There are two genuine reasons to buy P2. Nearly everything written about it describes a licensing model that has since changed.
What P2 genuinely adds is risk-based policy through ID Protection, and Privileged Identity Management. Access reviews and entitlement management have drifted toward needing Entra ID Governance instead, and a great deal of published advice has simply not caught up. We work this decision from the licensing documentation rather than from a comparison chart somebody made in 2023.

- P2 adds two thingsID Protection and PIM
- Governance movedAccess reviews are not simply P2
- Not everyonePIM licenses eligible admins only
- Expiry differsPIM removes assignments, CA does not
Eight things worth establishing before anybody sends you a quote for an upgrade.
What you already own, which is nearly always more than you expect
P1 comes bundled with Microsoft 365 E3, E5 and E7, with the frontline plans, with Enterprise Mobility and Security E3, and with Business Premium. P2 comes with E5 and E7, with the Defender Suite that used to be called E5 Security, and with Enterprise Mobility and Security E5. A genuinely surprising number of American companies are already entitled to capabilities nobody has ever switched on.
The first genuine P2 addition: Identity Protection
Conditional access driven by risk, meaning policies that act on sign-in risk and user risk, needs ID Protection, and that is P2. This is the single capability most often assumed to be in P1, and it is not. If your security plan involves automatically blocking a risky sign-in, that plan requires P2 and no amount of configuration further down will conjure it up.
The second: Privileged Identity Management
Privileged Identity Management makes administrative access eligible rather than permanent, so a role is activated at the moment it is needed and expires afterward, with an approval step and a record of all of it. Using it and all its settings requires either Governance or P2. For any company with a meaningful number of administrators, this is usually the strongest single argument for the upgrade.
Access reviews and entitlement management have moved
This is the change almost nobody writing about the subject has absorbed. Running access reviews now calls for a Governance subscription covering your own staff, with the caveat that some capabilities might work on P2. Identical wording covers entitlement management. If P2 is being considered specifically to get access reviews, establish what you would genuinely receive rather than trusting an article written two years ago.
What P1 does give you of ID Protection, which is not quite nothing
A nuance worth knowing. At P1 the risky users list shows only medium and high accounts, with nothing behind the row and no history, and risky sign-ins arrive carrying neither a level nor a reason. Risk detections are similarly cut down. So P1 will tell you something is happening without telling you what it is. Whether that partial view is enough for you is a genuine question rather than a formality.
How many licenses you actually need, which is not everyone
For Privileged Identity Management you need licenses for anybody holding an eligible or time-limited role assignment, for the members and owners covered when it is applied to groups, for anybody able to approve or refuse an activation request, and for anybody assigned to or carrying out a review. The published worked example adds up to 42 eligible roles, 5 approvers and 6 reviewers, so 53 licenses in a company considerably larger than that. Access reviews work the other way around, needing licenses for the reviewers and for every person being reviewed.
What happens when the license lapses, which differs sharply
Conditional Access fails gently. Policies are neither disabled nor deleted, and you can look at them and remove them but not change them. Privileged Identity Management does not fail gently at all. Eligible role assignments are removed, reviews in flight simply end, and the configuration goes with them, though anything permanently assigned survives. That asymmetry belongs in every renewal conversation and it is raised in almost none of them.
The smaller items that decide edge cases
A custom role needs P1 for everybody holding it, while the built-in ones cost nothing. Administering an administrative unit needs P1, being a member of one does not. Directory synchronization is free while its health monitoring is not. Provisioning logs, health data, Graph activity logs and usage insights all sit at P1, though the audit and sign-in logs are free. Verified ID is included even at the free tier. None of these decides an upgrade on its own, and collectively they settle a close call surprisingly often.
Whatever you have read about this may well describe a licensing model that no longer exists.
Capabilities have moved between editions, and the material circulating about P1 versus P2 has not kept pace with any consistency. These two points genuinely change decisions.
