formerly Azure AD) Security for UK Businesses
Microsoft Entra ID is the identity and access management system at the core of Microsoft 365. Every time a user signs in to Outlook, Teams, SharePoint, or any other Microsoft 365 service, Entra ID authenticates their identity and determines what they..
Overview
Microsoft Entra ID (formerly Azure AD) is the identity platform at the heart of every Microsoft 365 tenant. It manages user accounts, enforces Conditional Access policies, monitors sign-in risk, and provides Privileged Identity Management. Entra ID P1 — included in M365 Business Premium — enables the most important security features for UK SMEs.
Learn about M365 securityWhat is Microsoft Entra ID and what does it do?
Entra ID is the identity layer for Microsoft 365. It stores your user accounts, groups, devices and app registrations, then authenticates and authorises every request to Exchange, SharePoint, Teams and connected third-party apps. If a Microsoft 365 user signs in, Entra ID is the service that decides whether to let them through.
It is provisioned automatically with every Microsoft 365 subscription — you already own it. The 2023 rename from Azure AD signalled Microsoft folding the directory into a wider identity portfolio covering governance, permissions management and verification. The mechanics most SMEs rely on — accounts, groups, sign-in and conditional access — are unchanged.
Why is Entra ID the primary target for attackers?
Identity is the new perimeter. With data living in Microsoft 365 rather than behind an office firewall, attackers no longer breach a network — they sign in. Entra ID is the gatekeeper, so a single compromised account can expose mailboxes, files and any app that trusts Microsoft authentication.
According to Microsoft, over 95% of identity attacks are conducted using stolen credentials (Microsoft Security), usually harvested by phishing. The 2025 UK Cyber Security Breaches Survey names phishing as the most common attack vector for UK businesses, and Business Email Compromise — which relies on compromised Microsoft 365 accounts — cost UK businesses an estimated £190 million in 2024 (market estimate). A valid credential is the cheapest way in, and Entra ID is what stands between that credential and your data.
What security features are built into Microsoft Entra ID?
Entra ID ships with a layered set of identity controls. The most impactful are multi-factor authentication, risk-based protection, privileged access management and audit logging. Used together — and enforced through policy rather than left optional — they neutralise the credential-theft attacks that account for the overwhelming majority of breaches.
Multi-Factor Authentication (MFA)
MFA requires a second proof of identity — a Microsoft Authenticator push, a TOTP code or a hardware key — on top of the password. Microsoft's data shows "MFA blocks more than 99.99% of automated credential attacks" (Microsoft Security). Even a phished password fails without the second factor.
Enforce MFA through Conditional Access policies, not legacy per-user settings. Conditional Access lets you require MFA from untrusted networks while easing friction on a known office connection. Our MFA setup for Microsoft 365 guide walks through the rollout.
Entra ID Protection (risk-based access)
Included with Entra ID P2, Identity Protection scores the risk of every sign-in using Microsoft's global threat intelligence. Signals include impossible travel, known-malicious IPs, anonymous browsing and password-spray patterns. On high risk it can automatically block the sign-in, force a reset or require MFA — no administrator action needed.
Privileged Identity Management (PIM)
PIM, also in Entra ID P2, removes standing Global Admin rights. Instead of permanent elevated access — a major risk if that account is phished — administrators activate a role on demand, with approval and a time limit. PIM logs every activation, which supports access-control evidence for frameworks such as Cyber Essentials and ISO 27001.
Self-Service Password Reset and audit logging
Self-Service Password Reset (SSPR) lets users recover their own passwords via pre-registered methods, cutting helpdesk load; require at least two verification methods and exclude admins from it. Entra ID also logs every authentication event — successful and failed sign-ins, MFA challenges and risk events. Sign-in logs are retained 30 days on P1 and 90 days on P2; for longer retention, export them to Microsoft Sentinel or a SIEM.
What are the most common Entra ID weaknesses in UK SME tenants?
AMVIA's Microsoft 365 security audits keep finding the same gaps. Most are configuration oversights rather than missing licences — which means they are fixable quickly once identified. The recurring six below appear in tenant after tenant.
- No MFA enforcement — MFA available but not required, leaving unregistered users on password-only sign-in.
- Too many Global Admins — every Global Admin is full-tenant blast radius; keep it to two to four.
- Legacy authentication unblocked — basic SMTP and POP3 bypass MFA entirely and are actively exploited.
- Guest account sprawl — forgotten external B2B accounts that nobody reviews or expires.
- No break-glass accounts — without emergency access accounts excluded from Conditional Access, one bad policy locks out every admin.
- Default settings unchanged — Security Defaults is a floor, not a finished posture; most SMEs need tailored Conditional Access.
A structured Microsoft 365 security audit surfaces all six against NCSC and Microsoft baselines.
Which Entra ID licence do UK SMEs need?
