We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Entra
  2. Entra ID P1 or P2
Entra ID P1 or P2 for US businesses

There are two genuine reasons to buy P2. Nearly everything written about it describes a licensing model that has since changed.

What P2 genuinely adds is risk-based policy through ID Protection, and Privileged Identity Management. Access reviews and entitlement management have drifted toward needing Entra ID Governance instead, and a great deal of published advice has simply not caught up. We work this decision from the licensing documentation rather than from a comparison chart somebody made in 2023.

Book a licensing and capability reviewSee what actually changes
Microsoft Entra ID P1 versus P2 licensing decision for US organizations
  • P2 adds two thingsID Protection and PIM
  • Governance movedAccess reviews are not simply P2
  • Not everyonePIM licenses eligible admins only
  • Expiry differsPIM removes assignments, CA does not
What the license actually determines

Eight things worth establishing before anybody sends you a quote for an upgrade.

Every claim below comes from the licensing documentation itself rather than from anybody commentary on it. That matters more here than on almost any other subject, because several capabilities have moved between editions and an enormous amount of published advice describes an arrangement that stopped being true some time ago.

What you already own, which is nearly always more than you expect

P1 comes bundled with Microsoft 365 E3, E5 and E7, with the frontline plans, with Enterprise Mobility and Security E3, and with Business Premium. P2 comes with E5 and E7, with the Defender Suite that used to be called E5 Security, and with Enterprise Mobility and Security E5. A genuinely surprising number of American companies are already entitled to capabilities nobody has ever switched on.

The first genuine P2 addition: Identity Protection

Conditional access driven by risk, meaning policies that act on sign-in risk and user risk, needs ID Protection, and that is P2. This is the single capability most often assumed to be in P1, and it is not. If your security plan involves automatically blocking a risky sign-in, that plan requires P2 and no amount of configuration further down will conjure it up.

The second: Privileged Identity Management

Privileged Identity Management makes administrative access eligible rather than permanent, so a role is activated at the moment it is needed and expires afterward, with an approval step and a record of all of it. Using it and all its settings requires either Governance or P2. For any company with a meaningful number of administrators, this is usually the strongest single argument for the upgrade.

Access reviews and entitlement management have moved

This is the change almost nobody writing about the subject has absorbed. Running access reviews now calls for a Governance subscription covering your own staff, with the caveat that some capabilities might work on P2. Identical wording covers entitlement management. If P2 is being considered specifically to get access reviews, establish what you would genuinely receive rather than trusting an article written two years ago.

What P1 does give you of ID Protection, which is not quite nothing

A nuance worth knowing. At P1 the risky users list shows only medium and high accounts, with nothing behind the row and no history, and risky sign-ins arrive carrying neither a level nor a reason. Risk detections are similarly cut down. So P1 will tell you something is happening without telling you what it is. Whether that partial view is enough for you is a genuine question rather than a formality.

How many licenses you actually need, which is not everyone

For Privileged Identity Management you need licenses for anybody holding an eligible or time-limited role assignment, for the members and owners covered when it is applied to groups, for anybody able to approve or refuse an activation request, and for anybody assigned to or carrying out a review. The published worked example adds up to 42 eligible roles, 5 approvers and 6 reviewers, so 53 licenses in a company considerably larger than that. Access reviews work the other way around, needing licenses for the reviewers and for every person being reviewed.

What happens when the license lapses, which differs sharply

Conditional Access fails gently. Policies are neither disabled nor deleted, and you can look at them and remove them but not change them. Privileged Identity Management does not fail gently at all. Eligible role assignments are removed, reviews in flight simply end, and the configuration goes with them, though anything permanently assigned survives. That asymmetry belongs in every renewal conversation and it is raised in almost none of them.

The smaller items that decide edge cases

A custom role needs P1 for everybody holding it, while the built-in ones cost nothing. Administering an administrative unit needs P1, being a member of one does not. Directory synchronization is free while its health monitoring is not. Provisioning logs, health data, Graph activity logs and usage insights all sit at P1, though the audit and sign-in logs are free. Verified ID is included even at the free tier. None of these decides an upgrade on its own, and collectively they settle a close call surprisingly often.