- Access reviews and entitlement management are no longer simply P2 features. Running access reviews requires a Governance subscription for your own staff, with the qualification that some capabilities might work on P2. Entitlement management carries identical wording. Anybody upgrading specifically in order to run certification campaigns should pin down exactly what they will receive before committing, because the answer today is conditional rather than a straight yes.
- What happens when the license lapses differs sharply between the two, and it belongs in every renewal conversation. Conditional Access policies survive: nothing is disabled or deleted, and you can read them and remove them though not edit them. Privileged Identity Management does not survive. Eligible role assignments disappear, reviews in progress end, and the configuration goes with them. A company that has built its whole administrative model on eligible access and then lets P2 lapse does not freeze that model, it loses it.
- A third point, and this one saves money rather than costing it. Privileged Identity Management is licensed for the people it touches, not for the whole company. The published worked example runs to 42 administrators managed through it, 5 approvers and 6 reviewers, so 53 licenses in a business with a great many more staff than that. Access reviews invert this completely, needing licenses for both the reviewers and everybody being reviewed, which is why an access review program scales quite differently and needs its own arithmetic.
- What follows from all that is that this is rarely a decision covering the whole company. For a great many American businesses the sensible answer is P1 across the board, with P2 or Governance for the small group who actually hold administrative access. We would far rather work that arithmetic through with you than quote for an upgrade covering everybody.
Four things that make this advice worth having.
We check what you already own before recommending anything
A large proportion of the companies that ask us about P2 have never configured the P1 capabilities already sitting in their tenant, and a fair few of them already have P2 unused inside an E5 plan bought for something else entirely. Establishing that at the start regularly ends the conversation without anybody buying anything, which is the right outcome and one we would rather reach in the first week than the fourth.
We work from the licensing documentation, not from a comparison chart
Capabilities move between editions, and the access reviews change is a live example that a great deal of circulating advice has not absorbed. Every claim we make about what an edition contains traces back to the licensing documentation itself, and wherever the wording is conditional we reproduce the condition rather than flattening it into a convenient yes.
We scope P2 to the population that needs it
This is rarely a decision covering everybody. For most American businesses the right answer is P1 across the board with P2 or Governance for the small group holding administrative access, and the published worked examples support exactly that arithmetic. Upgrading everybody is far easier to quote for and usually wrong.
We tell you what happens if you stop paying
Conditional access policies survive a lapse, frozen but intact. Eligible role assignments are simply removed. That asymmetry matters enormously if your administrative model rests on eligible access, and it belongs in the original decision rather than surfacing during a renewal three years afterward. Nobody ever raises it, which is precisely why it should be raised.
Six US situations and what we would usually recommend.
A small business on Business Premium with nothing configured
P1 comes with Business Premium. The recommendation here is almost never P2. It is to configure conditional access properly, close off legacy authentication, switch on self-service password reset with writeback if you still have identities on your own servers, and use what is already being paid for every month. Upgrading before doing any of that simply buys more unused capability at a higher price.
A regulated firm with a real administrative population
Where an examiner expects controls over privileged access, as happens under the FTC Safeguards Rule and the New York DFS cybersecurity requirements, Privileged Identity Management is the strongest case for P2, because administrative access that is eligible rather than permanent, with an approval step and an audit trail, is almost word for word what those requirements describe. The licenses you need are the eligible administrators plus the approvers plus the reviewers, not the whole firm, which is usually what makes it affordable.
An organization already on E5 for other reasons
You hold P2 and there is a fair chance neither ID Protection nor Privileged Identity Management has ever been enabled. This is the most common waste we find in American Microsoft estates: capability paid for, never turned on, and then a separate security product bought to solve a problem the existing license already covered. What is needed here is configuration work, and it costs nothing further.
A business planning an access certification program
Check carefully before buying. Microsoft now states that access reviews require an Entra ID Governance subscription for member users, with some capabilities operating at P2. The license arithmetic is also unusual, since reviewers and reviewed users both need licenses. A program scoped as a P2 purchase may need re-costing, and it is much better to find that out now.
