Microsoft Entra ID
The identity you already own, used properly
Every organization on Microsoft 365 is already running Entra ID, formerly Azure Active Directory. The question is rarely whether to adopt it. It is whether the controls the licence already includes have been switched on, and which of them sit behind a higher tier.
An unconfigured tenant is a password-only perimeter
Microsoft 365 arrives working. Working is not the same as configured, and the gap between the two is where most tenant compromises happen.
Legacy authentication left open
Older protocols that cannot support modern verification are frequently still enabled, because something once needed them. An attacker with a valid password uses exactly that route, and the multi factor requirement configured elsewhere never applies.
Administrators without protection
The accounts with the most authority are often the ones exempted from the strongest controls, for convenience during setup and then permanently. A compromised global administrator is not an incident, it is the end of the tenant.
How a sign-in is actually decided
Conditional access is the mechanism that turns identity from a gate into a judgement, and it is the capability worth configuring first.
Signals are gathered about the attempt
Each sign-in carries context: the account, the device and whether it is managed, the network and location, the application being reached, and any risk detected about the user or the session.
None of these on its own decides anything. Together they distinguish an ordinary Tuesday from an attempt that deserves interruption.
Policy is evaluated, not merely applied
A policy states the conditions and the required response: permit, require stronger verification, require a compliant device, or block. Because the response varies with circumstance, security can be raised where it matters without making every routine login tedious.
That distinction matters practically. Verification demanded constantly and without reason teaches people to approve prompts reflexively, which is precisely the habit attackers rely on.
Privileged access is granted for a period, not permanently
Administrative rights can be held in a dormant state and activated when needed, with approval and a time limit. The estate then spends most of its life with no standing administrators at all, which substantially reduces what a single compromised account is worth.
Access is reviewed rather than assumed
Periodic reviews ask the people who own a group or application to confirm who still needs it. This is the control auditors increasingly ask to see evidence of, and the one most organizations have never run.
What sits behind which licence
This is the part worth establishing before designing anything, because assuming a capability is included and discovering otherwise mid-project is expensive.
| Capability | Typically requires | Comment |
|---|---|---|
| basic MFA | Included broadly | Enable it everywhere first |
| conditional access | A higher tier | The main reason to upgrade |
| risk based policy | The top identity tier | Detects anomalous sessions |
| privileged access | The top identity tier | Removes standing admin rights |
| access reviews | A higher tier | Often needed for audit |
Where this is right, and where it is not enough
A strong fit
Organizations substantially on Microsoft. The integration with the rest of the tenant is genuine rather than marketed, the licence is frequently already held, and the conditional access model is capable enough to serve as the primary access control for the whole estate.
Consider carefully
Estates spread across Microsoft, Google and many independent applications may be better served by a vendor-neutral identity layer. Entra can federate widely, but an organization whose centre of gravity is not Microsoft should weigh that honestly rather than defaulting to what the subscription includes.
Audit the tenant before buying anything else
Legacy authentication, unprotected administrators and absent conditional access are the three findings that appear in almost every first review, and all three are fixed with what most organizations already own.
Book the tenant reviewGet in touch with Your Company
Questions about this solution? Reach us directly.