When an attacker compromises a Microsoft 365 tenant, they usually do it through identity: a phished user, an over-privileged admin, or a malicious app granted access by a well-meaning employee. Entra ID sits at the centre of all of it.
These 10 Entra ID security best practices are the controls we prioritise in almost every tenant we assess.
What is Microsoft Entra ID?
Microsoft Entra ID is Microsoft's cloud identity and access management service, renamed from Azure Active Directory in 2023. It authenticates users for Microsoft 365, Azure and connected SaaS apps, and enforces access policies through Conditional Access.
10 Entra ID security best practices
1. Enforce MFA everywhere, phishing-resistant for admins
Require MFA for every user. For administrators, use phishing-resistant methods such as passkeys, FIDO2 security keys or Windows Hello for Business, enforced with authentication strengths.
Privileged Identity Management role activation
Illustration in progress
2. Block legacy authentication
Legacy protocols cannot do MFA and are heavily used in password spraying.
Legacy protocols cannot do MFA and are heavily used in password spraying.
3. Minimise Global Administrators
Keep Global Administrators to a small number (Microsoft recommends fewer than five) and use more specific roles, such as Exchange Administrator or User Administrator, for daily tasks.
4. Use Privileged Identity Management (PIM)
PIM (Entra ID P2) makes admin roles eligible rather than permanent. Admins activate a role for a limited time, with approval and justification. This removes standing privilege.
5. Separate admin accounts
Admins should use a dedicated, cloud-only admin account without a mailbox, separate from their daily account, ideally from a secured device.
6. Control user consent to applications
Restrict users from consenting to apps that request high-risk permissions. Enable the admin consent workflow so users can request access and admins review it. Review existing enterprise applications and their permissions.
7. Govern guest access
Limit who can invite guests, require MFA for guests and run access reviews to remove guests who no longer need access.
8. Enable risk-based protection
Entra ID Protection (P2) detects risky sign-ins and compromised credentials. Use risk-based Conditional Access to require MFA or password change when risk is high.
9. Monitor sign-ins and audit logs
Stream sign-in and audit logs to a SIEM such as Microsoft Sentinel. Alert on break-glass account use, new Global Admin assignments, new app credentials and suspicious consent grants.
10. Clean up stale accounts and secure workload identities
Disable inactive users, remove unused app registrations and rotate or replace client secrets with certificates or managed identities.
Quick reference: control, licence and priority
| Control | Licence | Priority |
|---|---|---|
| MFA and Conditional Access | Entra ID P1 | Critical |
| Block legacy auth | Entra ID P1 | Critical |
| Phishing-resistant MFA for admins | P1 | Critical |
| Privileged Identity Management | Entra ID P2 | High |
| Risk-based policies | Entra ID P2 | High |
| Access reviews | Entra ID P2 / Governance | Medium |
| App consent controls | Included | High |
How do you measure Entra ID security?
Use Microsoft Secure Score for identity recommendations, track the number of permanent privileged role assignments, MFA registration coverage, guest accounts not reviewed in 90 days and app registrations with expiring or unused credentials.
How Crozaint approaches identity security
Identity is the first workstream in Crozaint's Microsoft 365 security programme. Our 2–4 week assessment reviews privileged roles, authentication methods, Conditional Access, app consent and guest access, and produces a costed roadmap. In deployment, we harden Entra ID alongside Intune, Defender XDR and Purview.
Clients can then choose Crozaint-managed operations, including 24/7 SOC monitoring, or a full handover to their team. Both are reversible, and you always retain ownership of your tenant and licences.
Common mistakes to avoid
- Admins using their daily account for privileged tasks
- Too many permanent Global Administrators
- Allowing users to consent to any app
- Ignoring guest accounts after projects end
- Not monitoring break-glass account sign-ins
Conclusion
Entra ID is the front door to your organisation. Lock down admins, control app consent, govern guests and watch the logs, and most identity attacks fail.
Want an expert review of your Entra ID tenant? Book a 30-minute discovery call with Crozaint.