A company with a small IT team and no security operations
P2 gives you risk detection, and detection with nobody to act on it changes nothing. If there is no realistic responder for a risky sign-in alert at nine on a Friday evening, the honest recommendation is to spend on the controls that prevent rather than detect, meaning strong conditional access and device compliance at P1, and revisit P2 when there is somebody to receive the signal.
An organization weighing the Entra Suite
The Suite requires P1 or a package including P1, is available standalone or within Microsoft 365 E7, and bundles Private Access, Internet Access, ID Governance, ID Protection and Verified ID premium capabilities. If you want ID Governance for access reviews and also want to replace remote access infrastructure, the Suite arithmetic can beat buying the parts, and it is worth modeling rather than assuming either way.
How US organizations actually sit on Entra licensing.
| Feature | Licensed to fit | Entitled but unconfigured | Upgraded without a reason |
|---|---|---|---|
Knows which editions its users hold | Yes | Roughly | Yes, after buying |
Conditional access configured | Yes | No | Sometimes |
P2 scoped to the population that needs it | Yes | Not applicable | Bought for everyone |
PIM in use with eligible access | Yes | No | Rarely enabled |
Risk policies actioned by somebody | Yes | Not available | Alerts nobody reads |
Access review expectations checked against Governance | Yes | Not applicable | Assumed P2 covered it |
Renewal implications understood | Yes | Not applicable | No |
Spend matches capability actually used | Yes | Underused | Overspent |
Would survive a licensing true-up comfortably | Yes | Yes | Yes, expensively |
Frequency in the US mid-market | Uncommon | Very common | Common |
What Free, P1 and P2 each give you.
Capability
Conditional Access policies
- Free
- No
- P1
- Yes
- P2
- Yes
Capability
Risk-based Conditional Access
- Free
- No
- P1
- No
- P2
- Yes
Capability
Privileged Identity Management
- Free
- No
- P1
- No
- P2
- Yes, or ID Governance
Capability
Access reviews
- Free
- No
- P1
- No
- P2
- Some capabilities, ID Governance for the feature
Capability
Entitlement management
- Free
- No
- P1
- No
- P2
- Some capabilities, ID Governance for the feature
Capability
Risky users report
- Free
- Limited
- P1
- Limited, no details or history
- P2
- Full access
Capability
Risky sign-ins report
- Free
- Limited, no risk level
- P1
- Limited, no risk level
- P2
- Full access
Capability
Users at risk alerts and weekly digest
- Free
- No
- P1
- No
- P2
- Yes
Capability
Self-service password reset
- Free
- Yes
- P1
- Yes
- P2
- Yes
Capability
SSPR with on-premises writeback
- Free
- No
- P1
- Yes
- P2
- Yes
Capability
Custom RBAC roles
- Free
- No
- P1
- Yes, per user holding one
- P2
- Yes
Capability
Entra Connect Health
- Free
- No
- P1
- Yes
- P2
- Yes
Capability
Audit and sign-in logs
- Free
- Yes
- P1
- Yes
- P2
- Yes
Capability
Provisioning logs, Health, usage insights
- Free
- No
- P1
- Yes
- P2
- Yes
Capability
Verified ID core capability
- Free
- Yes
- P1
- Yes
- P2
- Yes
Five steps, and it frequently ends at step two.
- 1
Establish what your users are actually licensed for
Which plans exist, how many of each, and whether some group somewhere already holds P2 through E5, E7, the top mobility bundle or a Defender Suite. This turns up entitlement nobody knew about with some regularity, and it is the unavoidable baseline for any comparison, because an upgrade cannot be evaluated against an unknown starting point.
- 2
Check whether the P1 capabilities are configured
Conditional access, closing off legacy authentication, self-service password reset with writeback, health monitoring on the sync, custom roles, provisioning logs. If none of that is configured, then that is the work, and you will hear that rather than being walked toward a P2 conversation. A company not using what it has will not suddenly use more of it.
