IT

Guides / Microsoft 365

Microsoft Entra ID: the complete guide for starting from zero

Free, P1 and P2 licences, users and dynamic groups, MFA and Conditional Access. What you actually need and what can wait, with concrete examples.

You have heard of Microsoft Entra ID but do not know where to start? This guide explains it plainly, from the ground up. No jargon for its own sake — just clear concepts with practical examples.

The office badge analogy

The best way to understand Microsoft Entra ID is to think of an office badge. Picture your first day in a large building: reception hands you a badge. That badge decides where you can go and where you cannot. It opens your office, the canteen, the meeting room — but it will not let you into the server room or the CEO’s office.

When you leave the company, the badge is deactivated. Immediately.

Microsoft Entra ID works exactly like that: it is the system that issues, manages and revokes your users’ “digital badges” across Microsoft 365. It determines who you are, what you may use, and when your access must be removed.

What is Microsoft Entra ID (formerly Azure AD)?

Microsoft Entra ID — called Azure Active Directory, or Azure AD, until 2023 — is Microsoft’s cloud-based identity and access management service.

In practice: every time a user signs in to Microsoft 365, Teams, SharePoint, Outlook or any other Microsoft app, it is Entra ID that verifies who they are and what they can do. If your company uses Microsoft 365, you are already using Entra ID — whether you know it or not.

The difference from the old on-premises Active Directory — the one installed on a physical server in the building — is that Entra ID is entirely cloud: no server, no hardware maintenance, and reachable from anywhere.

The licences: Free, P1 and P2

Entra ID comes in three tiers. Understanding the difference matters, because several important features need a higher plan.

Entra ID Free

Included at no cost with any Microsoft 365 subscription. It offers basic user and group management, single sign-on for cloud apps, basic MFA through Security Defaults, and synchronisation with on-premises Active Directory via Entra Connect.

Entra ID P1

Included in Microsoft 365 Business Premium, EMS E3 and Microsoft 365 E3. It adds Conditional Access (the single most important security feature), dynamic groups (rule-based automatic membership), Hybrid Entra ID Join for hybrid environments, and Self-Service Password Reset, so users reset their own password without calling the helpdesk.

Entra ID P2

Included in Microsoft 365 E5 and EMS E5. Everything in P1, plus Identity Protection (automatic detection of risky sign-ins), Privileged Identity Management (admin roles activated only when needed rather than standing), Access Reviews (periodic access recertification) and real-time risk-based Conditional Access.

Users, and how to create them

Every person who needs access to company resources needs a user account in Entra ID. You reach Entra ID from the Microsoft 365 Admin Center → Admin Centers → Identity.

There are three ways to create users: manually, one at a time; in bulk by importing a CSV; or automatically, synchronised from your on-premises Active Directory with Entra Connect.

A useful thing to know: the users you see in the Microsoft 365 Admin Center and those in Entra ID are the same users — two interfaces onto the same thing. The Admin Center is simpler for licences and mail; Entra ID is the advanced console for security and identity.

The 30-day recycle bin

When you delete a user they do not vanish straight away: they go into the recycle bin for 30 days. During that window you can restore them completely, with every setting intact. After 30 days the deletion is permanent. If you need to reach a former employee’s mailbox, move inside that window.

Administrative roles

Roles define what an administrator can do. Entra ID has over 60, but in practice you mostly use these:

  • Global Administrator — full access to everything. Maximum caution: ideally no more than two to four people in the whole organisation.
  • User Administrator — creates, edits and deletes users, resets passwords. The typical helpdesk role.
  • Billing Administrator — manages subscriptions and payments.
  • Security Administrator — configures security policies and Conditional Access. Cannot manage ordinary users.
  • Helpdesk Administrator — resets passwords and handles basic tickets. A limited role, safe to give to support staff.
  • Exchange / SharePoint Administrator — manages mail and SharePoint sites respectively.

The golden rule: least privilege. Always assign the smallest role that does the job. If someone only needs to reset passwords, give them Helpdesk Administrator — not Global Administrator.

Groups: security group versus Microsoft 365 group

Groups let you manage access, licences and policies in bulk instead of user by user. There are two main types:

  • Security group — controls access to resources: SharePoint sites, apps, Intune policies, Conditional Access rules. It has no mailbox of its own. This is the type IT uses most.
  • Microsoft 365 group — built for collaboration. Creating one automatically produces a shared mailbox, a SharePoint site, a shared calendar and, if configured, a team in Microsoft Teams. Ideal for project teams.

Static versus dynamic membership

Membership works in one of two ways:

  • Assigned (static) — you add and remove people by hand. Simple, but it needs constant upkeep.
  • Dynamic (needs P1) — you define a rule and the system updates membership by itself. For example: “every user with department = Sales”, or “every device with OS = Windows 11”. When someone changes department they leave the old group and join the new one with no manual step.

Devices: three ways to connect

  • Entra ID Registered (BYOD) — the user’s personal device. It reaches company apps, but the company has minimal control. Right for someone who wants work mail on a personal phone without handing it to IT.
  • Entra ID Joined (cloud-only) — a company device managed entirely by Entra ID and Intune. The user signs in to Windows with their work credentials. No local server. Ideal for a modern, cloud-first organisation.
  • Hybrid Entra ID Joined — joined to both the local AD and Entra ID. For anyone migrating gradually while still running on-premises infrastructure.

