Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Microsoft Entra ID P2 Review: Risk-Based Identity Protection Assessed

10 min read Updated October 5, 2026 Microsoft Product Reviews

Fix it now

P2 now adds three things to P1 that are unambiguously P2: risk detection that reacts to suspicious sign-ins without waiting for you, risk-based Conditional Access, and just-in-time elevation so nobody holds administrative rights at rest. Access reviews and entitlement management, which older reviews sell as P2 features, now need a Microsoft Entra ID Governance subscription for member users.

  1. Buy it if administrative roles are assigned permanently to more people than you can name from memory. Privileged Identity Management is the strongest single argument for the licence.
  2. Buy it if you want sign-ins with leaked credentials or impossible travel handled automatically at three in the morning rather than after somebody notices.
  3. Buy it if an auditor, insurer or customer requires evidence that privilege is controlled rather than merely documented.
  4. Do not buy it for access reviews or entitlement management without checking first. Microsoft states those require a Microsoft Entra ID Governance subscription for member users, with only some capabilities operating on P2.
  5. Skip it if you have two administrators, no guests and no audit requirement. P1 plus disciplined habits covers you.
  6. Check the bundle before the add-on. P2 is included with Microsoft 365 E5 and E7, with Enterprise Mobility + Security E5, and with the security add-on Microsoft documentation now also calls the Microsoft Defender Suite.

Microsoft 365 E7 includes the Microsoft Entra Suite, which carries ID Governance along with Private Access, Internet Access, ID Protection and Verified ID premium capabilities. If governance is what you are after, that comparison is worth doing before buying P2 plus Governance separately.

If that settles it you can stop here. If you want the governance split explained properly and a cheaper first step, keep reading.

Why it happens

Start with what P2 unambiguously is, because the answer has narrowed. Microsoft Entra ID Protection scores two things. User risk is the probability that an identity itself is compromised, driven mainly by credentials appearing in breach data or by threat intelligence about the account. Sign-in risk is the probability that a particular sign-in is not the legitimate user, drawn from signals such as anonymised network addresses, unfamiliar properties for that person, addresses associated with malware, and travel between locations too quickly to be physical.

The value is not the reports. It is that Conditional Access can consume those scores as conditions, so a policy can force a password change when user risk is high and demand a fresh multifactor challenge when sign-in risk is medium or above. That reaction happens at the moment of the sign-in, without anyone on duty. Nothing in P1 does this, and no amount of manual review substitutes for it. Risk-based Conditional Access is explicitly a P2 capability because it depends on Identity Protection.

Privileged Identity Management is the second pillar and, for most organisations, the better argument. In most tenants privileged access is permanent because it was easier that way: somebody needed to be Global Administrator once and remains one. PIM changes assignments from active to eligible. The person can become an administrator but is not one until they activate the role, and the activation is time-boxed, can require justification, approval and a fresh multifactor challenge, and is logged. When the window expires the rights go away without anybody remembering to remove them. It covers directory roles and Azure resource roles alike.

Now the part that has changed, and it is the reason to reread your licensing before renewing. Access reviews and entitlement management used to be the third pillar of the P2 argument. Microsoft’s current licensing guidance states that using those features requires a Microsoft Entra ID Governance subscription for your organisation’s member users, and that only some capabilities within them might operate with a P2 subscription. Privileged Identity Management is documented as needing either Entra ID Governance licences or Entra ID P2. If your business case for P2 rested on quarterly guest reviews and access packages, that case now points at a different product.

Microsoft Entra ID Governance is sold standalone or included in Microsoft 365 E7, and it requires P1 or a package containing P1 underneath it. It adds the advanced end of the governance set: lifecycle workflows, machine-learning assisted access reviews, entitlement management with custom extensions, and Privileged Identity Management for Groups. The Microsoft Entra Suite bundles it with Private Access, Internet Access, ID Protection and Verified ID premium capabilities, and is itself included in E7. That is four different ways to end up holding the same capability, and the only way to choose sensibly is to write down which specific features you need before anyone quotes anything.

The honest summary is that P2 is a smaller product than it used to be described as, and still a worthwhile one. Buy it for automated reaction to risky sign-ins and for removing standing administrative access. Those two things fix real problems that no amount of policy writing addresses. Buy it as a general upgrade and you will acquire dashboards nobody opens, and then discover that the governance features you actually wanted need a further purchase.

Full reference

What sits where, after the governance split

Capability Entra ID P1 Entra ID P2 Microsoft Entra ID Governance
Conditional Access Yes Yes Requires P1 underneath
Risk-based Conditional Access No Yes Requires P1 underneath
Identity Protection risk detections No Yes Included in the Entra Suite
Privileged Identity Management No Yes Yes, either licence works
Access reviews No Some capabilities Required for member users
Entitlement management with access packages No Some capabilities Required for member users
Lifecycle workflows and PIM for Groups No No Yes

Where each licence comes from

  • Entra ID P2 is included with Microsoft 365 E5 and E7, with Enterprise Mobility + Security E5, and with the add-on Microsoft documentation now names Microsoft Defender Suite, formerly Microsoft 365 E5 Security. It is also sold standalone and as a Microsoft 365 Business Premium add-on.
  • Microsoft Entra ID Governance is sold standalone or included in Microsoft 365 E7, and requires a P1 subscription or a package containing P1.
  • The Microsoft Entra Suite contains Private Access, Internet Access, ID Governance, ID Protection and Verified ID premium capabilities, and is sold standalone or included in Microsoft 365 E7.
  • Microsoft 365 E7 became generally available on 1 May 2026 and is a strict superset of E5, adding Copilot, the Entra Suite and Agent 365.

