Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Microsoft Entra ID P1 Review: Conditional Access Is the Whole Point

9 min read Updated October 5, 2026 Microsoft Product Reviews

Fix it now

Entra ID P1 contains a long list of features and one reason to buy it. Conditional Access decides who may sign in, from what device, under which conditions, and it is what separates a tenant with multifactor authentication switched on from a tenant that is actually defended. Everything else in P1 is worth having and changes nothing this week.

  1. Buy it the moment you need an exception to a blanket rule: a service account, a location, an application, a group of contractors. Security defaults cannot express one.
  2. Buy it if you want to require a compliant or Microsoft Entra hybrid joined device before company data is reachable, which is the control that makes Intune worth deploying.
  3. Buy it if password resets consume helpdesk time, because self-service reset with write-back to on-premises Active Directory removes most of it.
  4. Skip it if you are a handful of people with no service accounts, no on-premises directory and no exceptions. Security defaults are available to all customers and are an honest position at that size.
  5. Skip buying it separately until you have checked what you already hold. Microsoft 365 E3, E5, E7, F1, F3, Enterprise Mobility + Security E3 and Microsoft 365 Business Premium all include it.
  6. Licence everyone a policy applies to, not just the administrators who write the policies. If you target all users, you licence all users.

Risk-based Conditional Access, which reacts to sign-in and user risk scores, needs Microsoft Entra ID Protection and therefore P2. Ordinary Conditional Access does not.

If that settles it you can stop here. If you want the conditions and controls listed, and a rollout order that avoids a Monday morning outage, read on.

Why it happens

A Conditional Access policy is a sentence: for these users, reaching these applications, under these conditions, require this. The signals available include the user or group, IP location, the device, the application, real-time and calculated risk detection, and Microsoft Defender for Cloud Apps. The controls include blocking outright, requiring multifactor authentication, requiring a particular authentication strength, requiring a device marked compliant, requiring a Microsoft Entra hybrid joined device, requiring an approved client application, requiring an app protection policy, requiring a password change, and requiring terms of use. Two of those, authentication strength and terms of use, are regularly missed by people who last read about this a few years ago.

Two policies matter more than the rest combined. The first requires multifactor authentication for all users, with break-glass administrator accounts excluded and monitored. The second blocks legacy authentication protocols, which cannot present a second factor and are therefore the route password-spray attacks take. Build both in report-only mode, read the sign-in logs for a week to find the service accounts and appliances that will break, then enforce. That sequence is what separates a smooth rollout from a morning of locked-out staff.

What the free tier gives you is better than most small tenants realise, and it is the right comparison to make first. Security defaults are available to all customers. They require every user to register for multifactor authentication and to use it, they protect privileged actions, and they block legacy authentication. For a small organisation with no service accounts and no unusual applications, that is a defensible position, and buying P1 to reproduce it would be waste.

The limitation is that security defaults are all or nothing. There are no exclusions, no per-application rules, no location awareness and no device requirements. The moment you need one exception, or want to require a managed device rather than merely a second factor, you have to turn security defaults off, and Conditional Access is what replaces them. That is the actual purchase decision, and it usually arrives with the first scanner, service account or line-of-business application that cannot do modern authentication.

The rest of P1 is useful housekeeping rather than a reason to buy. Self-service password reset with write-back to on-premises Active Directory is the fastest measurable helpdesk saving in the licence. Dynamic groups follow attributes such as department or job title, so joiners and leavers change access without a ticket. Group-based licensing assigns subscriptions by membership rather than one user at a time. Microsoft Entra Application Proxy publishes an internal web application to remote staff without exposing it or extending a VPN. Cloud Sync and Connect Health cover hybrid directories.

On licensing, the rule that catches people is that a licence is required for every user who benefits from a feature, not merely for the administrators who configure it. If a Conditional Access policy targets all users, all users need P1. Guests and external identities follow separate billing rules, so if partners sign in to your tenant, ask about those specifically rather than assuming they are covered or assuming they are not.

