In this blog post Microsoft Entra ID Security Settings Every Business Should Review we will explain which identity controls deserve attention, why they matter and how they reduce security risk without making work unnecessarily difficult.
If staff can access Microsoft 365, business applications and company data with a weak or poorly managed identity, your other security investments can be bypassed. One stolen account may be enough to read emails, download files, impersonate an executive or approve a fraudulent payment.
What Microsoft Entra ID does in plain English
Microsoft Entra ID, formerly called Azure Active Directory, is the identity and access system behind Microsoft 365, Azure and thousands of connected business applications. It checks who is signing in and helps decide what they should be allowed to access.
Think of it as the security desk at the entrance to your business. It verifies each person, checks whether they have permission to enter and can apply extra conditions when something does not look right.
The challenge is that Entra ID is not automatically tailored to your organisation. Its effectiveness depends on your licences, configuration, user lifecycle processes and whether anyone regularly reviews the settings.
We have already covered broader checks in our Microsoft 365 tenant security checklist. Here, we are focusing specifically on the identity controls that protect your users, administrators, guests and connected applications.
1. Confirm your baseline sign-in protection
The first question is simple: does every user have effective multi-factor authentication?
Multi-factor authentication, usually shortened to MFA, requires another proof of identity in addition to a password. This may be a prompt in Microsoft Authenticator, a passkey, Windows Hello facial recognition or a physical security key.
Smaller businesses may use Microsoft Security Defaults, which provides a standard set of protections. Organisations with more complex requirements generally use Conditional Access, which creates rules based on the user, application, device, location and level of risk.
A Conditional Access rule might say that finance staff can only access payment systems after completing MFA and only from a company-managed device. Microsoft Intune, which manages and secures company laptops and mobile devices, can confirm whether that device meets the required standard.
What to review
- Security Defaults are enabled, or a complete set of Conditional Access policies has replaced them.
- MFA applies to employees, contractors, guests and administrators.
- Older sign-in methods that cannot enforce modern security checks are blocked.
- New policies are tested in report-only mode before enforcement to avoid locking out staff.
- Emergency access accounts are excluded from policies that could accidentally block every administrator.
For Australian organisations, this review also supports the Essential 8, the Australian Government’s cybersecurity framework that many businesses are required or expected to follow. MFA is one of its eight core security measures.
2. Review which authentication methods are allowed
Having MFA enabled does not automatically mean every sign-in method is equally secure. Text messages and voice calls are better than relying on a password alone, but they can still be targeted through social engineering, mobile number theft and convincing fake login pages.
Passkeys and FIDO2 security keys provide stronger protection because they are designed to work only with the genuine service. In practical terms, they make it much harder for an employee to accidentally hand their login to a fake Microsoft website.
Businesses do not need to move every employee to the strongest method overnight. Start with administrators, executives, finance teams, payroll staff and anyone with access to sensitive customer information.
What to review
- The central Authentication Methods policy controls which methods staff can register.
- SMS and voice authentication are limited where stronger options are practical.
- Passkeys, Windows Hello for Business or security keys are available to high-risk users.
- Temporary Access Pass is controlled and time-limited when used for onboarding or account recovery.
- Self-service password reset is enabled with suitable verification requirements.
Self-service password reset allows staff to regain access without waiting for the help desk. Properly configured, it reduces support costs and lost working time while keeping the recovery process controlled.
3. Reduce permanent administrator access
Administrator accounts can change security policies, create users, access sensitive systems and grant permissions. Yet we still find businesses where everyday user accounts have powerful administrator rights that were assigned years ago and never removed.
Entra roles should follow the principle of least privilege. This means giving people only the access needed for their job, rather than making everyone a Global Administrator because it is convenient.
Microsoft Entra Privileged Identity Management, often called PIM, can provide administrator access only when it is needed. A person activates the role for a limited period, completes MFA and may need to provide a reason or obtain approval.
What to review
- Every Global Administrator assignment has a current business reason.
- Administrators use separate accounts for privileged work and normal email.
- Permanent access is replaced with time-limited access where licensing allows.
- Departed employees and previous IT providers no longer hold roles.
- At least two monitored emergency access accounts are available if normal sign-in systems fail.
This directly supports the Essential 8 requirement to restrict administrative privileges. It also limits how much damage can occur if one employee account is compromised.
4. Control guests and connected applications
External collaboration often grows quietly. A project manager invites a supplier into Teams, a department connects a new cloud application, and an executive approves access for a reporting tool. Each decision may be reasonable, but access can remain long after the original need disappears.
Review who can invite guests and what those guests can see. Recurring access reviews can ask the relevant manager or data owner to confirm whether a contractor, partner or supplier still requires access.
Application consent deserves the same attention. Consent is the permission given to an application to access information such as a user’s profile, email, calendar or files. Staff should not be able to grant broad access to unverified applications without review.
What to review
- Only authorised people can invite external guests.
- Inactive guest accounts are identified and removed.
- Access reviews run regularly for sensitive groups and applications.
- User consent is limited to low-risk, verified applications.
- An administrator approval process exists for applications requesting broader access.
- Unused enterprise applications and old integrations are removed.
The same discipline now needs to cover non-human identities, including automated services and AI tools. Our article on securing AI agent identities with Entra ID explains how to assign ownership, limited access and an audit trail to AI agents.
5. Monitor identity risk and account lifecycle events
Good policies prevent many problems, but someone must still watch for unusual activity. Entra sign-in logs show who accessed your systems, which application they used, where the request came from and whether security controls were applied.
Depending on your licensing, Entra ID Protection can identify risky users and suspicious sign-ins. Conditional Access can then require stronger verification, force secure remediation or block the attempt.
Monitoring should also cover normal business changes. Promotions, department transfers, extended leave and employee departures can all create inappropriate access if identity processes are not connected to HR.
What to review
- Risky users and risky sign-ins are reviewed promptly.
- Alerts exist for emergency account use and major administrator changes.
- Sign-in and audit logs are retained for an appropriate period.
- Departing employees are disabled quickly and their active sessions are ended.
- Access is reviewed when employees change roles rather than simply adding new permissions.
What these gaps look like in a real business
Consider a 200-person professional services firm with MFA enabled. On the surface, the environment appears secure.
A focused identity review might still find several permanent Global Administrators, hundreds of old guest accounts, widespread use of weaker authentication methods and a third-party application that can access company data even though the original project ended two years ago.
Fixing those issues does not require replacing Microsoft 365. It requires using the controls already available, removing unnecessary access and creating a repeatable review process.
The business outcomes are practical: fewer opportunities for account takeover, clearer Essential 8 evidence, lower support effort and less chance that an old user or application becomes the starting point for a serious incident.
A sensible review order
- Confirm MFA coverage and your Security Defaults or Conditional Access baseline.
- Review authentication methods and move high-risk users toward phishing-resistant options.
- Remove unnecessary administrator roles and secure emergency access.
- Clean up guest users, application consent and unused integrations.
- Enable risk monitoring and formalise the joiner, mover and leaver process.
As a Melbourne-based Microsoft Partner and Wiz Security Integrator, CloudProInc takes a practical approach to identity reviews. Our team draws on more than 20 years of enterprise IT experience across Entra ID, Microsoft 365, Azure, Intune, Defender, Wiz and AI platforms.
If you are not sure whether your Entra ID settings reflect how your business operates today, we are happy to take a look. A focused review can show what is working, what needs attention and which changes will reduce the most risk without creating unnecessary disruption.
Discover more from CPI Consulting
Subscribe to get the latest posts sent to your email.