If you have logged into anything Microsoft in the last decade, you have used Azure Active Directory. It is the part of Microsoft 365 that knows who your staff are, what they can access, and whether they are who they say they are. Without it, nothing else works.
In July 2023, Microsoft renamed it to Microsoft Entra ID. The same product, mostly the same admin portal, a different name. Most UK SMBs we work with still call it Azure AD because the rebrand never made it into day-to-day conversation. That is fine until a cyber insurance renewal form, a compliance auditor or a software vendor asks specifically about “Entra ID configuration” and nobody knows what they mean.
Here is the honest explanation of what changed, what is the same, and what your business actually needs to do about it.
In short: Entra ID is simply the new name for Azure AD, Microsoft’s identity and access service, so for most SMEs the real change is the name plus some licensing and feature tidy-ups. Here is what actually changed and what to do about it.
Key takeaways
- Entra ID is the new name for Azure AD. Same product, same data, same passwords. You did not need to migrate anything in 2023.
- The wider family includes Entra ID (identity), Entra Permissions Management (cloud entitlements), Entra Verified ID (digital credentials) and Entra Internet Access / Private Access (network security). Most UK SMBs only need Entra ID.
- The features that matter most for a UK SMB – MFA, Conditional Access, Self-Service Password Reset, External Identities – have not changed names or behaviour.
- Your cyber insurance renewal will ask about it. Almost every UK insurer in 2026 requires MFA on all admin accounts via Entra (or equivalent) before renewing a policy.
- If you are on Microsoft 365 Business Premium, you already have Entra ID P1 included – you just need someone to switch it on properly.

What did Microsoft actually rename?
The headline change in July 2023 was that Azure Active Directory became Microsoft Entra ID. Everything else underneath stayed the same:
- Your tenant ID is the same.
- Your users, groups, applications and policies are the same.
- Your licences are the same (the names changed but the products did not).
- The admin portal moved from aad.portal.azure.com to entra.microsoft.com, but the old URL still works and redirects.
The reason for the rebrand was Microsoft consolidating its identity and security products under one name. “Azure Active Directory” was confusing because it had nothing to do with on-premise Active Directory (despite the name), and Microsoft wanted a brand that covered identity, access management and network security in one umbrella.
The new Entra family in plain English
When someone says “Entra” today, they could mean any of these:
- Entra ID – what used to be Azure AD. Your user directory, sign-ins, MFA, Conditional Access, Self-Service Password Reset. Almost every SMB uses this.
- Entra ID Governance – access reviews, entitlement management, lifecycle workflows. Larger orgs only.
- Entra Permissions Management – sees who has access to what across AWS, Azure and Google Cloud. Multi-cloud orgs only.
- Entra Verified ID – digital credentials (think verifiable employment records). Emerging tech, niche use.
- Entra Internet Access and Entra Private Access – Microsoft’s answer to Zscaler/ZTNA. Enterprise networks only.
For 90% of UK SMBs we work with, Entra ID is the only one that matters. The rest are either enterprise-scale, multi-cloud-scale, or genuinely new products that have nothing to do with the rebrand.
What Entra ID actually does for your business
Strip away the marketing and Entra ID does five things that genuinely matter for a UK SMB:
1. It stores your staff identities
Every user in your Microsoft 365 tenant exists in Entra ID. That is what lets them log into email, Teams, SharePoint, and (with Entra ID configured properly) every other line-of-business app you have.
2. It enforces multi-factor authentication
This is the single most important security control your business has. MFA, configured via Entra ID, prevents 99.9% of account compromise attacks. If you are not enforcing it on every user (not just admins), you are leaving the front door open. We have a separate article on MFA vs Conditional Access for the longer version.
3. It applies Conditional Access policies
Conditional Access is the rule engine that says things like: “Only allow sign-in from the UK”, “Block sign-ins from devices that are not company-managed”, “Require MFA when accessing email from outside the office”. This is where Entra ID earns its keep. Cyber Essentials assessors expect to see these policies. Insurers expect to see them. Auditors expect to see them.
4. It manages Single Sign-On (SSO) to your other apps
Anything that supports SAML or OIDC SSO (most modern SaaS does) can be connected to Entra ID. The win is huge: one set of credentials, one MFA prompt, and when a user leaves, you disable them once in Entra and lose access to every connected app instantly.
5. It handles guest access (External Identities)
When a client, supplier or contractor needs to access a SharePoint site or a Teams channel, Entra ID can invite them as a guest. They sign in with their own Microsoft account or email-and-code; your security policies still apply to what they see and do.
What licence do you need?
This is where it gets fiddly, because Microsoft licenses Entra ID separately from M365 in some plans and bundled in others. The plain-English summary for 2026:
- Microsoft 365 Business Basic / Standard – you get Entra ID Free. MFA via “security defaults” only, no Conditional Access.
- Microsoft 365 Business Premium – you get Entra ID P1. Full Conditional Access, Self-Service Password Reset, dynamic groups, Hybrid Identity. This is what every UK SMB we work with should be on.
