Entra ID P1 vs P2: The 3 Features That Justify the Upgrade (2025)
Entra ID P2 adds exactly three things over P1: Identity Protection, Privileged Identity Management, and Access Reviews. Here's when each one matters and whether the $3/user/month difference is worth it.
In brief
- P2 adds exactly three things over P1: Identity Protection, Privileged Identity Management (PIM), and Access Reviews
- P1 costs $6/user/month; P2 costs $9/user/month — a $3 difference that matters at scale
- 91% of organizations reported an identity-related breach in the past year (SpyCloud, 2025) — the question isn’t whether identity matters, but which controls you actually need
- If your IT admins have standing admin access and you’re in a regulated industry, P2 pays for itself
- Many organizations already have P1 or P2 included in their Microsoft 365 E3/E5 licenses without realizing it
Entra ID P1 vs P2: what actually changes
The honest answer is simple. Entra ID P2 adds three features over P1:
- Identity Protection — ML-based risk scoring for every sign-in, with automated policies that can block, challenge, or allow access based on real-time risk
- Privileged Identity Management (PIM) — just-in-time elevation for admin roles, with time limits, approval workflows, and full audit logs. No more permanently assigned Global Admins
- Access Reviews — scheduled automated audits that ask managers or users to confirm whether they still need specific access, with automatic removal for non-responses
Everything else in P2 is also in P1. Conditional access, MFA, SSPR, hybrid sync, dynamic groups — all P1.
According to Microsoft’s 2025 Digital Defense Report, 80% of MFA-bypass breaches involved session-token theft via adversary-in-the-middle attacks. Identity Protection in P2 detects these patterns and can block access automatically — a capability P1’s conditional access alone cannot replicate (Microsoft Security, 2025).
What is Microsoft Entra ID?
Entra ID (formerly Azure Active Directory) is Microsoft’s cloud identity platform. It handles authentication and authorization for Microsoft 365, Azure, and thousands of integrated SaaS applications. Every user in your Microsoft tenant has an Entra ID identity.
The platform comes in four tiers: Free, P1, P2, and Entra Suite. Free covers the basics. P1 and P2 are the paid tiers most organizations compare. Entra Suite is the bundle for organizations that also need network access security (ZTNA, SWG).
Our team put together a video covering exactly what Entra ID is and how it replaced Azure Active Directory:
Note: this video is in Italian. Enable YouTube auto-translated subtitles for English captions.
For a broader overview of Entra ID’s architecture and capabilities, see our guide on Microsoft Defender for Identity.
Entra ID Free: the baseline
The free tier covers what every Microsoft tenant gets by default:
- Basic user and group management (static groups)
- Password hash sync and pass-through authentication
- SSO for Microsoft apps and limited third-party SaaS
- MFA at tenant level only (no per-user or per-group granularity)
- SSPR for cloud-only users
Free is fine for very small organizations with simple setups. The moment you need conditional access policies, granular MFA, or on-premises integration, you need P1.
Entra ID P1: the practical security baseline
P1 is included in Microsoft 365 E3, M365 Business Premium, EMS E3, and Microsoft 365 F1. If you have any of these, you already have P1.
Key additions over Free:
- Conditional Access engine — full policy control based on user, device, location, app, and risk signals. The foundation of Zero Trust identity security
- Group-based MFA — assign different MFA requirements to different user groups, not just blanket tenant settings
- Dynamic groups — automatically assign users to groups based on attributes (department, job title, location)
- SSPR for hybrid users — extend self-service password reset to on-premises accounts
- Hybrid identity sync — synchronize on-premises Active Directory with Entra ID, including password writeback
- Session lifetime management — control token expiration for high-risk applications
- Cross-tenant synchronization — keep security policies consistent across multiple Azure AD tenants
For most SMBs and mid-market organizations, P1 is enough. It covers all the standard Zero Trust building blocks without the advanced identity governance that P2 adds.