Full reference

Conditions and controls, in full

Signals you can test Controls you can require
User, group or agent Block access
IP location information and named locations Require multifactor authentication
Device state, including compliance and hybrid join Require a specific authentication strength
Application being reached Require the device to be marked compliant
Client application in use Require a Microsoft Entra hybrid joined device
Real-time and calculated risk detection (needs P2) Require an approved client application
Microsoft Defender for Cloud Apps signals Require an app protection policy
Require a password change
Require terms of use

Where P1 sits between free and P2

Capability Free tier Entra ID P1 Entra ID P2
Multifactor authentication Through security defaults, no exceptions Through Conditional Access, fully targeted Same, plus risk-based
Conditional Access policies No Yes Yes
Self-service password reset with write-back Cloud accounts only Yes Yes
Dynamic groups and group-based licensing No Yes Yes
Application Proxy No Yes Yes
Identity Protection and risk-based Conditional Access No No Yes
Privileged Identity Management No No Yes

Who already owns it

  • Microsoft 365 E3, E5 and E7.
  • Microsoft 365 F1 and F3.
  • Enterprise Mobility + Security E3.
  • Microsoft 365 Business Premium, which Microsoft names explicitly as carrying Conditional Access.
  • Check before you buy. A large share of the firms asking about Conditional Access already hold the licence for it.

A rollout order that does not lock anyone out

  1. Create at least two break-glass administrator accounts, exclude them from every Conditional Access policy, store the credentials properly and monitor their sign-ins.
  2. Build the multifactor authentication policy and the legacy authentication block in report-only mode.
  3. Read a week of sign-in logs and list every service account, appliance and application that would have been blocked.
  4. Fix or replace those rather than planning permanent exclusions, because a permanent exclusion reopens the hole you were closing.
  5. Turn security defaults off and enforce the two policies together, since leaving both on is not a supported arrangement.
  6. Add device compliance requirements afterwards, once Intune enrolment is real rather than aspirational.

Always keep at least one break-glass administrator account excluded from every Conditional Access policy, with a long stored password and no multifactor requirement that could itself fail. Tenants have locked out their entire administrator population by enforcing a policy against a factor nobody had yet registered.

Mistakes that cost money rather than security

  • Buying P1 standalone when Business Premium or E3 already includes it, which happens often enough to be worth a five-minute check.
  • Licensing only the administrators. The rule is that every user a policy applies to needs a licence.
  • Leaving security defaults on and building Conditional Access policies alongside them, then wondering why behaviour is inconsistent.
  • Assuming risk-based policies are included. They need Identity Protection, which is P2.
  • Forgetting guests. External identities follow their own billing rules and deserve a specific question rather than an assumption.

When a licence is the actual fix

Microsoft Entra ID P1 is the correct purchase the moment blanket security defaults stop fitting, and that point arrives for almost every organisation with more than a handful of staff. It is what lets you require multifactor authentication with the exceptions your business genuinely needs, insist on a managed device before company data is reachable, and block the legacy protocols attackers rely on. Before buying it standalone, check what you hold: Microsoft 365 E3, E5, E7, F1, F3, Enterprise Mobility + Security E3 and Microsoft 365 Business Premium all include it. Arco can compare the standalone subscription against those bundles on your seat count and tell you which way round is cheaper, and will say plainly when the answer is that you already own it and simply have not switched it on.

Questions people ask about this

Do all users need a licence, or only administrators?

Every user a Conditional Access policy applies to must be licensed, not just the people who write the policies. If you target all users, you licence all users. Guests and external identities follow separate rules, so ask about those specifically if partners sign in to your tenant.

Is P1 enough, or should we go straight to P2?

P1 is enough for most organisations. P2 earns its place when you have standing privileged accounts to control or want sign-ins with leaked credentials handled automatically. Note that access reviews and entitlement management, which used to be presented as P2 features, now require a Microsoft Entra ID Governance subscription for member users, so check what you are actually buying.

Will Conditional Access break our old applications?

Blocking legacy authentication will break anything that cannot use modern protocols, which is the point of it. Find them first with report-only mode and the sign-in logs, then fix or replace them. Excluding them permanently reopens the hole you were closing, and the exclusion always outlives the person who added it.

Can we start without paying anything?

Yes. Security defaults are available to all customers, and they require multifactor registration and use, protect privileged actions and block legacy authentication. They are a real improvement over nothing and the correct first step while you work out whether you need the flexibility P1 buys.

What is the single most valuable thing in the licence besides Conditional Access?

Self-service password reset with write-back to on-premises Active Directory, if you run a hybrid directory. It is the one feature whose benefit shows up in a helpdesk ticket count within a month, and it is easy to deploy without breaking anything.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review SQL Server 2025 Developer Edition Review: Free, Full-Featured, Limited Review Planner Plan 1 Review: The Renamed Project Plan 1, for Team Members Review SQL Server 2025 CAL Review: When Server Plus CAL Beats Core Licensing Review Windows Server 2025 Standard Review: Core Licensing and Two-VM Limits
โ† Back to Knowledge Base