- Microsoft 365 E3 – same as Business Premium for identity purposes (Entra ID P1).
- Microsoft 365 E5 – you get Entra ID P2. Adds Identity Protection (risk-based sign-in), Privileged Identity Management. Worth it if you have admin accounts that need just-in-time access.
If you are paying for Business Basic but you genuinely need Conditional Access (and at this point, most UK businesses do), the £5 a user a month upgrade to Business Premium is the cheapest cyber insurance you will ever buy.
Why cyber insurance renewals are asking about Entra
Every UK cyber insurance renewal questionnaire we have seen in the last 18 months asks specifically about:
- MFA enforcement on all user accounts (not just admins)
- Conditional Access policies, particularly geo-blocking and device compliance
- Privileged account separation (admin accounts not used for email)
- Self-Service Password Reset to reduce helpdesk-based social engineering
- Sign-in logs retained for at least 90 days
All of those live in Entra ID. The insurer may not call it that – they might say “Microsoft 365 identity controls” or “Azure AD” – but the answers are in the Entra admin centre. If your current IT provider cannot produce a one-page summary of what is enforced, that is a red flag for renewal.
The Entra ID baseline we apply to every new client
When a UK SMB onboards with us, the first job is auditing what is in their Entra tenant and bringing it up to a baseline. The baseline takes roughly five days and includes:
- MFA enforced on every user – not security defaults, but explicit Conditional Access policies you can show an auditor.
- Geo-blocking on sign-ins – everything outside the UK requires step-up authentication.
- Admin accounts separated from day-to-day user accounts.
- Self-Service Password Reset enabled with appropriate security questions.
- Risky sign-in alerts wired into our 24/7 monitoring.
- Inactive account sweep – anyone who has not logged in for 90 days gets disabled.
- Guest account review – anyone listed as External who is no longer working with the business gets removed.
- Sign-in logs forwarded to our SIEM for 90-day retention.
That eight-point baseline takes most clients from “we have MFA on most accounts” to “we can pass a cyber insurance renewal and a Cyber Essentials audit”. It is included in every Microsoft 365 tenant management engagement.
Common questions we get asked
“Do I need to do anything because of the rebrand?”
No. If your team is signing in as normal, MFA is working and you have not seen any error messages, the rebrand has not affected you. The change was cosmetic.
“Should I be on Entra ID Free, P1 or P2?”
P1 (which comes with M365 Business Premium) is the right answer for almost every UK SMB. Free is too limited; P2 is overkill unless you have a regulatory reason to use Privileged Identity Management.
“Is Entra ID the same as on-premise Active Directory?”
No. They share a name but are different products. On-prem AD runs on a Windows server in your office and manages local PCs and file shares. Entra ID is Microsoft’s cloud identity service and manages M365 access. Most modern UK SMBs run Entra ID alone with no on-prem AD – if you still have an on-prem domain controller, that is usually a conversation worth having.
“Can Entra ID handle our line-of-business apps?”
Most modern SaaS apps connect cleanly via SAML or OIDC, which Entra ID handles natively. Older applications that only support local accounts or LDAP are harder, but options exist (Entra ID Application Proxy, Microsoft Entra ID Federation). If you tell us which apps you depend on we can be specific.
“What about Entra Internet Access – do I need it?”
Almost certainly not, unless you are 200+ users and looking at Zero Trust Network Access. For a typical UK SMB with cloud-first apps, normal Conditional Access in Entra ID does the same job at a fraction of the cost.
What we do at Initial IT
We are a Microsoft Azure and Microsoft 365 consultancy in Lichfield, working with UK businesses of small businesses up to 100 staff. Most of our clients are on Microsoft 365 Business Premium with Entra ID P1, which is the sweet spot for SMB identity.
If you would like us to audit your Entra ID configuration against the eight-point baseline above and tell you where the gaps are, we run a free two-hour audit. You get a written report with screenshots of every setting, the gaps prioritised by insurance / compliance risk, and a fixed quote to close them.
Related reading: MFA vs Conditional Access: what UK small businesses actually need and Cyber insurance survival guide: passing your renewal in 2026.
Frequently asked questions
Is Microsoft Entra ID the same as Azure AD?
Yes. Microsoft renamed Azure Active Directory to Microsoft Entra ID in 2023. It is the same product, the same data and the same logins, just a different name.
Do I need to do anything because of the rename?
No. If your team is signing in as normal and MFA is working, the rename has not affected you. It was a cosmetic change.
Do I need Entra ID P1 or P2?
P1 is the right answer for almost every UK SMB, and it comes with Microsoft 365 Business Premium. P2 is only worth it if you have a specific need for risk-based sign-in or privileged access management.
Is Entra ID included in Microsoft 365 Business Premium?
Yes. Business Premium includes Entra ID P1, which gives you Conditional Access, Self-Service Password Reset and the controls most growing businesses need.
– Andy Price, Founder & MD, Initial IT · 01543 524594 · hello@initialit.co.uk
