0%

Preparing the page

Microsoft Entra ID Security: 10 Best Practices to Protect Your Identities

Secure Microsoft Entra ID (formerly Azure AD) with 10 best practices: phishing-resistant MFA, PIM, least privilege, app consent, guest access and monitoring.

Joseph

Joseph · Cloud Consulting

· 4 min read

Share
Placeholder illustration

When an attacker compromises a Microsoft 365 tenant, they usually do it through identity: a phished user, an over-privileged admin, or a malicious app granted access by a well-meaning employee. Entra ID sits at the centre of all of it.

These 10 Entra ID security best practices are the controls we prioritise in almost every tenant we assess.

What is Microsoft Entra ID?

Microsoft Entra ID is Microsoft's cloud identity and access management service, renamed from Azure Active Directory in 2023. It authenticates users for Microsoft 365, Azure and connected SaaS apps, and enforces access policies through Conditional Access.

10 Entra ID security best practices

1. Enforce MFA everywhere, phishing-resistant for admins

Require MFA for every user. For administrators, use phishing-resistant methods such as passkeys, FIDO2 security keys or Windows Hello for Business, enforced with authentication strengths.

PIM just-in-time activation flow

2. Block legacy authentication

Legacy protocols cannot do MFA and are heavily used in password spraying.

Legacy protocols cannot do MFA and are heavily used in password spraying.

3. Minimise Global Administrators

Keep Global Administrators to a small number (Microsoft recommends fewer than five) and use more specific roles, such as Exchange Administrator or User Administrator, for daily tasks.

4. Use Privileged Identity Management (PIM)

PIM (Entra ID P2) makes admin roles eligible rather than permanent. Admins activate a role for a limited time, with approval and justification. This removes standing privilege.

5. Separate admin accounts

Admins should use a dedicated, cloud-only admin account without a mailbox, separate from their daily account, ideally from a secured device.

Restrict users from consenting to apps that request high-risk permissions. Enable the admin consent workflow so users can request access and admins review it. Review existing enterprise applications and their permissions.

7. Govern guest access

Limit who can invite guests, require MFA for guests and run access reviews to remove guests who no longer need access.

8. Enable risk-based protection

Entra ID Protection (P2) detects risky sign-ins and compromised credentials. Use risk-based Conditional Access to require MFA or password change when risk is high.

9. Monitor sign-ins and audit logs

Stream sign-in and audit logs to a SIEM such as Microsoft Sentinel. Alert on break-glass account use, new Global Admin assignments, new app credentials and suspicious consent grants.

10. Clean up stale accounts and secure workload identities

Disable inactive users, remove unused app registrations and rotate or replace client secrets with certificates or managed identities.

Quick reference: control, licence and priority

ControlLicencePriority
MFA and Conditional AccessEntra ID P1Critical
Block legacy authEntra ID P1Critical
Phishing-resistant MFA for adminsP1Critical
Privileged Identity ManagementEntra ID P2High
Risk-based policiesEntra ID P2High
Access reviewsEntra ID P2 / GovernanceMedium
App consent controlsIncludedHigh

How do you measure Entra ID security?

Use Microsoft Secure Score for identity recommendations, track the number of permanent privileged role assignments, MFA registration coverage, guest accounts not reviewed in 90 days and app registrations with expiring or unused credentials.

How Crozaint approaches identity security

Identity is the first workstream in Crozaint's Microsoft 365 security programme. Our 2–4 week assessment reviews privileged roles, authentication methods, Conditional Access, app consent and guest access, and produces a costed roadmap. In deployment, we harden Entra ID alongside Intune, Defender XDR and Purview.

Clients can then choose Crozaint-managed operations, including 24/7 SOC monitoring, or a full handover to their team. Both are reversible, and you always retain ownership of your tenant and licences.

Common mistakes to avoid

  • Admins using their daily account for privileged tasks
  • Too many permanent Global Administrators
  • Allowing users to consent to any app
  • Ignoring guest accounts after projects end
  • Not monitoring break-glass account sign-ins

Conclusion

Entra ID is the front door to your organisation. Lock down admins, control app consent, govern guests and watch the logs, and most identity attacks fail.

Want an expert review of your Entra ID tenant? Book a 30-minute discovery call with Crozaint.

Frequently Asked Questions

Is Entra ID the same as Azure AD?

Yes. Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023. The service, features and licensing tiers continued under the new name, with Azure AD Premium P1 and P2 becoming Entra ID P1 and P2. Existing configurations were not affected by the rename.

How many Global Administrators should we have?

Microsoft recommends having fewer than five Global Administrators, and at least two for redundancy. Most administrative tasks should use more specific, least-privilege roles. Global Administrator roles should be eligible through PIM rather than permanently assigned wherever possible.

What is Privileged Identity Management?

Privileged Identity Management (PIM) is an Entra ID P2 feature that provides just-in-time privileged access. Admins are made eligible for roles and activate them only when needed, for a limited time, with optional approval, MFA and justification. Every activation is logged for auditing.

What is an OAuth consent phishing attack?

In a consent phishing attack, a user is tricked into granting a malicious application permissions to their Microsoft 365 data, such as reading mail. The app then accesses data without needing the password. Restricting user consent and reviewing app permissions reduces this risk.

What is phishing-resistant MFA?

Phishing-resistant MFA uses methods that cannot be intercepted or replayed by a fake login page, such as FIDO2 security keys, passkeys, Windows Hello for Business and certificate-based authentication. They are strongly recommended for administrators and high-risk users.

Joseph

Written by

Joseph

Cloud Consulting · 15 articles

Joseph has spent fifteen years at the operating end of infrastructure — from data-centre and network operations to multi-cloud consulting across AWS, Azure and GCP. He turns unreadable cloud bills into decisions teams can act on, and he knows the automation underneath them — Terraform, Ansible, Kubernetes — well enough to make the savings stick.

Nidhish JoyReviewed for technical accuracy by Nidhish Joy, Co-founder & CEO.

After the reading

Reading About Digital Workplace & Security Is the Easy Part.Doing It in Your Estate Is Ours.

Thirty minutes with the people who wrote this. We look at your setup, say what we would fix first and leave you with a plan, whether or not you go further with us.

  • A look at your estate, not a demo
  • What we would fix first, and why
  • A plan you keep, whether or not you hire us
Joseph

Talk to Joseph

Wrote this article · Cloud Consulting

Thirty minutes on your estate. Joseph looks at what you have and tells you what we would do first.

Book 30 Minutes

No deck, no pitch, no commitment.