Microsoft Entra ID (formerly Azure AD) for SME Security
Microsoft Entra ID is the identity platform at the heart of Microsoft 365 — managing user accounts, enforcing authentication policies, and controlling access to applications. Understanding Entra ID is essential for any business managing Microsoft 365 security.
Overview
Microsoft Entra ID (formerly Azure AD) is the identity platform at the heart of every Microsoft 365 tenant. It manages user accounts, enforces Conditional Access policies, monitors sign-in risk, and provides Privileged Identity Management. Entra ID P1 — included in M365 Business Premium — enables the most important security features for UK SMEs.
Learn about M365 securityWhat Is Microsoft Entra ID?
Microsoft Entra ID (formerly Azure Active Directory or Azure AD) is Microsoft's cloud-based identity and access management platform. Every Microsoft 365 tenant includes an Entra ID directory — it is where user accounts are created, where group memberships are managed, where authentication happens, and where access policies are configured. When a user signs in to Outlook, Teams, or SharePoint, it is Entra ID that authenticates them.
The rebrand from Azure Active Directory to Microsoft Entra ID happened in 2023. The underlying technology is the same — if you see references to Azure AD in documentation or settings, these refer to the same service now called Entra ID. The admin portal is now at entra.microsoft.com.
Entra ID Licence Tiers
Entra ID is available in three tiers. Entra ID Free is included in all Microsoft 365 plans — it provides basic user and group management, SSO for up to 10 applications, and basic security reporting. Entra ID P1 is included in Microsoft 365 Business Premium — it adds Conditional Access, Privileged Identity Management (PIM), and self-service password reset. Entra ID P2 is included in Microsoft 365 E5 — it adds Identity Protection (risk-based Conditional Access using machine learning to assess sign-in and user risk) and Identity Governance.
For most UK SMEs on Business Premium, Entra ID P1 provides the critical security capabilities — Conditional Access for MFA enforcement and device compliance, and PIM for admin account protection.
Conditional Access: The Core Security Control
Conditional Access is the most important security feature in Entra ID P1. It is a policy engine that evaluates every access request — checking who is trying to access, from which device, from which location, with what level of sign-in risk — and determines whether to grant access, require additional verification, or block. AMVIA configures Conditional Access as the primary mechanism for enforcing MFA, blocking legacy authentication, and requiring device compliance across all M365 applications.
Privileged Identity Management (PIM)
Privileged Identity Management addresses one of the most significant security risks in Microsoft 365: permanent admin role assignments. When an account is permanently assigned Global Administrator, it means that if that account is compromised at any time — through phishing, credential theft, or malware — the attacker immediately has unrestricted access to the entire M365 tenant. PIM replaces permanent assignment with just-in-time elevation.
With PIM, admin roles are not permanently active. When a user needs to perform an admin task, they request role activation — providing a justification, specifying a duration, and sometimes requiring approval from another admin. The role is active for the specified duration and then automatically expires. Every activation is logged, providing a full audit trail of who activated which admin role, when, for how long, and what they did. AMVIA configures PIM for all admin accounts as a standard part of its M365 security service.
Identity Protection and Risk Signals
Entra ID continuously monitors sign-in activity for risk signals. These include: sign-ins from anonymous IP addresses or known Tor exit nodes; impossible travel (a user appearing to sign in from two geographically distant locations within a timeframe that makes travel impossible); leaked credentials (Microsoft monitors dark web sources for credential dumps); and atypical sign-in properties (unusual device, location, or time).
With Entra ID P1, these risk signals can inform Conditional Access policies — for example, requiring step-up MFA when a sign-in is flagged as medium risk, or blocking access entirely for high-risk sign-ins. With Entra ID P2, full Identity Protection adds more sophisticated risk modelling and can automatically remediate low-risk events.
Key Considerations for UK SMEs
- Entra ID P1 (in M365 Business Premium) enables the most important security controls — Conditional Access and PIM
- Review and remove stale accounts regularly — former employees, contractors, and test accounts are attack surface
- Manage guest access carefully — Entra ID B2B allows external users into your tenant; review these accounts regularly
- Enable self-service password reset — reduces helpdesk burden and ensures users can recover accounts without IT assistance
- Monitor the Entra ID sign-in logs — they provide visibility of authentication activity and are essential for incident investigation
How AMVIA Can Help
AMVIA configures and manages Entra ID security as part of its Microsoft 365 security service. This includes Conditional Access policy configuration and management, PIM setup for all admin accounts, review and remediation of stale accounts and guest access, and monitoring of identity risk signals through AmviaIQ. For businesses migrating from on-premises Active Directory to Entra ID, AMVIA manages the identity migration as part of its M365 migration service. Contact AMVIA on 0333 733 8050.
Key Points
What UK businesses need to know about Microsoft Entra ID.
Every M365 Tenant Has Entra ID
Entra ID Free is included in all M365 plans. Entra ID P1 (Conditional Access, PIM) is included in M365 Business Premium. Entra ID P2 adds risk-based access and identity protection.
Single Sign-On for Cloud Apps
Entra ID provides single sign-on (SSO) to thousands of third-party SaaS applications — reducing the number of separate credentials staff manage.
Identity Protection Detects Risk
Entra ID monitors sign-ins for risk signals — impossible travel, anonymous IP, leaked credentials — and can trigger step-up authentication or block access automatically.
Privileged Identity Management
PIM requires just-in-time elevation for admin roles — no permanent Global Admin assignments — with approval workflow and full audit logging.
Entra ID Security Checklist
Conditional Access policies configured — MFA and device compliance enforced
Privileged Identity Management (PIM) deployed — no permanent Global Admin assignments
Stale accounts reviewed and removed — former staff, contractors, test accounts
Guest access reviewed — B2B guest accounts audited and unnecessary ones removed
Self-service password reset enabled — users can recover accounts without IT assistance
Sign-in logs monitored — risky sign-ins reviewed and investigated
Frequently Asked Questions
Active Directory (AD) is Microsoft's traditional on-premises directory service — running on a server in your office, managing user accounts for domain-joined computers. Entra ID is Microsoft's cloud-based equivalent, designed for cloud-first and hybrid environments. Entra ID manages user accounts for Microsoft 365 and cloud applications. Many businesses run both: on-premises AD for legacy applications and domain-joined computers, synchronised with Entra ID for cloud access — a configuration called Hybrid Identity.
For most UK SMEs, Entra ID P1 (included in M365 Business Premium) provides the critical security features — Conditional Access for MFA and device compliance, PIM for admin account protection, and basic identity risk signals. Entra ID P2 (in M365 E5) adds machine learning-based Identity Protection with more sophisticated risk modelling, Identity Governance for access reviews, and Entitlement Management. P2 is appropriate for businesses with more complex governance requirements or elevated risk profiles.
Entra ID B2B (Business-to-Business) allows you to invite external users — partners, clients, contractors — into your Microsoft 365 environment as guests. They authenticate with their own credentials and access only what you explicitly share with them. AMVIA recommends configuring B2B settings to require MFA for all guest users, limiting which applications guests can access, and conducting regular guest access reviews to remove accounts that are no longer needed.
Secure Your Microsoft 365 Identity
AMVIA configures Entra ID — Conditional Access, PIM, and identity risk monitoring — as part of its comprehensive Microsoft 365 security service.
Related Resources
Conditional Access Guide
Conditional Access in Entra ID — the most powerful security control in Microsoft 365.
Microsoft 365 Security Guide
How Entra ID fits within a complete M365 security strategy for UK businesses.
Zero Trust Security
Entra ID and Conditional Access are the foundation of zero trust identity security.