Microsoft Just Made Token Protection More Affordable. Here's What You're Getting
Microsoft has quietly made one of its most important security features accessible to a much wider audience. Token Protection, previously exclusive to premium Entra ID tiers, is now available to Entra ID P1 customers. If your firm runs Microsoft 365 Business Premium, you already have the licensing.
What is Token Protection and why should you care?
When you log into Microsoft 365, the system issues a digital token, essentially a key that proves you’ve authenticated. That token gets reused for subsequent requests so you don’t have to enter your password every time you open Outlook or Teams.
The problem: if an attacker steals that token (through adversary-in-the-middle attacks, malware, or session hijacking), they can use it from a completely different device. Your MFA doesn’t help because the authentication already happened. The attacker is effectively logged in as you.
Token Protection creates a cryptographic binding between the token and the specific device it was issued to. If someone steals the token and tries to use it from a different machine, it doesn’t work. The token is useless without the original device.
This is a significant defence against one of the most common post-authentication attack techniques we see in the field.
Who benefits from this change?
Any organisation using Microsoft 365 Business Premium already includes Entra ID P1 licensing. That means enterprise-grade token protection is now available at no additional cost for most professional services firms that maintain proper Microsoft 365 licensing.
Previously, this capability required P2 licensing, a meaningful cost increase that put it out of reach for many smaller firms. That barrier is now gone.
Every managed cyber security plan at Novaguard includes Microsoft 365 Business Premium, which means this protection is available to all our managed clients.
What do you need to implement it?
There are requirements:
- Licensing: Entra ID P1 (included in Business Premium)
- Device management: Devices must be enrolled in Microsoft Intune
- Platform support: Currently Windows 10/11 (macOS and mobile support is on the roadmap)
- Device compliance: Devices must meet your defined compliance policies
The Intune enrolment requirement is the key dependency. If your devices aren’t managed through Intune, you’ll need to set that up first, which is something you should be doing regardless for proper device management.
How do you roll it out?
Phase 1: Preparation
Ensure all devices are enrolled in Intune and meeting your compliance policies. If you’re not sure about your current state, this is a good reason to run an M365 security audit.
Phase 2: Policy configuration
Configure the Token Protection policy through the Microsoft Entra admin centre. Start with report-only mode. This lets you see which sign-ins would be affected without actually blocking anything.
Phase 3: Gradual rollout
Begin with a pilot group (IT staff, then senior leadership, then general staff). Monitor for any disruption, then expand to the full organisation.
What else should you pair it with?
Token Protection works best as part of a layered identity security approach:
- Local Security Authority (LSA) protection: prevents credential dumping on Windows devices
- Microsoft Defender for Endpoint: detects suspicious authentication behaviour
- Credential Guard: isolates credentials in a virtualised environment
- Continuous Access Evaluation (CAE): revokes access in near-real-time when risk conditions change
If these terms sound unfamiliar, that’s exactly why it pays to have someone managing your Microsoft 365 security properly rather than leaving it at default settings. Most tenants we audit have less than 30% of their available security features actually configured.
What should you do next?
- Check your licensing. If you’re on Business Premium, you have P1. If you’re not sure, ask your IT provider.
- Check your device management. Are your devices enrolled in Intune? If not, that’s step one.
- Start in report-only mode. See what the impact looks like before enforcing.
- Talk to us if you want help. We configure this as part of our standard M365 security hardening process. It’s one of dozens of settings that most firms leave at default.
Want to know where you are actually exposed?
A Cyber Business Review tells you what an attacker would find first and what to fix in what order. Independent, and no switch required.
More on this: Cybersecurity articles · Managed Cybersecurity