Azure Active Directory Basic for Education

I once got a call from a K-12 district IT director who had just rolled out Microsoft 365 A1 licenses to 4,000 students and staff, only to discover that self-service password reset wasn’t working for students and conditional access policies wouldn’t save. Nobody on the team had told her that the identity tier bundled into her free education license had real limits.

That’s the story with Azure Active Directory Basic for Education — it’s the free identity foundation that ships with every Microsoft 365 Education tenant, but it’s not the same thing as the paid, full-featured identity plans schools eventually need.

Azure Active Directory Basic for Education

Azure Active Directory has since been rebranded to Microsoft Entra ID, but the “Basic for Education” tier name still shows up in licensing comparison sheets, procurement documents, and older support tickets, so IT admins searching for it need a clear picture of what it actually does and doesn’t cover.

This matters more than most administrators expect, because identity is the front door to every other Microsoft 365 and Azure resource a school or university uses — email, Teams, SharePoint, and any custom Azure app built on top.

By the end of this guide, you’ll understand exactly what’s included in the Basic for Education identity tier, where its limits will bite you operationally, and how to plan a secure upgrade path to Microsoft Entra ID Plan 1 or Plan 2 without over-licensing or overspending your education budget.

What Is Azure AD Basic for Education

Microsoft Entra ID for Education – Basic (the modern name for Azure Active Directory Basic for Education) is the free identity and access management tier included automatically with Microsoft 365 A1 and Office 365 A1 education subscriptions.

It provides the core directory service that every Microsoft cloud app in a school tenant depends on: user accounts, group membership, basic sign-in, and a limited set of security controls.

Think of it as the entry-level version of the same Microsoft Entra ID service that powers identity for every Azure subscription. A school district doesn’t pay extra for it — it’s bundled the moment you activate free or A1-tier Microsoft 365 Education licensing.

What’s actually included:

  • User provisioning — creating and managing student, teacher, and staff accounts, either manually or through bulk import.
  • Cloud user self-service password change — users who already know their current password can change it themselves.
  • Basic multifactor authentication (MFA) — a limited version of MFA, not the full conditional-access-driven MFA available in paid tiers.
  • Microsoft 365 Groups — basic group creation for collaboration spaces tied to Teams and SharePoint.
  • Limited single sign-on (SSO) — sign-on to a restricted set of pre-integrated SaaS apps, not the full app gallery.
  • Windows Hello for Business — basic biometric and PIN sign-in support on managed Windows devices.
  • School Data Sync (SDS) — the connector that syncs student information system (SIS) data into Microsoft 365 to auto-create classes, groups, and rosters.

What’s missing — and this is where I’ve seen the most support tickets — is Conditional Access, self-service password reset for users who forgot their password, dynamic group membership rules, the full SSO app gallery, and any identity governance or risk-based protection. If you’ve ever tried to build a conditional access policy in a free-tier Microsoft Entra tenant and found the option grayed out, this is why.

Basic vs. Premium: What Actually Changes

Schools frequently ask which paid Entra ID tier they should move to once Basic starts limiting daily operations. Here’s the practical breakdown based on what each tier actually unlocks in an education tenant.

CapabilityEntra ID Basic (Free, EDU)Entra ID P1Entra ID P2
User provisioning and groupsYesYesYes
Self-service password change (knows old password)YesYesYes
Self-service password reset (forgot password)NoYesYes
Conditional AccessNoYesYes
Dynamic group membershipNoYesYes
Application Proxy (secure remote access to on-prem apps)NoYesYes
Full SSO app galleryLimitedYesYes
Identity Protection (risk-based sign-in detection)NoNoYes
Privileged Identity Management (PIM)NoNoYes
Access reviews and entitlement managementNoNoYes

Microsoft 365 A3 education licensing includes Entra ID P1, and A5 includes Entra ID P2. That means the identity upgrade path for most districts is really a Microsoft 365 licensing tier decision, not a standalone Entra purchase — although standalone Entra ID P1 and P2 licenses are also available for schools that want to add identity capability without moving the entire tenant to a higher Microsoft 365 tier.

