Back to main siteBack Contact us
Identity and Access

Microsoft Entra ID

Identity and Access

The identity you already own, used properly

Every organization on Microsoft 365 is already running Entra ID, formerly Azure Active Directory. The question is rarely whether to adopt it. It is whether the controls the licence already includes have been switched on, and which of them sit behind a higher tier.

SIGN-IN CONDITIONAL ACCESS who is the user is the device managed where from, how risky what is being reached ALLOW CHALLENGE BLOCK
The default tenant

An unconfigured tenant is a password-only perimeter

Microsoft 365 arrives working. Working is not the same as configured, and the gap between the two is where most tenant compromises happen.

Legacy authentication left open

Older protocols that cannot support modern verification are frequently still enabled, because something once needed them. An attacker with a valid password uses exactly that route, and the multi factor requirement configured elsewhere never applies.

Administrators without protection

The accounts with the most authority are often the ones exempted from the strongest controls, for convenience during setup and then permanently. A compromised global administrator is not an incident, it is the end of the tenant.

The pipeline

How a sign-in is actually decided

Conditional access is the mechanism that turns identity from a gate into a judgement, and it is the capability worth configuring first.

01

Signals are gathered about the attempt

Each sign-in carries context: the account, the device and whether it is managed, the network and location, the application being reached, and any risk detected about the user or the session.

None of these on its own decides anything. Together they distinguish an ordinary Tuesday from an attempt that deserves interruption.

02

Policy is evaluated, not merely applied

A policy states the conditions and the required response: permit, require stronger verification, require a compliant device, or block. Because the response varies with circumstance, security can be raised where it matters without making every routine login tedious.

That distinction matters practically. Verification demanded constantly and without reason teaches people to approve prompts reflexively, which is precisely the habit attackers rely on.

03

Privileged access is granted for a period, not permanently

Administrative rights can be held in a dormant state and activated when needed, with approval and a time limit. The estate then spends most of its life with no standing administrators at all, which substantially reduces what a single compromised account is worth.

04

Access is reviewed rather than assumed

Periodic reviews ask the people who own a group or application to confirm who still needs it. This is the control auditors increasingly ask to see evidence of, and the one most organizations have never run.

Specification

What sits behind which licence

This is the part worth establishing before designing anything, because assuming a capability is included and discovering otherwise mid-project is expensive.

CapabilityTypically requiresComment
basic MFAIncluded broadlyEnable it everywhere first
conditional accessA higher tierThe main reason to upgrade
risk based policyThe top identity tierDetects anomalous sessions
privileged accessThe top identity tierRemoves standing admin rights
access reviewsA higher tierOften needed for audit
Honest qualification

Where this is right, and where it is not enough

A strong fit

Organizations substantially on Microsoft. The integration with the rest of the tenant is genuine rather than marketed, the licence is frequently already held, and the conditional access model is capable enough to serve as the primary access control for the whole estate.

Consider carefully

Estates spread across Microsoft, Google and many independent applications may be better served by a vendor-neutral identity layer. Entra can federate widely, but an organization whose centre of gravity is not Microsoft should weigh that honestly rather than defaulting to what the subscription includes.

In short

Audit the tenant before buying anything else

Legacy authentication, unprotected administrators and absent conditional access are the three findings that appear in almost every first review, and all three are fixed with what most organizations already own.

Book the tenant review

Get in touch with Your Company

Questions about this solution? Reach us directly.