Cloud · 6 min

Entra ID (Azure AD) — the identity foundation

Identity is the new perimeter. Entra ID in practice.

12 October 2025

Public cloud, private cloud, hybrid — for many boards these words simply mean "expensive and complicated". In reality a well-designed cloud reduces TCO and strengthens business resilience. Here we break Entra ID (Azure AD) — the identity foundation down into simple decision steps.

Identity is the new perimeter. Entra ID in practice.

Identity as the foundation

The answer is "it depends" — but it depends on a few very concrete things that can fit on one page. For Entra ID (Azure AD) — the identity foundation the four key variables are: company size, industry, downtime tolerance, and budget.

  • Companies up to 20 people — outsourcing and public cloud usually win.
  • 20–100 people — a mixed model: a dedicated account manager + provider's team.
  • 100+ people — an internal IT department supported by external specialists (security, cloud).
  • Regulated industries (medical, financial) — always additional compliance layers, regardless of size.

MFA and SSO

Modern IT security works in layers. No single solution protects a company 100% — only a full set of layers (identity, endpoints, network, data, people) provides real effect. In the context of Entra ID (Azure AD) — the identity foundation it is worth starting with the basics:

  • MFA on all accounts (no exceptions for the board — the most common gap).
  • EDR/XDR instead of classic antivirus — it detects behaviour, not just signatures.
  • Backups in several locations, including an offline or immutable copy — ransomware cannot encrypt them.
  • Patches within 14 days of the vendor's release.
  • Anti-phishing training at least quarterly, with simulations.
Rule of thumb: spending on prevention is on average 10–15× lower than the cost of recovering from a successful ransomware attack (not counting lost reputation and GDPR fines).

Conditional Access

This section frames the topic "Conditional Access" in the context of Entra ID (Azure AD) — the identity foundation. We approach it from the business side — what concrete value or risk it brings to the company.

What you gain

  • Scalability — you pay for what you actually use.
  • High availability without investing in your own HA infrastructure.
  • Faster rollout of new applications and test environments.

Most common mistakes

  • Lift-and-shift migration without optimisation — the cloud ends up more expensive than the on-prem room.
  • No resource tagging — after six months nobody knows what belongs to whom.
  • Publicly open storage buckets — the most common source of leaks.

Dynamic groups

This section frames the topic "Dynamic groups" in the context of Entra ID (Azure AD) — the identity foundation. We approach it from the business side — what concrete value or risk it brings to the company.

What you gain

  • Scalability — you pay for what you actually use.
  • High availability without investing in your own HA infrastructure.
  • Faster rollout of new applications and test environments.

Most common mistakes

  • Lift-and-shift migration without optimisation — the cloud ends up more expensive than the on-prem room.
  • No resource tagging — after six months nobody knows what belongs to whom.
  • Publicly open storage buckets — the most common source of leaks.

Key takeaways

  • Scalability — you pay for what you actually use.
  • Lift-and-shift migration without optimisation — the cloud ends up more expensive than the on-prem room.
  • Treat the topic of "Entra ID (Azure AD) — the identity foundation" as a project, not a one-off purchase — the best results come from a step-by-step approach.

Frequently asked questions

Planning a cloud migration?

Book a free cloud consultation. We will do a quick assessment of your current infrastructure, estimate cloud TCO and present a migration plan tuned to your budget.