Building risk policies without locking people out

  1. Start with a single policy requiring multifactor authentication at high sign-in risk only.
  2. Watch what it catches for a few weeks and read the Identity Protection reports before widening anything.
  3. Add a user-risk policy requiring a secure password change, again at high risk first.
  4. Widen to medium risk only when you can predict what the policy will do on an ordinary Tuesday.
  5. Keep break-glass accounts excluded and monitored throughout, as with any Conditional Access work.
  6. Resist setting every threshold to its most aggressive value on day one. That produces lockouts, and lockouts produce exceptions that never get removed.

Getting value from Privileged Identity Management

  1. List every permanent role assignment in the tenant and put a name against each one.
  2. Remove the assignments nobody can justify. That step alone is worth the exercise and costs nothing.
  3. Convert the rest from active to eligible, starting with Global Administrator.
  4. Set activation windows, and require justification and a fresh multifactor challenge on the roles that matter.
  5. Turn on the alerts for too many permanent administrators and for roles activated unusually often.
  6. Review the activation log monthly. If nobody reads it, the control is theatre.

Who genuinely needs P2

  • Organisations with more than a handful of privileged accounts, particularly where partners or contractors hold them.
  • Anyone who has already had a business email compromise incident and wants automated reaction to risky sign-ins.
  • Tenants that are a high-value target because of what they hold rather than because of their size.
  • Organisations under an audit or certification regime that asks how privilege is granted and removed, though check whether the evidence they want lives in Governance rather than P2.
  • Not an organisation with two administrators, no guest population and no audit requirement. Spend the money on P1 policies done properly and revisit when you have grown.

The cheapest step towards the same outcome

Remove permanent Global Administrator assignments you cannot justify. Create dedicated administrative accounts separate from daily-use ones. Run a manual guest review each quarter and actually delete what nobody claims. None of that requires a licence, and doing it first tells you whether you need the automation, which is a better basis for the purchase than a feature list.

When a licence is the actual fix

Microsoft Entra ID P2 is the right purchase when you can name the problem it solves: standing administrative access you cannot justify, or risky sign-ins that nobody is awake to notice. Bought for those reasons it is excellent value, because Privileged Identity Management removes a category of risk no amount of policy writing addresses. Bought as a general upgrade it becomes dashboards nobody opens. Check the scope carefully first, because access reviews and entitlement management now require a Microsoft Entra ID Governance subscription for member users rather than coming with P2. Arco can supply Entra ID P2 standalone and will compare it against Microsoft 365 E5, the security add-on Microsoft now also calls the Defender Suite, Microsoft Entra ID Governance, and Microsoft 365 E7, which bundles the Entra Suite outright. Where the honest answer is that P1 plus a quarterly manual review covers you, we will say so.

Questions people ask about this

Do access reviews and entitlement management still come with P2?

Not in the way older articles describe. Microsoft’s current licensing guidance states that using those features requires a Microsoft Entra ID Governance subscription for your organisation’s member users, and that only some capabilities within them might operate with a P2 subscription. Microsoft does not enumerate which ones, so confirm against the specific reviews you intend to run before you buy.

Do we need P2 for every user?

Licence the users who benefit from the features you deploy. If Privileged Identity Management covers only your administrators, those administrators need the licence. Risk policies applied to everyone do mean everyone needs it, so the scope of your policies decides the cost more than the headcount does.

Can we mix P1 and P2 in one tenant?

Yes, and it is common. Administrators and high-risk roles on P2, general staff on P1. Make sure the scope of each policy matches who is licensed for the features it uses, because a risk-based policy targeting all users pulls everyone into the P2 requirement.

Does P2 replace a dedicated privileged access management product?

For Microsoft cloud roles and Azure resources, largely yes. For on-premises systems, network devices and third-party applications it does not, so an organisation with a large non-Microsoft estate may still need a dedicated tool alongside it.

We are comparing E5 and E7. Where does identity fit?

E5 carries Entra ID P2. E7, generally available since 1 May 2026, carries the full Microsoft Entra Suite, which includes ID Governance, ID Protection, Private Access, Internet Access and Verified ID premium capabilities. If your requirement includes access reviews or entitlement management at scale, that is the comparison that matters rather than P2 against P1.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Microsoft 365 Family Review: Six People, One Bill, Any Real Catch? Review Visio LTSC Professional 2024 Review: Perpetual Diagramming Still Works Review Office Home & Business 2024 Review: Outlook Is the Whole Argument Review Windows 11 Pro for Workstations Review: Who Needs ReFS and SMB Direct?
โ† Back to Knowledge Base