Microsoft Entra ID — key features overview
Entra ID P2: the three additions worth knowing
P2 is included in Microsoft 365 E5, EMS E5, Microsoft 365 E5 Security, and Microsoft 365 A5.
1. Identity Protection
Identity Protection continuously analyzes every sign-in for risk indicators: leaked credentials, anonymous IP addresses, atypical travel, token anomalies, and malware-linked IP addresses. Each sign-in gets a real-time risk score (low/medium/high).
You can then create risk-based conditional access policies:
- User risk policy: if a user’s credentials appear in a breach list, require a password reset before the next login
- Sign-in risk policy: if a sign-in scores medium risk, require MFA; if high risk, block entirely
22% of all enterprise breaches in 2025 started with stolen credentials (Verizon DBIR, 2025). Identity Protection’s automated response to compromised credentials is the clearest justification for P2 in most organizations.
2. Privileged Identity Management (PIM)
PIM eliminates standing admin access. Instead of permanently assigning Global Admin or other privileged roles, you configure them as eligible. When an admin needs elevated access:
- They request activation through the Entra portal or PIM app
- They provide a justification (and optionally go through approval)
- Access is granted for a defined window (e.g., 1-4 hours)
- Access expires automatically, and the full session is logged
This matters because standing admin accounts are a primary target for attackers. An admin account that only has elevated access for 2 hours out of every 720 dramatically shrinks the attack surface.
PIM also enables PIM-based Access Reviews — reviewing who is eligible for privileged roles, not just who has active assignments.
3. Access Reviews
Access Reviews automate the governance question: “Does this person still need this access?” You configure a review cadence (monthly, quarterly, annually), assign reviewers (managers, resource owners, or users themselves), and set what happens when no response comes in — typically, access is removed.
Without Access Reviews, access accumulation goes unchecked. Users change roles, leave projects, or move departments while their previous access permissions stay intact. Access Reviews are the structured way to close that gap, and they’re a direct compliance requirement in NIS2, ISO 27001, and SOC 2.
For more on NIS2 compliance requirements, see our NIS2 guide.
P1 vs P2: which one do you need?
| Scenario | Recommendation |
|---|---|
| SMB, under 100 users, no IT admins with elevated roles | P1 is enough |
| Microsoft 365 E3 subscription | P1 is already included |
| IT team with Global Admin or similar standing assignments | P2 (PIM) |
| Regulated industry (finance, healthcare, legal) | P2 (Identity Protection + Access Reviews) |
| History of credential compromise or phishing incidents | P2 (Identity Protection) |
| Audit requirements for user access governance | P2 (Access Reviews) |
| Microsoft 365 E5 subscription | P2 is already included |
A practical approach for cost optimization: assign P2 only to accounts that are eligible for privileged roles or subject to Identity Protection risk policies. Most end users can stay on P1. A 500-user organization where 15 people have admin access might need P2 licenses for 15-20 users, not 500.
Pricing and licensing summary
| Plan | Standalone price | Included in |
|---|---|---|
| Entra ID Free | $0 | All Microsoft 365 plans |
| Entra ID P1 | $6/user/month | M365 E3, M365 Business Premium, EMS E3, M365 F1 |
| Entra ID P2 | $9/user/month | M365 E5, EMS E5, M365 E5 Security, M365 A5 |
| Entra Suite | $12/user/month | Add-on (requires P1) |
Prices are in USD on annual commitment. EUR pricing is approximately €5.60 (P1) and €8.40 (P2).
Before purchasing P1 or P2 standalone, check what’s already included in your Microsoft 365 subscription. Many organizations pay for extra Entra licenses without realizing they’re already covered.
Microsoft Entra Suite: when you need more than P2
The Entra Suite bundles five products into one SKU at $12/user/month:
- Private Access: ZTNA for on-premises applications, replacing legacy VPN
- Internet Access: secure web gateway (SWG) with content filtering and TLS inspection
- ID Protection: same as P2’s Identity Protection
- ID Governance: automated identity lifecycle management (joiners, movers, leavers)
- Verified ID Face Check: decentralized credential verification with facial liveness check
Entra Suite requires P1 as a prerequisite. It’s designed for organizations moving to a full Zero Trust architecture, replacing network-based perimeter security with identity-based access controls for both internal and internet-bound traffic.
