A school’s security perimeter used to be the building’s network. Now it is the sign-in: whoever can authenticate as your staff is your staff, from anywhere on earth. Identity security is the discipline of making that sign-in trustworthy — and in a Microsoft school it comes down to two things with confusing names: Entra ID, and Conditional Access.
Entra ID, in one paragraph
Entra ID (formerly Azure Active Directory) is the directory your Microsoft 365 tenant runs on — every account, every group, every sign-in decision. Your school already has it; the question is which tier. Here the naming catches almost everyone: Office 365 Education plans (A1 included) carry basic Entra ID, while the Microsoft 365 Education A3/A5 families carry the premium tiers (P1/P2) that unlock policy-based security. Two similarly-named product families, materially different security ceilings — check which one your invoice actually says.
Conditional Access, and what it adds over the free baseline
Every tenant gets Microsoft’s free security defaults: one switch that makes everyone register for MFA, challenges when needed, always challenges admins, and blocks legacy protocols. It is genuinely good — and deliberately inflexible: no exceptions, no tailoring, on or off. Conditional Access (needs Entra ID P1, i.e. the Microsoft 365 A3/A5 families) replaces the one switch with rules: who is signing in, from where, on what device, into what — allow, challenge, or block.
- Require MFA for all staff, everywhere — the baseline policy, with a break-glass account deliberately excluded (see the MFA guide).
- Hold admin accounts to a higher bar — the accounts that control everything else justify stricter rules than classroom sign-ins.
- Block legacy authentication by policy — the old protocols that cannot do MFA are the back door password-sprayers love.
- Roll out in report-only first — Conditional Access can simulate a policy before enforcing it, which is how you avoid discovering at 8:45am that the whole staff room matched the wrong rule. Insist your provider uses it.
What the school should hold
Whichever tier you are on: a dated note of what protects sign-ins (security defaults on, or the Conditional Access policy list), the exception and break-glass arrangements, and who holds the highest-privilege roles. With consent, Atlas reads Microsoft’s sign-in risk detections and MFA registration coverage to keep a school’s identity picture current — it reads those reports, and configures nothing. The wider Microsoft context lives in the Microsoft 365 hub.