- 3
Test the P2 case honestly against two questions
Would anybody act on a risk signal, and do you have enough administrators for eligible access to mean anything. If no one would respond to a risk alert, ID Protection buys you reporting rather than protection. If there are three administrators and all of them genuinely need access most days, Privileged Identity Management is pure overhead. Both of those are perfectly legitimate answers.
- 4
Do the arithmetic on the population that needs it
For Privileged Identity Management it is the eligible administrators, the approvers and the reviewers. For access reviews it is the reviewers plus everybody being reviewed, which scales in an entirely different direction, along with a check on whether Governance rather than P2 is what that feature now demands. The result is nearly always a smaller and far more defensible number than upgrading everybody.
- 5
Decide, implement, and record why
A written recommendation carrying the reasoning and the license counts, in a form somebody can hand to finance or pull out again at the next renewal. Where the answer turns out to be do not upgrade, that is the deliverable and there is no shame in it. Where it is upgrade, we configure what you buy, because a P2 license with both marquee features left switched off is precisely the waste this whole exercise exists to prevent.
What US organizations ask about Entra ID licensing.
Fifteen questions that settle P1 against P2.
What you already have
- Which Microsoft 365 or EMS plans do your users hold?E3 and Business Premium both include P1.
- Does anyone already hold E5, E7 or EMS E5?Those include P2, and it may be unused.
- Have you configured conditional access at all?If not, you have unused P1 before considering P2.
- Are provisioning logs and usage insights being used?P1 capabilities most tenants never open.
- Is Entra Connect Health configured?Needs P1, and costs nothing to switch on if you have it.
Would you use what P2 adds
- Do you want risky sign-ins blocked automatically, not just reported?That is P2, via Identity Protection.
- Is that cut-down P1 risk view genuinely not enough for you?P1 shows something is wrong without saying what.
- Do you have enough administrators to justify eligible access?Privileged Identity Management pays for itself at scale, not with three administrators.
- Would anybody actually action a risk alert?Detection with no responder changes nothing.
- Are you buying P2 for access reviews specifically?Establish what you would actually receive. That capability has drifted toward Governance.
The arithmetic
- How many administrators would be managed through PIM?License the eligible admins, not the organization.
- How many approvers and reviewers would there be?They need licenses too, per Microsoft own example.
- If access reviews are in scope, how many people would be under review?Those users need licenses, which changes the count sharply.
- Could you license P2 for a subset rather than everyone?Usually yes, and usually the right answer.
- What happens to your admin model if P2 lapses?Eligible role assignments are removed, not frozen.
The pages around this one.
Entra Conditional Access
The P1 capability nearly everybody already owns and nobody has configured, including why these deployments fail on the exclusions rather than on the policies.
Microsoft Entra
The identity platform as a whole and the practice around it, for context before narrowing down to a licensing decision.
Entra ID Protection
The P2 capability itself: what the risk reports and policies actually do at each tier.
Establish what your people already hold before comparing anything at all.
A meaningful share of the companies that ask us about P2 turn out to already hold it inside an E5 plan, or to have never configured the P1 capabilities they pay for monthly. Finding that out costs nothing, takes one conversation, and quite often ends the question without anybody buying anything.
Related Services
Explore more solutions that work great with this service
Microsoft Entra ID Protection
Entra ID Protection deployment for US organizations: establishing
Learn moreMicrosoft Entra ID Governance
Entra ID Governance implementation for US organizations: automating
Learn moreMicrosoft Entra Conditional Access Design
Conditional Access design and review for US organizations:
Learn moreMicrosoft Entra Privileged Identity Management
Privileged Identity Management deployment for US organizations:
Learn moreMicrosoft Entra
Identity and access management solutions
Learn moreMicrosoft Security Services
The Microsoft security stack deployed and managed end to end
Learn more