Microsoft 365 Security

Microsoft Entra ID (formerly Azure AD) Security for UK Businesses

Microsoft Entra ID is the identity and access management system at the core of Microsoft 365. Every time a user signs in to Outlook, Teams, SharePoint, or any other Microsoft 365 service, Entra ID authenticates their identity and determines what they..

Overview

Microsoft Entra ID (formerly Azure AD) is the identity platform at the heart of every Microsoft 365 tenant. It manages user accounts, enforces Conditional Access policies, monitors sign-in risk, and provides Privileged Identity Management. Entra ID P1 — included in M365 Business Premium — enables the most important security features for UK SMEs.

Learn about M365 security

What is Microsoft Entra ID and what does it do?

Entra ID is the identity layer for Microsoft 365. It stores your user accounts, groups, devices and app registrations, then authenticates and authorises every request to Exchange, SharePoint, Teams and connected third-party apps. If a Microsoft 365 user signs in, Entra ID is the service that decides whether to let them through.

It is provisioned automatically with every Microsoft 365 subscription — you already own it. The 2023 rename from Azure AD signalled Microsoft folding the directory into a wider identity portfolio covering governance, permissions management and verification. The mechanics most SMEs rely on — accounts, groups, sign-in and conditional access — are unchanged.

Why is Entra ID the primary target for attackers?

Identity is the new perimeter. With data living in Microsoft 365 rather than behind an office firewall, attackers no longer breach a network — they sign in. Entra ID is the gatekeeper, so a single compromised account can expose mailboxes, files and any app that trusts Microsoft authentication.

According to Microsoft, over 95% of identity attacks are conducted using stolen credentials (Microsoft Security), usually harvested by phishing. The 2025 UK Cyber Security Breaches Survey names phishing as the most common attack vector for UK businesses, and Business Email Compromise — which relies on compromised Microsoft 365 accounts — cost UK businesses an estimated £190 million in 2024 (market estimate). A valid credential is the cheapest way in, and Entra ID is what stands between that credential and your data.

What security features are built into Microsoft Entra ID?

Entra ID ships with a layered set of identity controls. The most impactful are multi-factor authentication, risk-based protection, privileged access management and audit logging. Used together — and enforced through policy rather than left optional — they neutralise the credential-theft attacks that account for the overwhelming majority of breaches.

Multi-Factor Authentication (MFA)

MFA requires a second proof of identity — a Microsoft Authenticator push, a TOTP code or a hardware key — on top of the password. Microsoft's data shows "MFA blocks more than 99.99% of automated credential attacks" (Microsoft Security). Even a phished password fails without the second factor.

Enforce MFA through Conditional Access policies, not legacy per-user settings. Conditional Access lets you require MFA from untrusted networks while easing friction on a known office connection. Our MFA setup for Microsoft 365 guide walks through the rollout.

Entra ID Protection (risk-based access)

Included with Entra ID P2, Identity Protection scores the risk of every sign-in using Microsoft's global threat intelligence. Signals include impossible travel, known-malicious IPs, anonymous browsing and password-spray patterns. On high risk it can automatically block the sign-in, force a reset or require MFA — no administrator action needed.

Privileged Identity Management (PIM)

PIM, also in Entra ID P2, removes standing Global Admin rights. Instead of permanent elevated access — a major risk if that account is phished — administrators activate a role on demand, with approval and a time limit. PIM logs every activation, which supports access-control evidence for frameworks such as Cyber Essentials and ISO 27001.

Self-Service Password Reset and audit logging

Self-Service Password Reset (SSPR) lets users recover their own passwords via pre-registered methods, cutting helpdesk load; require at least two verification methods and exclude admins from it. Entra ID also logs every authentication event — successful and failed sign-ins, MFA challenges and risk events. Sign-in logs are retained 30 days on P1 and 90 days on P2; for longer retention, export them to Microsoft Sentinel or a SIEM.

What are the most common Entra ID weaknesses in UK SME tenants?