For most UK SMEs, Microsoft 365 Business Premium is the right tier — it bundles Entra ID P1, which adds Conditional Access and SSPR on top of the free MFA baseline. Step up to Entra ID P2 only when you need PIM, risk-based Identity Protection or Access Reviews for governance.
| Feature | Entra ID Free | Entra ID P1 (in Business Premium) | Entra ID P2 |
|---|---|---|---|
| Basic MFA (Security Defaults) | Yes | Yes | Yes |
| Conditional Access | — | Yes | Yes |
| Self-Service Password Reset | — | Yes | Yes |
| Identity Protection (risk-based) | — | Limited | Yes |
| Privileged Identity Management | — | — | Yes |
| Access Reviews | — | — | Yes |
Microsoft 365 Business Premium lists at £16.90 per user per month (ex VAT, annual) and includes Entra ID P1 (Microsoft 365 UK pricing). For most 10–500-staff businesses, that bundle delivers enough identity security without buying standalone licences.
How does AMVIA secure Entra ID for UK businesses?
AMVIA manages Entra ID as a living configuration, not a one-off setup. An initial hardening goes stale as people join, roles change and apps are added, so we audit, enforce and review continuously as part of our managed Microsoft 365 service. One provider, security-first, with Microsoft-certified engineers.
| Identity task | Typical SME, self-managed | AMVIA managed Entra ID |
|---|---|---|
| MFA | Available, inconsistently enforced | Enforced for all users via Conditional Access |
| Legacy auth | Often still open | Blocked tenant-wide |
| Admin rights | Standing Global Admins | PIM just-in-time, no permanent roles |
| Guest accounts | Accumulate unchecked | Reviewed with expiry policies |
| Sign-in logs | Rarely reviewed | Monitored 24/7 with alerting |
| Review cadence | Ad hoc | Quarterly configuration review |
Identity sits at the centre of our wider managed cybersecurity and Microsoft Defender for Business services, so a risky sign-in and a compromised endpoint are seen as one story, not two.
Key Points
What UK businesses need to know about Microsoft Entra ID.
Every M365 Tenant Has Entra ID
Entra ID Free is included in all M365 plans. Entra ID P1 (Conditional Access, PIM) is included in M365 Business Premium. Entra ID P2 adds risk-based access and identity protection.
Single Sign-On for Cloud Apps
Entra ID provides single sign-on (SSO) to thousands of third-party SaaS applications — reducing the number of separate credentials staff manage.
Identity Protection Detects Risk
Entra ID monitors sign-ins for risk signals — impossible travel, anonymous IP, leaked credentials — can trigger step-up authentication or block access automatically.
Privileged Identity Management
PIM requires just-in-time elevation for admin roles — no permanent Global Admin assignments — with approval workflow and full audit logging.
Entra ID Security Checklist
Conditional Access policies configured — MFA and device compliance enforced
Privileged Identity Management (PIM) deployed — no permanent Global Admin assignments
Stale accounts reviewed and removed — former staff, contractors, test accounts
Guest access reviewed — B2B guest accounts audited and unnecessary ones removed
Self-service password reset enabled — users can recover accounts without IT assistance
Sign-in logs monitored — risky sign-ins reviewed and investigated
Frequently Asked Questions
They are the same product. Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023 as part of a wider rebranding of its identity and security portfolio. The functionality, licensing tiers and capabilities are unchanged — only the name is different, so existing Azure AD configurations continue to work exactly as before.
Yes. Every Microsoft 365 subscription includes Entra ID Free, which covers basic identity management and MFA via Security Defaults. Microsoft 365 Business Premium includes Entra ID P1, adding Conditional Access and Self-Service Password Reset. Entra ID P2, which adds Privileged Identity Management and risk-based Identity Protection, is available as an add-on licence.
A compromised Global Admin gives an attacker unrestricted control of the entire Microsoft 365 tenant — every mailbox, file and setting. They can create admin accounts, disable security controls, exfiltrate data and lock out legitimate administrators. This is why you should keep Global Admins to a handful, enforce MFA on all of them, and use PIM to remove standing access.
Warning signs include sign-ins from unusual locations, new accounts or app registrations you did not create, unexpected changes to Conditional Access or MFA settings, mailbox forwarding rules, and alerts from Identity Protection. AMVIA's managed Microsoft 365 service monitors these indicators continuously so suspicious activity is caught and investigated early.
Yes. Frameworks such as Cyber Essentials and ISO 27001 require multi-factor authentication, unique user accounts, least-privilege access and account management — all enforced and evidenced through Entra ID's Conditional Access, PIM and audit logs. A properly configured tenant is a substantial, demonstrable step toward meeting those control requirements.
For most UK SMEs, Entra ID P1 — included with Microsoft 365 Business Premium — is sufficient, giving you Conditional Access and SSPR. Move to P2 when you need just-in-time admin access via PIM, automated risk-based sign-in protection, or Access Reviews for tighter governance, typically driven by regulatory obligations or larger user counts.
Secure Your Microsoft 365 Identity
AMVIA configures Entra ID — Conditional Access, PIM, and identity risk monitoring — as part of its comprehensive Microsoft 365 security service.