Pro Tip: I usually advise districts to pilot Conditional Access with a small P1-licensed admin group before buying P1 for the whole staff population. It’s much easier to catch a misconfigured policy that locks out five test accounts than five thousand real ones.

Common Azure Mistakes to Avoid

  • Assuming Basic tier includes Conditional Access. It doesn’t, and this is the single most common gap I see reported — admins configure a policy, save it, and it silently doesn’t apply because the tenant lacks P1 licensing.
  • Leaving self-service password reset unclear to end users. Basic tier only supports password change, not reset, so a locked-out student without their old password will need help desk intervention every time.
  • Over-provisioning Global Administrator roles. Use scoped roles like User Administrator or Groups Administrator instead of Global Admin for day-to-day identity management tasks.
  • Skipping MFA rollout because “it’s basic.” Even limited MFA is better than none — enable it for all staff and any account with elevated access immediately, regardless of licensing tier.
  • Forgetting School Data Sync governs more than rosters. SDS-created groups and classes affect Teams membership and SharePoint permissions automatically, so a bad SIS import can cascade into access problems across the whole tenant.
  • Not planning the upgrade path early. Waiting until a compliance audit forces a scramble to Entra ID P1 or P2 is far more disruptive than budgeting the upgrade during the annual licensing renewal cycle.

Securing Identity When You Can’t Use Conditional Access

If your tenant is still on the Basic for Education tier and a full Entra ID P1/P2 upgrade isn’t budgeted yet, you’re not defenseless — you just have to work harder on the controls that are available.

Start with multifactor authentication, an authentication method that requires more than one form of verification, such as a password plus a phone approval. Even the basic MFA available in the free tier significantly reduces account takeover risk, and it should be mandatory for every staff and admin account handling student records, grading systems, or financial data.

Next, review your RBAC assignments in the Microsoft Entra admin center. Least privilege means giving each IT staffer only the specific administrative role they need — a helpdesk technician managing password resets doesn’t need the same role as someone managing Exchange Online settings. Document who holds which role and why, and revisit that list on a schedule, not just when someone leaves.

If your district is building or hosting any custom application — a parent communication portal, an attendance dashboard, a grade-reporting tool — never store database connection strings, API keys, or service credentials in application configuration files or in a spreadsheet shared over email.

Use Azure Key Vault, a service purpose-built for securely storing secrets, keys, and certificates, and connect your app to it using a managed identity so the application authenticates without any credential ever being written into code or config. This is non-negotiable for anything handling student data under FERPA-comparable privacy expectations.

For any Azure resource beyond the Microsoft 365 tenant itself — say, an Azure-hosted grading API — apply RBAC roles scoped to a specific resource group rather than subscription-wide Contributor access. That way a compromised app credential can’t pivot into unrelated district resources.

Pro Tip: I’ve told more than one district technology director the same thing: MFA and tight RBAC scoping cost nothing extra and stop the vast majority of real-world account compromise attempts I’ve investigated. Don’t wait for a paid tier to start enforcing them.

Planning the Upgrade to Entra ID P1 or P2

When a district outgrows Basic — usually triggered by a compliance requirement, a cyber-insurance questionnaire, or a security incident — the upgrade decision comes down to matching the license to the actual operational need rather than buying the most expensive tier available.

Entra ID P1 is the right call when the core pain point is Conditional Access, real self-service password reset, or dynamic group membership for large student populations that change every semester. Most districts moving from Basic to A3 licensing get P1 bundled in automatically.

Entra ID P2 becomes necessary when the district needs Identity Protection’s risk-based sign-in detection, Privileged Identity Management for just-in-time admin access, or access reviews to periodically validate who still needs elevated permissions. This tier is usually justified by a formal security or compliance mandate rather than day-to-day convenience, and it typically arrives bundled with Microsoft 365 A5.