Feature comparison: Free vs P1 vs P2 vs Entra Suite
| Feature | Free | P1 | P2 | Suite |
|---|---|---|---|---|
| Basic SSO | Yes | Yes | Yes | Yes |
| MFA (tenant level) | Yes | Yes | Yes | Yes |
| Group-based MFA | No | Yes | Yes | Yes |
| Conditional Access | No | Yes | Yes | Yes |
| Dynamic groups | No | Yes | Yes | Yes |
| Hybrid identity sync | No | Yes | Yes | Yes |
| SSPR (cloud + hybrid) | Cloud only | Yes | Yes | Yes |
| Identity Protection | No | No | Yes | Yes |
| Privileged Identity Management | No | No | Yes | Yes |
| Access Reviews | No | No | Yes | Yes |
| Private Access (ZTNA) | No | No | No | Yes |
| Internet Access (SWG) | No | No | No | Yes |
| ID Governance | No | No | No | Yes |
FAQ
What does Entra ID P2 add over P1? Entra ID P2 adds three capabilities: Identity Protection (ML-based risk scoring for every sign-in), Privileged Identity Management (just-in-time admin access with approval workflows), and Access Reviews (automated periodic audits of who has access to what). Everything else — conditional access, MFA, hybrid sync, dynamic groups — is already in P1.
How much does Entra ID P1 vs P2 cost? P1 costs $6/user/month (approx. €5.60). P2 costs $9/user/month (approx. €8.40). The $3 difference per user gets you Identity Protection, PIM, and Access Reviews. Both require annual commitment. Many organizations already have P1 or P2 included in their existing Microsoft 365 E3 or E5 subscriptions.
Which Microsoft 365 licenses include Entra ID P1 or P2? P1 is included in Microsoft 365 E3, Microsoft 365 Business Premium, EMS E3, and Microsoft 365 F1. P2 is included in Microsoft 365 E5, EMS E5, Microsoft 365 E5 Security, and Microsoft 365 A5. Always check your existing subscription before purchasing separately.
Is Entra ID P1 enough for most organizations? For most SMBs without strict compliance requirements, P1 covers the main security needs: conditional access, MFA, SSPR, and hybrid sync. P2 is worth the upgrade when you have IT admins with standing elevated access, work in a regulated industry, or need structured access governance for compliance audits.
Can you mix P1 and P2 licenses in the same tenant? Yes. You can assign P2 only to users who need PIM or are subject to Identity Protection risk policies — typically IT admins and power users with access to critical systems — while keeping most end users on P1. This approach significantly reduces cost while meeting compliance requirements where they actually apply.
What is the Microsoft Entra Suite? The Entra Suite bundles Private Access (ZTNA for on-premises apps), Internet Access (SWG), ID Protection, ID Governance, and Verified ID Face Check into a single SKU at $12/user/month. It requires P1 as a prerequisite and is designed for organizations building a full Zero Trust architecture that also addresses network access security.
Written by
Emanuele Rossi
Infra & Security · Dev4Side
Dev4Side Software · Microsoft Gold Partner
Need help implementing this in your company?
Our specialist teams have delivered 200+ Microsoft implementations across Italy. Contact us for a free, no-obligation evaluation of your project.
Related articles
NIS2 Directive: What it is and how to achieve compliance
Let's see what it is, when it comes into force, and how to meet the requirements of NIS2, the new European directive for managing cybersecurity risks.
Defender for Identity: How to combat threats to user identities
Defender for Identity monitors on-premises Active Directory to detect lateral movement and identity-based attacks before they compromise your network.
Microsoft Entra ID is the new Azure AD: How does it work?
Microsoft Entra ID is the evolution of Azure Active Directory, the solution for identity and access management. Here are differences, features, and costs.