Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Entra ID P1 vs P2: Conditional Access or Full Identity Governance?

10 min read Updated October 4, 2026 Microsoft Licensing Guides

Fix it now

P1 is where conditional access appears, along with self-service password reset with on-premises writeback, dynamic groups, group-based licensing and Application Proxy. P2 adds Identity Protection and risk-based conditional access, Privileged Identity Management, access reviews and basic entitlement management. Lifecycle workflows and the deeper governance features sit in a separate Microsoft Entra ID Governance licence, not in P2.

  1. Start with the free tier if the tenant is small and has no exceptions to make. Security defaults enforce multi-factor authentication for everyone at no cost.
  2. Buy P1 the moment a policy must differ by role, location, device state or application. That is conditional access, and there is no free route to it.
  3. Buy P2 for accounts that hold standing administrative rights, so the role becomes something they activate rather than something they hold.
  4. Buy P2 where you must demonstrate periodic access recertification, because access reviews produce the evidence auditors ask for.
  5. Buy Entra ID Governance, not P2, if lifecycle workflows or the advanced entitlement features are the reason you are buying.
  6. Check what you own first. P1 comes with Microsoft 365 Business Premium, E3, F1, F3 and EMS E3; P2 comes with E5, EMS E5 and the Microsoft Defender Suite.

Licensing is per user, and the rule is that every user in scope of a paid feature needs the licence – not just the administrator who wrote the policy.

If you only need multi-factor authentication with no exceptions, stop here: the free tier covers it. Below is what each tier buys and the scoping rule that decides how many licences you actually need.

Why it happens

The question is not which tier is better but which controls you have committed to operating, because Entra licensing is bought per user in scope rather than per administrator.

The free tier does more than people assume. Every Microsoft 365 subscription carries Microsoft Entra ID at no extra cost, and Microsoft lists security defaults with multi-factor authentication enabled for all users, single sign-on to cloud applications, self-service password change, audit and sign-in logs, and basic user and group management. What it cannot do is make exceptions. Security defaults apply the same rule to everyone; you cannot exempt a service account, relax the requirement on a trusted network or tighten it for administrators.

Somebody has said the policy must differ

You have this one if You need a compliant device for mailbox access but a browser session from anywhere for a low-value application, or you need to block sign-ins from countries you do not operate in.

  1. That is conditional access, and conditional access is P1. It evaluates each sign-in against signals you choose – user or group, application, device compliance state, location, client type – and permits, blocks or adds a requirement.
  2. Around it sit the features that quietly matter more day to day: self-service password reset with writeback to on-premises Active Directory, dynamic groups that populate themselves from attributes, group-based licence assignment, and Application Proxy for publishing internal web applications without a VPN.
  3. Once you turn security defaults off to build conditional access, build the policies deliberately and verify them before relying on them. You have replaced a working baseline with an empty ruleset.

Administrators hold standing privilege

You have this one if Several accounts are permanently in privileged roles, and the security policy says they should not be.

  1. Privileged Identity Management is the mechanism, and it needs Entra ID P2 or Entra ID Governance. It makes an administrative role something a person activates for a defined period with justification and approval, rather than something they hold.
  2. Microsoft’s licensing rule for it is explicit: users with eligible or time-bound assignments, plus approvers and reviewers, all need the licence.
  3. Buying P2 for a small group of administrators and keeping everyone else on P1 is a supported and sensible pattern. Write down which population is covered so it survives staff changes.

An auditor wants evidence of access recertification

You have this one if You must show that somebody periodically confirms each member of a group still needs to be in it.

  1. Access reviews are the feature and they need P2. Microsoft’s licensing example is worth internalising: an access review of a group with 75 member users and one group owner as reviewer requires 76 licences – 75 for the reviewed users and one for the reviewer.
  2. That arithmetic applies to entitlement management too: all users who can request an access package must be licensed.
  3. So the number of P2 licences is set by the population in scope of the control, not by the number of people who operate it.

You are buying P2 for joiner-mover-leaver automation

You have this one if The requirement is automated onboarding and offboarding workflows driven by attribute changes.

  1. Lifecycle workflows are not in P2. Microsoft lists them under Microsoft Entra ID Governance only, along with custom extensions using Logic Apps and machine-learning-assisted access certifications.
  2. Entra ID Governance is sold as an add-on for P1 and P2 customers, and it also includes the P2 governance capabilities.
  3. Confirm which licence carries the specific feature you are buying before ordering, because this is the boundary Microsoft has moved most recently.

Full reference

What sits in each tier

Capability Free P1 P2 ID Governance
Single sign-on and cloud user management Yes Yes Yes Yes
Security defaults, enforcing MFA for everyone Yes Yes Yes Yes
Self-service password change Yes Yes Yes Yes
Audit and sign-in logs Yes Yes Yes Yes
Conditional access policies No Yes Yes Yes
Self-service password reset with on-premises writeback No Yes Yes Yes
Dynamic groups and group-based licensing No Yes Yes Yes
Application Proxy for internal web apps No Yes Yes Yes
Identity Protection and risk-based conditional access No No Yes Yes
Privileged Identity Management No No Yes Yes
Access reviews for groups and applications No No Yes Yes
Entitlement management, basic access packages No No Yes Yes
Lifecycle workflows No No No Yes
Custom extensions and machine-learning access recommendations No No No Yes

The licensing rule that decides your quantity

Entra ID is licensed per user, and Microsoft’s rule is that users in scope of a governance or premium feature must be licensed – requesting access, being reviewed, holding an eligible role assignment, or falling within a workflow’s scope. Its own worked example is the clearest statement of how literally that is meant: an access review covering 75 users with one reviewer needs 76 licences.

