IT professional reviewing Microsoft Entra ID identity management dashboard in Manchester office

Azure AD and Entra ID for SMEs: A Practical Guide

Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023. If that sentence already has you reaching for a search engine, you are not alone – and it matters more than you might think for your Manchester business.

Whether you call it Azure AD or Entra ID, the underlying technology controls who can access your systems, from which devices, and under what conditions. For small and medium-sized businesses across Sale, Altrincham, and Greater Manchester, getting this right is the difference between a secure, well-managed workforce and an IT estate that is one stolen password away from a serious breach.

What Is Microsoft Entra ID?

Microsoft Entra ID (formerly Azure Active Directory, or Azure AD) is Microsoft’s cloud-based identity and access management platform. It acts as the central directory for your organisation: a single system that knows who your users are, what they are permitted to access, and how they must prove their identity before being granted entry.

If your business uses Microsoft 365, you already have Entra ID. It is the identity layer sitting beneath your email accounts, SharePoint, Teams, and every other Microsoft service your team uses day to day. The question is not whether you have it – it is whether you are using it properly.

The Azure AD to Entra ID Rebrand: What Changed?

In August 2023, Microsoft renamed Azure Active Directory to Microsoft Entra ID as part of a broader consolidation of its identity and network security products. The core functionality remains the same; the naming structure and product family have been unified under the Entra brand.

For Manchester SMEs already familiar with Azure AD, the practical impact is minimal. Existing configurations and licences carry forward automatically. What has shifted more significantly is Microsoft’s direction: identity, governance, and access are being built into a coherent security platform, with Entra ID at its centre.

Why Identity Management Matters for Manchester SMEs

The majority of cyber incidents begin with compromised credentials. A phishing email leads to a stolen password, and suddenly an attacker has the same level of access as a legitimate employee. Without proper identity controls in place, there is little to stop them moving through your systems unchallenged.

Microsoft Entra ID addresses this by inserting an intelligent checkpoint between your users and your systems. Before access is granted, Entra ID evaluates:

  • Is this the correct user?
  • Are they signing in from a known, approved device?
  • Is the location consistent with their normal behaviour?
  • Do they need to prove their identity with a second factor?

For Sale and Manchester businesses managing distributed or hybrid teams, this kind of visibility and control is what modern cyber security looks like in practice for a Microsoft 365 environment.

Key Features Worth Understanding

Single Sign-On (SSO)

Entra ID enables single sign-on across every connected application in your estate. Rather than maintaining separate credentials for each tool, users authenticate once and gain seamless access to everything they are authorised to use – from Microsoft 365 to third-party platforms like Salesforce, DocuSign, or your line-of-business software.

SSO reduces password fatigue, cuts helpdesk tickets for locked accounts, and makes offboarding straightforward: disable one account in one place and access is revoked everywhere simultaneously.

Multi-Factor Authentication (MFA)

Entra ID makes organisation-wide MFA enforcement simple. When a user signs in, they must confirm their identity using a second method – the Microsoft Authenticator app, an SMS code, or a FIDO2 hardware key. According to Microsoft, MFA blocks more than 99% of account compromise attacks.

For Manchester businesses worried about phishing and credential theft, enabling MFA across all users is the single highest-impact security control available. It costs nothing extra on most Microsoft 365 plans and can be deployed with the right IT support in a matter of hours.

Conditional Access

Conditional access policies let you define the exact circumstances under which access is granted. You might require MFA for all remote sign-ins, block authentication from high-risk countries, or restrict sensitive applications to managed corporate devices only.

A Manchester professional services firm, for example, might allow full access from managed devices on the office network, demand MFA for remote connections, and block sign-ins from countries where they have no business presence. All of this is managed centrally from the Entra ID admin centre.

Device Management and Compliance

Entra ID integrates with Microsoft Intune for mobile device and endpoint management. Devices can be Entra-joined or registered, giving your IT team full visibility into the compliance state of every endpoint touching your systems.

For Sale-based businesses with field staff or hybrid workers on personal devices, this provides a way to apply baseline security requirements – encrypted storage, up-to-date operating systems, approved apps – without taking full ownership of someone’s personal machine. This is a critical component of any sound BYOD policy and helps with business IT support planning for distributed teams.

Privileged Identity Management

For businesses with administrator accounts or access to sensitive data, Privileged Identity Management (PIM) in Entra ID provides just-in-time privileged access. Rather than staff holding permanent admin rights, they request elevated access when needed, it is approved for a defined period, and the rights expire automatically. This limits the damage if an admin account is ever compromised.

Common Mistakes Manchester Businesses Make with Entra ID

Leaving Default Settings in Place

A Microsoft 365 tenancy with default settings has no conditional access policies, no enforced MFA, and no restrictions on which devices can connect to your data. Many Sale and Manchester businesses have operated this way since migrating to Microsoft 365, unaware of the exposure they carry.