Where Microsoft Intune fits: Entra ID manages the user’s identity, Intune manages the device itself — apps, policies, encryption, remote wipe. The two work as a pair.

Enterprise apps and single sign-on

Entra ID is the central authentication hub not only for Microsoft apps but for third-party ones too: Salesforce, Box, Dropbox, Google Workspace, ServiceNow, Zoom and hundreds of others.

With single sign-on the user authenticates once with their Microsoft credentials and needs no separate username and password per app. With automatic provisioning, creating or deleting a user in Entra ID creates or disables the account in the connected app as well. Centralised, and auditable.

Multi-factor authentication

A password on its own is no longer enough. With MFA, even someone who steals the password cannot get in without the second factor. Entra ID supports several methods, from least to most secure:

  • SMS or phone call — a code by text or a call. Convenient, but vulnerable to SIM swapping. Use it only as a fallback.
  • TOTP app (Google or Microsoft Authenticator) — a six-digit code that changes every 30 seconds. Considerably safer than SMS.
  • Microsoft Authenticator push notification — you approve the sign-in with a tap. Simple and secure, and the right default for most users. Entra ID adds number matching to defend against MFA fatigue attacks.
  • Passwordless — no password at all: username plus biometric approval on the phone.
  • Windows Hello for Business — fingerprint or face recognition at the PC. No phone, no password.
  • FIDO2 security key (a YubiKey, for instance) — a physical USB or NFC key. The most secure method there is, and phishing-resistant. Ideal for privileged accounts.
  • Passkeys — where this is going: device biometrics, no password. Already available in Entra ID.

You configure them in Entra ID under Protection → Authentication methods. Each method can be enabled and scoped to specific users or groups.

Conditional Access

Conditional Access is the most powerful security feature in Entra ID. It needs P1 or above. The logic is simple: IF (conditions) → THEN (action).

Practical examples:

  • IF signing in from a country not on the allow list → BLOCK
  • IF the device is not managed by Intune → REQUIRE MFA
  • IF you are a Global Administrator → ALWAYS REQUIRE MFA, everywhere
  • IF reaching SharePoint from an external address → REQUIRE MFA
  • IF in the office on a corporate address → ALLOW without MFA, so people on site are not interrupted

Every policy has three parts: assignments (who and what), conditions (when, where, on which device) and controls (block, allow, require MFA, require a compliant device).

Practical advice: always switch a new policy on in report-only mode first. The logs will show who would have been blocked, without blocking anyone. It saves you from unpleasant surprises.

Authentication strengths: which MFA to require

Authentication strengths let you specify not just “require MFA” but which kind of MFA is acceptable for a given scenario. Reaching the Azure portal might require FIDO2 or Windows Hello only; Teams might accept any form of MFA. Finer-grained control over security.

Risk-based Conditional Access (P2)

With P2, Conditional Access integrates with Identity Protection to react to threats in real time. Entra ID assigns a risk score — low, medium or high — to each sign-in and each user. You can then write policies such as “IF sign-in risk = high → BLOCK” or “IF user risk = medium → REQUIRE password change”. Automatic, with no manual monitoring.

Governance: lifecycle workflows

Lifecycle workflows automate what happens when an employee joins, moves or leaves — removing repetitive manual work from the IT team.

  • Joiner — triggers a set number of days before the start date. Creates the account, assigns licences, adds the department groups, sends a welcome email with temporary credentials, notifies the manager. On day one everything is ready.
  • Mover — triggers when the user’s attributes change. Removes the old access, grants the new. No manual step.
  • Leaver — triggers a set number of days before the contract ends. Disables the account, removes licences and access, notifies the manager, and deletes permanently after the configured period.

Microsoft ships ready-made templates under Entra ID → Identity Governance → Lifecycle Workflows. Use them as they are, or adapt them.

Entitlement management and access packages

Access packages solve the problem of granting several pieces of access one at a time. You build a “package” bundling every resource a role or a project needs.

A concrete example: “Project Alpha access” contains the Teams team, the SharePoint site, the security group for the line-of-business app and a specific licence. You configure who may request it, who approves, and how long it lasts. The user requests it → the manager approves → every piece of access is granted automatically → after three months it expires on its own. All of it auditable.

It is particularly useful for external collaborators: instead of ad-hoc access that nobody can track, you send a link to request the package. Access expires by itself when the project ends.

Where to start: the practical priorities

  1. Turn on MFA for everyone — with Security Defaults, which are free, or better with Conditional Access on P1. It is the single change that most reduces the risk of an account being compromised.
  2. Configure basic Conditional Access — at minimum: require MFA off site, and block sign-ins from countries that have no business reaching you.
  3. Review the roles — who holds Global Administrator? Redistribute on the least-privilege principle.
  4. Organise users into groups — use security groups to assign licences and access in bulk.
  5. Connect the third-party apps — enable SSO for what you already use. Fewer passwords, control in one place.
  6. Automate onboarding and offboarding — if you have P2, set up at least the joiner and leaver workflows.

Microsoft Entra ID can look complicated at first, but once the logic lands — identity, access, conditions — it becomes a genuinely powerful way to protect an organisation without getting in the way of the people doing the work.