Every Microsoft 365 customer already has Microsoft Entra ID, even if nobody calls it that. It is the directory behind your Outlook and Teams logins. Azure uses the same directory. Set up properly, your staff sign in to Azure with the accounts they already have, the same security rules apply, and when someone leaves you switch off one account, not three.
Set up badly, you end up with an Azure subscription in a different directory, shared admin passwords and former staff who can still reach production.
How the pieces fit
- Tenant: your organisation’s copy of Entra ID. Microsoft 365 created one for you, usually named after your domain.
- Azure subscription: where your Azure resources and bill live. Each subscription trusts exactly one tenant for sign-in.
- Roles: what someone can do in Azure (Owner, Contributor, Reader and many more specific ones), given at the level of a subscription, a resource group or a single resource.
Step 1: Put Azure in your Microsoft 365 tenant
When you create Azure, sign up with a work account from your Microsoft 365 domain. The subscription then trusts your existing tenant and every staff account is available straight away.
If someone created Azure earlier with a personal Microsoft account, or with a separate trial tenant, you can move the subscription to your company tenant with Change directory. Plan it: role assignments are removed during the move and have to be added back, and some services need extra steps. It is much easier to do this before anything important runs there.
Step 2: Give access to groups, not people
- Create groups such as Azure Admins, Azure Developers and Azure Billing Readers.
- Give each group the smallest role that does the job, at the narrowest level that works. Developers rarely need Owner on the whole subscription.
- Joiners and leavers are then a group change. When HR disables an account, its Azure access goes with it.
Step 3: Require MFA, which Microsoft now enforces anyway
Microsoft has made multi-factor authentication mandatory for managing Azure. It has been required for the Azure portal, the Microsoft Entra admin center and the Intune admin center since the second half of 2024, and for the Microsoft 365 admin center since February 2025. From 1 October 2025 it extended to Azure CLI, Azure PowerShell, the Azure mobile app and infrastructure-as-code tools for any action that creates, changes or deletes something.
So the question is not whether to use MFA, but how:
- Security defaults are free with every tenant and switch on sensible MFA rules for everyone.
- Conditional Access lets you set your own rules, for example: always require MFA for admins, block sign-ins from outside India, or allow only company-managed laptops. It needs Entra ID P1.
Which licence gives you what
| Entra ID edition | Included in | Adds |
|---|---|---|
| Free | Every Microsoft 365 and Azure subscription | Users and groups, security defaults, MFA with Microsoft Authenticator, self-service password reset |
| P1 | Microsoft 365 Business Premium, E3, E5, F1, F3 | Conditional Access, password reset written back to your on-site Active Directory |
| P2 | Microsoft 365 E5 | Privileged Identity Management, Identity Protection (risk-based sign-in rules), access reviews |
For most small and mid-sized companies, Microsoft 365 Business Premium is the sweet spot: it includes P1, so you get Conditional Access for both Microsoft 365 and Azure without buying anything extra.
Step 4: Protect the admin accounts
- Separate admin accounts. People who manage Azure should have a second account for admin work, not use the one they read email with.
- Admin rights only when needed. With Entra ID P2, Privileged Identity Management lets someone switch on an admin role for a few hours, with a reason, and it switches off by itself.
- Two emergency accounts. Keep two “break-glass” accounts for when normal sign-in fails. Under Microsoft’s rules they need MFA too, so give them hardware security keys or passkeys and store those safely.
Step 5: Let apps sign in without passwords
Scripts and apps that talk to Azure shouldn’t use a person’s login or a password saved in a file. Use managed identities for anything running in Azure: the app gets its own identity and nobody handles a secret. Microsoft’s MFA rules don’t apply to these workload identities, but user accounts used as service accounts must move to them.
Partners and contractors
When an outside firm needs to work in your Azure, invite their people as guests in your tenant instead of creating new accounts for them. They sign in with their own company login, your MFA rules still apply, and you can remove their access in one step when the work ends. Put guests in their own group so they are easy to review.
Still running Active Directory on site?
Many companies still have a Windows Active Directory in the office. Microsoft Entra Connect (or the lighter Cloud Sync) copies those users into Entra ID, so the same username and password work in the office, in Microsoft 365 and in Azure.
A 30-day plan
- Week 1: confirm the Azure subscription is in your Microsoft 365 tenant (move it if not), and list everyone who has a role in Azure today.
- Week 2: create the groups, give roles to groups, and remove direct assignments to individuals.
- Week 3: turn on security defaults or Conditional Access, create separate admin accounts and the two emergency accounts.
- Week 4: replace stored passwords in scripts and apps with managed identities, and write down who owns what.
Tick what is already true
A quick check of your setup
- Is your Azure subscription in the same tenant as Microsoft 365?
- Are Azure roles given to groups, with nobody holding Owner who doesn’t need it?
- Does every account that manages Azure use MFA, including emergency accounts?
- Do admins use separate admin accounts?
- Do your apps use managed identities instead of stored passwords?
Where DevOps TechLab fits
We sell every Microsoft 365 plan, usually below list price, and we are a Microsoft Solutions Partner for Cloud and AI Platforms. We can move your Azure subscription into the right tenant, set up groups, roles and Conditional Access, protect your admin accounts, and raise and follow up Microsoft support cases for you if anything goes wrong.
Questions people ask
Is Microsoft Entra ID the same as Azure Active Directory?
Yes. Microsoft renamed Azure Active Directory to Microsoft Entra ID. It is the directory behind Microsoft 365 and Azure sign-ins.
Can we use our Microsoft 365 accounts to sign in to Azure?
Yes, as long as the Azure subscription trusts the same tenant as Microsoft 365. Create Azure with a work account, or move an existing subscription with Change directory.
Is MFA required for Azure?
Yes. Microsoft requires MFA for the Azure portal and admin centres, and since 1 October 2025 for Azure CLI, PowerShell and infrastructure-as-code tools when they create, change or delete resources.
Do we need Entra ID P1 for Conditional Access?
Yes. P1 is included in Microsoft 365 Business Premium, E3, E5, F1 and F3, or can be bought on its own.
What happens to Azure access when an employee leaves?
If access is given through groups and the account is disabled in Entra ID, their Azure access stops at the same time.
Want one login and fewer admin accounts to worry about?
Book a 20-minute review. We will check your tenant, Azure roles and MFA, and tell you what to fix first.