Apply the same test to conditional access. A policy scoped to all users puts all users in scope, so every one of them needs P1, not just the administrator who wrote it. Scoping a policy narrowly to a licensed group is a legitimate way to control cost, but it is a decision to make deliberately and to document, not one to discover at renewal. The same logic applies to P2: build risk-based policies that evaluate the whole tenant and the whole tenant is in scope.

Where each tier comes from

  • Entra ID P1 is included in Microsoft 365 E3 and E5, Microsoft 365 F1 and F3, Enterprise Mobility + Security E3, and Microsoft 365 Business Premium.
  • Entra ID P2 is included in Microsoft 365 E5, Enterprise Mobility + Security E5, and the Microsoft Defender Suite – the add-on Microsoft renamed from Microsoft 365 E5 Security on 1 October 2025 – including its Business Premium variant.
  • Entra ID Governance is a separate add-on for P1 and P2 customers, and the Microsoft Entra Suite bundles P1 with Governance and Verified ID.
  • Buying the Microsoft 365 plan that contains the tier is often cheaper than buying the tier standalone, so price both routes.

A sensible sequence

  1. Turn security defaults on if they are not already. It costs nothing and prevents the most common compromise.
  2. List the controls you have actually committed to – in a policy document, an insurance questionnaire or a certification scheme – rather than the ones that sound good.
  3. Map each control to the tier that carries it: exceptions and device conditions to P1, risk-based automation and privileged access to P2, lifecycle automation to Entra ID Governance.
  4. Count the population in scope of each control, not the administrators. That is your licence quantity.
  5. Check what your existing Microsoft 365 plans already grant before buying anything standalone.
  6. Assign ownership for each control. A licence with nobody operating it produces cost and no improvement.

Which tier to buy, by situation

  • A small tenant with no exceptions to make and no on-premises directory: security defaults may be enough, and that is a defensible position that costs nothing.
  • A tenant under 300 seats already on Microsoft 365 Business Premium: you have P1. Build conditional access deliberately and buy nothing else yet.
  • Any organisation that must require compliant or hybrid-joined devices, restrict sign-ins by location, or treat administrators differently: P1 at minimum.
  • Any organisation with permanent global administrators: P2 for those accounts, plus their approvers and reviewers.
  • Regulated organisations that must demonstrate periodic access recertification: P2, and count the reviewed population as well as the reviewers.
  • Anyone needing joiner-mover-leaver automation: Entra ID Governance, not P2.
  • Anyone already licensed for Microsoft 365 E5: you hold P2. Check before buying it again.

When a licence is the actual fix

If you need conditional access – and almost every organisation that has answered a security questionnaire does – Microsoft Entra ID P1 is the licence that provides it, and there is no free route to the same control. Arco supplies Entra ID P1 and P2 standalone and the Microsoft 365 plans that include them, which is often the cheaper way to arrive at the same entitlement: P1 comes with Business Premium and E3, and P2 with E5 and the Microsoft Defender Suite. Tell us your seat count and which controls you have committed to operating, and we will check what your current subscriptions already grant before quoting anything new. If lifecycle workflows are the reason you are asking, we will point you at Entra ID Governance rather than P2, because that is where Microsoft puts them.

Questions people ask about this

Do I need a licence for every user, or only for administrators?

Every user in scope of a paid feature. A conditional access policy scoped to all users puts all users in scope. Microsoft’s governance licensing guidance gives the arithmetic explicitly for access reviews: a review of a group with 75 members and one reviewer needs 76 licences. Guests are handled under separate rules, so check those if you have many external collaborators.

Is multi-factor authentication free?

Yes, in the sense that security defaults come with the free Microsoft Entra ID tier and enforce multi-factor authentication for all users at no cost. The limitation is that security defaults are all or nothing, and with them enabled the authentication prompt is limited to the Microsoft Authenticator app including its text and voice options. What P1 buys is the ability to decide when it is required rather than applying one rule to everyone.

Can I mix P1 and P2 in the same tenant?

Yes, and it is common. Buy P2 for privileged accounts and for anyone in scope of a governance control, and keep everyone else on P1. Be aware that risk-based policies only cover the licensed users, so document which population is actually protected and review it when staff change.

Does P2 include lifecycle workflows and the full entitlement management features?

No. Microsoft lists lifecycle workflows, custom extensions using Logic Apps and machine-learning-assisted access certifications under Microsoft Entra ID Governance only. P2 carries Privileged Identity Management, access reviews and basic entitlement management. Entra ID Governance is sold as an add-on for P1 and P2 customers, so confirm which licence carries the specific feature you are buying.

Does P2 replace a security operations team?

No. It automates a specific set of responses to identity risk and produces evidence for access reviews. Somebody still has to define what risky means for your organisation, handle exceptions and act on what the reviews reveal. Buying P2 without assigning that ownership produces a licence cost and no improvement.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Microsoft 365 F1 vs F3: Licensing Frontline Staff Who Share Devices Review Counting Cores Correctly: Server Licence Minimums That Catch People Out Review Visio Plan 1 vs Plan 2: Web Diagrams or the Full Desktop Application? Review Running Office on a Terminal Server: Which Licences Are Even Allowed?
โ† Back to Knowledge Base