Microsoft Entra ID: What Growing Businesses Need to Know
Most businesses running Microsoft 365 Business Premium already have Microsoft Entra ID P1 included in their subscription. The majority have never done anything with it beyond the default settings. That gap is exactly where most credential-based attacks get in.
Microsoft Entra ID is the cloud identity and access management platform behind every Microsoft 365 sign-in. Microsoft renamed it from Azure Active Directory in July 2023. The name changed. The technology did not. More than 1.2 billion sign-ins per day run through it.
What Is Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity platform. It controls who can sign into your Microsoft 365 apps, Azure services, and any other applications you connect to it. Think of it as the authentication layer for your entire cloud environment.
When an employee opens Outlook, Teams, or SharePoint, Entra ID is the service verifying their identity and deciding what they can access. When someone leaves your company and you disable their account, Entra ID is what cuts off their access across every connected application.
If your IT team or managed IT provider refers to Azure Active Directory or Azure AD, that is the same product under an older name. Microsoft completed the rebrand in 2023 to reflect the platform's expansion into a broader identity and security product family. Nothing about your existing configuration changed.
What Comes with Your Microsoft 365 Plan
Not every Microsoft 365 subscription includes the same level of Entra ID. Here is how the tiers break down.
Microsoft 365 Business Basic and Business Standard include Entra ID Free. This covers basic user and group management, single sign-on to Microsoft 365 apps, and MFA through Security Defaults (which Microsoft enables on all new tenants by default). There is no Conditional Access.
Microsoft 365 Business Premium includes Entra ID P1. At $26.40 per user per month, Business Premium bundles in Entra ID P1 alongside Microsoft Intune for device management and Microsoft Defender for Business. Entra ID P1 adds Conditional Access, which is the policy engine that controls when and how users authenticate. This is where the meaningful security configuration lives.
Microsoft 365 E3 also includes Entra ID P1. E3 is the enterprise-tier equivalent of Business Premium for larger organizations.
Microsoft 365 E5 includes Entra ID P2, which adds risk-based Conditional Access, Identity Protection, and Privileged Identity Management on top of what P1 provides.
For a 40-to-150-person business, Business Premium is typically the practical baseline. If your business is on Business Basic or Standard to save on licensing, you are working with Entra ID Free only. That means no Conditional Access.
Security Defaults vs. Conditional Access
This is the gap that most businesses do not realize they have.
Security Defaults is the baseline setting Microsoft turns on for every new Microsoft 365 tenant. It requires MFA for all users and blocks legacy authentication protocols like IMAP, POP3, and basic SMTP. For a business that stood up Microsoft 365 and has not revisited its identity settings since, Security Defaults provides a floor.
The problem is it does not scale. The moment your business has a service account that cannot use MFA, an executive who travels internationally and gets blocked, a third-party app that connects to your Microsoft 365 tenant, or a contractor who needs temporary access, Security Defaults starts to break things. The most common response is to disable it and move on. What should replace it never gets configured.
Conditional Access is what replaces it. It is a policy engine where your IT team defines the rules: which users need MFA, what devices are allowed to connect, which locations are trusted, what happens when a sign-in looks suspicious. Instead of a blanket rule for everyone, you get policies that match how your business actually operates.
CISA, Microsoft, and the FBI identified identity-layer attacks as the dominant breach vector in 2024 and into 2025. Most of those attacks do not break MFA. They find the gaps in how MFA is configured. Businesses that experienced MFA bypass attacks in 2026 were not victims of clever hacking. They had policies that left doors open.
The Configuration Gaps That Show Up in Every Audit
Security teams that audit Microsoft 365 tenants see the same issues repeatedly.
Legacy authentication still enabled. IMAP, POP3, and basic SMTP are old protocols that do not support modern authentication. They are specifically targeted by attackers because they route around MFA. A single Conditional Access policy that blocks legacy authentication for all users eliminates one of the most widely exploited MFA bypass methods. This is often the single highest-value change a business can make.
Service accounts with no restrictions. Shared mailboxes, integration accounts, and automation service accounts typically get excluded from MFA policies to avoid disrupting workflows. Without a Conditional Access policy restricting those accounts to trusted IP addresses or named locations, they are effectively unprotected.
Security Defaults disabled, Conditional Access never built. This is the most common scenario. Security Defaults got turned off during an implementation or migration. Nobody built the Conditional Access policies that were supposed to replace them. The tenant has weaker identity controls now than it did before.
No break-glass account. Conditional Access requires at least one Global Administrator account excluded from all policies for emergency access. Configuring break-glass accounts is not optional. A misconfigured policy can lock every admin out of the Microsoft 365 tenant simultaneously. Without a properly stored break-glass account, recovery can take days.
Entra ID P1 includes the tools to address all of these gaps. Most businesses with Business Premium are sitting on the capability. The issue is that proper configuration requires deliberate architecture work that the initial Microsoft 365 setup rarely includes.
Why This Matters as Your Business Grows
A 10-person business that stood up Microsoft 365 three years ago and left the default settings in place has a different risk profile than a 75-person firm with a dozen SaaS integrations, a mix of full-time employees and contractors, and remote workers across multiple states.
Growing businesses add users, connect new tools, onboard contractors, and move to new platforms faster than anyone revisits identity security settings. Each addition creates a potential gap. Conditional Access is the mechanism that lets your IT team enforce consistent policies across all of it without blocking legitimate work.
Proper Entra ID configuration also gives your managed IT provider a single place to audit access, review sign-in logs, and respond when something looks wrong. Sign-in logs in a well-configured Entra ID environment are actually useful for investigation. Sign-in logs in a tenant running Security Defaults with gaps tell you very little.
The configuration that worked fine at 15 people looks different at 75. What is appropriate at 75 looks different at 200. Entra ID P1 scales with that. Security Defaults does not.
Frequently Asked Questions
Is Microsoft Entra ID the same as Azure Active Directory?
Yes. Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID in July 2023. The underlying service, APIs, and licensing stayed the same. If your IT team refers to Azure AD, they are talking about the same product.
Does every Microsoft 365 plan include Microsoft Entra ID?
Every Microsoft 365 plan includes Entra ID Free, which covers basic sign-in and single sign-on. Entra ID P1, which includes Conditional Access, is included with Business Premium and Microsoft 365 E3 and above. Entra ID P2, which adds risk-based controls and Identity Protection, comes with Microsoft 365 E5.
What is the difference between Security Defaults and Conditional Access in Entra ID?
Security Defaults is a single set of baseline rules Microsoft turns on by default: MFA for all users, no legacy authentication. Conditional Access is a policy engine where you build rules based on your specific needs, including device compliance, user location, application sensitivity, and sign-in risk level. Security Defaults is a starting point. Conditional Access is where most businesses that have been on Microsoft 365 for more than a year should be.
What does an Entra ID audit cover?
An Entra ID audit reviews your current Conditional Access policies, whether legacy authentication is blocked, how admin accounts are protected, whether break-glass accounts are properly configured, how service accounts are restricted, and whether sign-in risk signals are in use. It typically produces a prioritized list of what needs to change.
Do I need an IT provider to set up Conditional Access?
Technically no. Conditional Access is accessible to any Global Administrator in the Microsoft Entra admin center. In practice, the rollout sequence matters. A misconfigured policy can lock your team out of Microsoft 365. Most businesses configure Conditional Access with an IT provider who knows how to stage policies in report-only mode first, set up break-glass accounts before any enforcement, and verify each policy does what it is supposed to before turning it on.
Wondering if your Microsoft 365 setup is actually protecting your business? A quick Entra ID review can show you what is configured, what is missing, and what to fix first. Let us take a look.