Before committing budget, run a pilot. Enable the new tier for a test group of accounts, configure a handful of Conditional Access policies — for example, requiring MFA for sign-ins outside the country or blocking legacy authentication protocols — and validate the behavior with both an admin account and a standard non-admin test account.

Testing with a limited-privilege account catches permission-scoping mistakes that testing only as Global Administrator will hide.

Pro Tip: I always run a two-week pilot with IT staff accounts before touching student or faculty populations. Conditional Access policies can lock people out fast if a location or device condition is misconfigured, and it’s much less painful to fix that mistake with five IT staff than five thousand students mid-semester.

Monitoring, Logging, and Ongoing Maintenance

Regardless of which identity tier a school tenant runs, ongoing visibility into sign-in activity matters. Azure Monitor and the sign-in and audit logs available in the Microsoft Entra admin center let you track failed sign-ins, unusual location patterns, and administrative role changes. Even Basic-tier tenants get access to sign-in logs, though retention periods and advanced log analytics require paid tiers.

Set up alerts for sensitive operations — a new Global Administrator being added, a bulk user deletion, or a spike in failed sign-ins from an unfamiliar country — so your team finds out about a problem in minutes, not weeks.

If your district also runs workloads in Azure proper (not just Microsoft 365), pair Entra ID monitoring with Application Insights for any custom-built application, giving you telemetry on both the identity layer and the application layer in one operational view.

Maintenance in this space isn’t a one-time project. New staff onboarding, graduating student offboarding, and annual licensing renewals all touch the identity tier.

Build a repeatable checklist: verify license assignment through group-based licensing rather than manual per-user assignment, confirm stale accounts are disabled promptly, and re-review admin role membership every semester.

Pro Tip: Group-based licensing has saved my clients more administrative hours than almost any other single Entra ID feature — assign a license to a dynamic or SDS-synced group once, and every new student or staff member who lands in that group inherits the license automatically, with no manual per-user task.

Frequently Asked Questions

What is Microsoft Azure used for in education?

Microsoft Azure and Microsoft 365 Education together give schools cloud-based email, collaboration tools like Teams and SharePoint, identity management through Microsoft Entra ID, and infrastructure for hosting custom applications like grade portals or data pipelines without maintaining on-premises servers.

Is Azure Active Directory Basic for Education still an active product name?

The service is now called Microsoft Entra ID for Education – Basic, following Microsoft’s 2023 rebrand of Azure Active Directory to Microsoft Entra ID. The underlying free tier and its feature set remain functionally the same as what was previously marketed as Azure AD Basic for Education.

Does Azure AD Basic for Education include Conditional Access?

No. Conditional Access, the feature that enforces sign-in rules based on location, device, or risk level, is only available starting at Microsoft Entra ID P1, which comes bundled with Microsoft 365 A3 and higher education licensing tiers.

How do I secure secrets and credentials in an education Azure tenant?

Store all API keys, connection strings, and certificates in Azure Key Vault rather than app settings or spreadsheets, and connect applications to it using a managed identity so no credential is ever hardcoded. This applies regardless of which Entra ID tier your tenant runs.

Should a school district upgrade to Entra ID P1 or P2?

Choose P1 if the priority is Conditional Access, real self-service password reset, and dynamic groups for a changing student population. Choose P2 only if you need risk-based Identity Protection, Privileged Identity Management, or access reviews, since P2 is typically driven by a formal compliance or security mandate.

You now know exactly what Azure Active Directory Basic for Education includes, where its limits show up in daily school operations, and how to plan a secure, cost-aware upgrade to Microsoft Entra ID P1 or P2 when the time comes. Whatever tier your tenant runs, the principles of least-privilege RBAC, mandatory MFA, and proper secret storage in Azure Key Vault apply from day one, not just after a paid upgrade. I hope you found this article helpful.

You May Also Like