If your business uses Microsoft 365, you are already using Microsoft Entra ID — even if you have never opened it. It is the identity service that decides who can sign in and what they are allowed to reach. Getting it configured well is one of the highest-impact things you can do for both security and day-to-day productivity. This guide explains what Entra ID is, its key features, and how the licensing tiers differ.
Microsoft Entra ID (formerly Azure AD) is Microsoft's cloud identity and access management service. It manages user accounts and controls sign-in to Microsoft 365, Azure and thousands of connected apps, providing single sign-on, multi-factor authentication and Conditional Access from one central place.
What is Microsoft Entra ID?
Microsoft Entra ID is the directory and identity platform behind Microsoft 365 and Azure. It holds your organisation's user accounts, groups and devices, and it enforces the rules that govern access to applications. Whenever a staff member signs in to Outlook, Teams or SharePoint, Entra ID is what authenticates them.
Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID in 2023. The capabilities are the same — only the name changed — so the two terms refer to the same product. You can read the official overview on Microsoft Learn.
Key features
Single sign-on (SSO)
Single sign-on lets staff authenticate once and then reach many applications without signing in again. Beyond convenience, SSO improves security: fewer separate passwords means fewer weak or reused credentials, and access can be granted or revoked centrally the moment someone joins or leaves.
Multi-factor authentication
Entra ID provides built-in multi-factor authentication, which you can turn on for everyone through security defaults or apply selectively through Conditional Access. This is one of the most effective ways to stop account takeovers.
Conditional Access
Conditional Access is a policy engine that evaluates each sign-in and decides whether to allow it, block it or require an extra check. Policies can consider the user, their location, whether their device is managed and compliant, and how risky the sign-in looks. Typical rules include requiring MFA from unmanaged devices, or blocking sign-ins from outside Australia. Conditional Access is the backbone of a zero trust approach.
Identity governance
Entra ID also handles the housekeeping of identity — group-based access, self-service password reset, and, at higher tiers, just-in-time privileged access and automated access reviews.
Entra ID licensing tiers at a glance
Entra ID comes in a free tier plus two paid tiers, P1 and P2. Higher tiers are also bundled into certain Microsoft 365 plans. Here is a high-level comparison — always confirm current inclusions on Microsoft Learn, as Microsoft updates plans over time.
| Capability | Free | P1 | P2 |
|---|---|---|---|
| User & group management, SSO | Yes | Yes | Yes |
| MFA via security defaults | Yes | Yes | Yes |
| Conditional Access | No | Yes | Yes |
| Self-service password reset | Limited | Yes | Yes |
| Risk-based Identity Protection | No | No | Yes |
| Privileged Identity Management | No | No | Yes |
P1 is the practical choice for most small and medium businesses that want Conditional Access and self-service password reset; it is included in Microsoft 365 Business Premium and E3. P2 adds risk-based Identity Protection and Privileged Identity Management for just-in-time admin access, and suits organisations with stricter governance needs. Microsoft publishes the current feature matrix on Microsoft Learn.
Common use cases
- Securing Microsoft 365. Enforce MFA, block risky sign-ins, and require managed devices for access to sensitive data.
- Onboarding and offboarding. Grant or revoke access to every connected app from one place when staff join or leave — critical for security and compliance.
- Remote and hybrid work. Give staff secure single sign-on to cloud apps from any location, with policy-based controls.
- Third-party app access. Connect line-of-business and SaaS applications for centralised, auditable sign-in.
The honest takeaway
Entra ID is powerful, but its value comes from thoughtful configuration — the right Conditional Access policies, sensible admin roles, and a clean joiner-mover-leaver process. Misconfigured, it can either block legitimate work or leave gaps open. That is where a managed Microsoft 365 partner earns its keep: designing the policies, choosing the right licence tier, and keeping identity secure as your business changes.
Related services
Explore our Microsoft 365 management and cyber security services, or book a free IT assessment to review your identity setup. Need help now? Contact our Sydney team.
Frequently asked questions
Microsoft Entra ID, formerly known as Azure Active Directory (Azure AD), is Microsoft's cloud identity and access management service. It stores user accounts and groups and controls who can sign in to Microsoft 365, Azure and thousands of connected applications, providing single sign-on, MFA and Conditional Access.
Yes. Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023. The service and its capabilities are the same; only the name changed. You may still see the old Azure AD name in older documentation and some tools.
Entra ID P1 adds Conditional Access, self-service password reset and group-based licensing on top of the free tier. P2 includes everything in P1 plus identity protection with risk-based policies and Privileged Identity Management for just-in-time admin access. Choose P1 for strong baseline controls and P2 where you need risk-based and privileged-access governance.
Every Microsoft 365 subscription includes the free tier of Microsoft Entra ID, which covers core sign-in, user management and basic MFA via security defaults. Advanced features such as Conditional Access require an Entra ID P1 or P2 licence, which is bundled into some Microsoft 365 plans such as Business Premium and E3.
Conditional Access is a policy engine in Entra ID that decides whether to allow, block or challenge a sign-in based on signals such as user, location, device compliance and risk. For example, you can require MFA from unmanaged devices or block sign-ins from outside Australia.