Using Shared Admin Accounts

Shared global administrator credentials are an audit and security problem. Entra ID makes it easy to assign granular, role-specific admin permissions to named individuals with full sign-in logging. There is no justification for sharing admin accounts in a properly configured Entra ID tenancy.

Allowing Guest Access to Accumulate

Entra ID allows external users to be added as guests for collaboration. Without a regular review cycle, former contractors, clients, and suppliers can retain access long after the relationship has ended. A quarterly access review closes this gap in under an hour.

Ignoring Sign-In Logs

Entra ID logs every sign-in attempt, including failed logins, unusual locations, and risk events flagged by Microsoft’s threat intelligence. Most SMEs never look at them. These logs are your earliest warning system, and they are already there, waiting to be used.

A Practical Starting Point for Sale and Manchester SMEs

You do not need to implement every feature at once. For most businesses, the priority order is:

  1. Enable MFA for all users – start with the Microsoft Authenticator app
  2. Audit existing accounts – remove former staff, review guest access, identify shared admin credentials
  3. Block legacy authentication protocols – older protocols bypass modern MFA entirely and are a known attack vector
  4. Deploy baseline conditional access policies – require compliant devices, enforce MFA for remote access
  5. Enable sign-in risk policies – automatic responses to high-risk sign-in events via Entra ID Protection

An experienced IT support partner can work through the first three steps with a 20-person Manchester business in a single working day. Steps four and five require slightly more planning but are achievable within a week for most organisations.

Licensing: What Does Your Business Need?

Basic Entra ID features – including MFA and standard conditional access – are included in Microsoft 365 Business Premium. Advanced capabilities such as Entra ID Protection, Privileged Identity Management, and identity governance require Microsoft Entra ID P2, available as an add-on or included in Microsoft 365 E5.

For most Sale and Manchester SMEs, Microsoft 365 Business Premium strikes the right balance of capability and cost. Our cloud services team can assess your current licensing and identify any gaps.

Need Expert Help With Microsoft Entra ID?

PC Express IT works with businesses across Sale, Manchester, Altrincham, and Trafford to configure and manage Microsoft Entra ID properly. If you are unsure what your current identity setup looks like, or whether your access controls are fit for purpose, get in touch for a straightforward conversation with no obligation.

Our managed IT support service covers everything from initial Entra ID audits to ongoing identity management. For businesses that need a broader view of their security posture, our dedicated cyber security team can help build the complete picture.

Frequently Asked Questions

Is Microsoft Entra ID the same as Azure Active Directory?

Yes. Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID in August 2023. The functionality is the same; only the name and product family structure changed. Existing Azure AD configurations, licences, and integrations carry forward automatically with no action required from businesses.

Do I already have Microsoft Entra ID if I use Microsoft 365?

Yes. Every Microsoft 365 subscription includes Microsoft Entra ID as its underlying identity service. It powers your user accounts, email access, Teams authentication, and SharePoint permissions. The question is not whether you have it but whether you have configured it securely – with MFA, conditional access, and proper account governance in place.

How much does Microsoft Entra ID cost for a small business?

Basic Entra ID features including MFA and standard conditional access policies are included in Microsoft 365 Business Premium at around £19.70 per user per month. Advanced features such as Entra ID Protection and Privileged Identity Management require Entra ID P2, available as an add-on or in Microsoft 365 E5. For most Manchester SMEs, Business Premium provides everything needed to implement strong identity security.

What is conditional access in Microsoft Entra ID?

Conditional access is a policy engine within Entra ID that evaluates each sign-in request and decides whether to grant access, require MFA, or block the attempt based on conditions you configure. Conditions can include the user’s location, device compliance status, the application being accessed, and the risk level Microsoft’s threat intelligence assigns to the sign-in. This lets you apply different rules for office versus remote access automatically.

How does Microsoft Entra ID help when a staff member leaves?

Entra ID centralises all identity management, so disabling an account when someone leaves immediately revokes access across all connected applications – Microsoft 365, Teams, SharePoint, and integrated third-party tools. Without this centralisation, IT teams often miss access revocation in some systems during offboarding, creating a security gap that can persist for months after someone has left the business.

Can Microsoft Entra ID protect against phishing attacks?

Entra ID significantly reduces the impact of successful phishing attacks. Even if a user’s password is stolen, MFA means an attacker cannot use it without also compromising the second factor. Conditional access adds further protection by blocking sign-ins from unusual locations or non-compliant devices even when valid credentials are presented. Entra ID Protection can also automatically detect and respond to compromised accounts in real time using Microsoft’s global threat intelligence.

How long does it take to set up Microsoft Entra ID properly?

For a Manchester SME of 10 to 30 users, enabling MFA and deploying baseline conditional access policies typically takes one working day with an experienced IT support partner. A full Entra ID configuration including device compliance, Privileged Identity Management, guest access review, and sign-in risk policies is usually achievable within a week. The most important step is simply to start: MFA alone eliminates the majority of credential-based attack risk.