AMVIA's Microsoft 365 security audits keep finding the same gaps. Most are configuration oversights rather than missing licences — which means they are fixable quickly once identified. The recurring six below appear in tenant after tenant.

  • No MFA enforcement — MFA available but not required, leaving unregistered users on password-only sign-in.
  • Too many Global Admins — every Global Admin is full-tenant blast radius; keep it to two to four.
  • Legacy authentication unblocked — basic SMTP and POP3 bypass MFA entirely and are actively exploited.
  • Guest account sprawl — forgotten external B2B accounts that nobody reviews or expires.
  • No break-glass accounts — without emergency access accounts excluded from Conditional Access, one bad policy locks out every admin.
  • Default settings unchanged — Security Defaults is a floor, not a finished posture; most SMEs need tailored Conditional Access.

A structured Microsoft 365 security audit surfaces all six against NCSC and Microsoft baselines.

Which Entra ID licence do UK SMEs need?

For most UK SMEs, Microsoft 365 Business Premium is the right tier — it bundles Entra ID P1, which adds Conditional Access and SSPR on top of the free MFA baseline. Step up to Entra ID P2 only when you need PIM, risk-based Identity Protection or Access Reviews for governance.

FeatureEntra ID FreeEntra ID P1 (in Business Premium)Entra ID P2
Basic MFA (Security Defaults)YesYesYes
Conditional AccessYesYes
Self-Service Password ResetYesYes
Identity Protection (risk-based)LimitedYes
Privileged Identity ManagementYes
Access ReviewsYes

Microsoft 365 Business Premium lists at £16.90 per user per month (ex VAT, annual) and includes Entra ID P1 (Microsoft 365 UK pricing). For most 10–500-staff businesses, that bundle delivers enough identity security without buying standalone licences.

How does AMVIA secure Entra ID for UK businesses?

AMVIA manages Entra ID as a living configuration, not a one-off setup. An initial hardening goes stale as people join, roles change and apps are added, so we audit, enforce and review continuously as part of our managed Microsoft 365 service. One provider, security-first, with Microsoft-certified engineers.

Identity taskTypical SME, self-managedAMVIA managed Entra ID
MFAAvailable, inconsistently enforcedEnforced for all users via Conditional Access
Legacy authOften still openBlocked tenant-wide
Admin rightsStanding Global AdminsPIM just-in-time, no permanent roles
Guest accountsAccumulate uncheckedReviewed with expiry policies
Sign-in logsRarely reviewedMonitored 24/7 with alerting
Review cadenceAd hocQuarterly configuration review

Identity sits at the centre of our wider managed cybersecurity and Microsoft Defender for Business services, so a risky sign-in and a compromised endpoint are seen as one story, not two.

Key Points

What UK businesses need to know about Microsoft Entra ID.

Every M365 Tenant Has Entra ID

Entra ID Free is included in all M365 plans. Entra ID P1 (Conditional Access, PIM) is included in M365 Business Premium. Entra ID P2 adds risk-based access and identity protection.

Single Sign-On for Cloud Apps

Entra ID provides single sign-on (SSO) to thousands of third-party SaaS applications — reducing the number of separate credentials staff manage.

Identity Protection Detects Risk

Entra ID monitors sign-ins for risk signals — impossible travel, anonymous IP, leaked credentials — can trigger step-up authentication or block access automatically.

Privileged Identity Management

PIM requires just-in-time elevation for admin roles — no permanent Global Admin assignments — with approval workflow and full audit logging.

Entra ID Security Checklist

Conditional Access policies configured — MFA and device compliance enforced

Privileged Identity Management (PIM) deployed — no permanent Global Admin assignments

Stale accounts reviewed and removed — former staff, contractors, test accounts

Guest access reviewed — B2B guest accounts audited and unnecessary ones removed

Self-service password reset enabled — users can recover accounts without IT assistance

Sign-in logs monitored — risky sign-ins reviewed and investigated

Frequently Asked Questions

Secure Your Microsoft 365 Identity

AMVIA configures Entra ID — Conditional Access, PIM, and identity risk monitoring — as part of its comprehensive Microsoft 365 security service.