Two things worth knowing before you decide

Whatever you have read about this may well describe a licensing model that no longer exists.

Capabilities have moved between editions, and the material circulating about P1 versus P2 has not kept pace with any consistency. These two points genuinely change decisions.

  • Access reviews and entitlement management are no longer simply P2 features. Running access reviews requires a Governance subscription for your own staff, with the qualification that some capabilities might work on P2. Entitlement management carries identical wording. Anybody upgrading specifically in order to run certification campaigns should pin down exactly what they will receive before committing, because the answer today is conditional rather than a straight yes.
  • What happens when the license lapses differs sharply between the two, and it belongs in every renewal conversation. Conditional Access policies survive: nothing is disabled or deleted, and you can read them and remove them though not edit them. Privileged Identity Management does not survive. Eligible role assignments disappear, reviews in progress end, and the configuration goes with them. A company that has built its whole administrative model on eligible access and then lets P2 lapse does not freeze that model, it loses it.
  • A third point, and this one saves money rather than costing it. Privileged Identity Management is licensed for the people it touches, not for the whole company. The published worked example runs to 42 administrators managed through it, 5 approvers and 6 reviewers, so 53 licenses in a business with a great many more staff than that. Access reviews invert this completely, needing licenses for both the reviewers and everybody being reviewed, which is why an access review program scales quite differently and needs its own arithmetic.
  • What follows from all that is that this is rarely a decision covering the whole company. For a great many American businesses the sensible answer is P1 across the board, with P2 or Governance for the small group who actually hold administrative access. We would far rather work that arithmetic through with you than quote for an upgrade covering everybody.
Ask us to work the license count against your actual admin population
How we advise on this

Four things that make this advice worth having.

Advice about licensing generally comes from somebody who stands to gain if you upgrade. Being a Microsoft partner, that applies to us as much as anyone, so the discipline that follows is worth writing down rather than leaving implied.

We check what you already own before recommending anything

A large proportion of the companies that ask us about P2 have never configured the P1 capabilities already sitting in their tenant, and a fair few of them already have P2 unused inside an E5 plan bought for something else entirely. Establishing that at the start regularly ends the conversation without anybody buying anything, which is the right outcome and one we would rather reach in the first week than the fourth.

We work from the licensing documentation, not from a comparison chart

Capabilities move between editions, and the access reviews change is a live example that a great deal of circulating advice has not absorbed. Every claim we make about what an edition contains traces back to the licensing documentation itself, and wherever the wording is conditional we reproduce the condition rather than flattening it into a convenient yes.

We scope P2 to the population that needs it

This is rarely a decision covering everybody. For most American businesses the right answer is P1 across the board with P2 or Governance for the small group holding administrative access, and the published worked examples support exactly that arithmetic. Upgrading everybody is far easier to quote for and usually wrong.

We tell you what happens if you stop paying

Conditional access policies survive a lapse, frozen but intact. Eligible role assignments are simply removed. That asymmetry matters enormously if your administrative model rests on eligible access, and it belongs in the original decision rather than surfacing during a renewal three years afterward. Nobody ever raises it, which is precisely why it should be raised.

Where the answer differs

Six US situations and what we would usually recommend.

In three of the six the recommendation is not to upgrade at all, which is roughly the real ratio once you establish what a company already owns.

A small business on Business Premium with nothing configured

P1 comes with Business Premium. The recommendation here is almost never P2. It is to configure conditional access properly, close off legacy authentication, switch on self-service password reset with writeback if you still have identities on your own servers, and use what is already being paid for every month. Upgrading before doing any of that simply buys more unused capability at a higher price.

A regulated firm with a real administrative population

Where an examiner expects controls over privileged access, as happens under the FTC Safeguards Rule and the New York DFS cybersecurity requirements, Privileged Identity Management is the strongest case for P2, because administrative access that is eligible rather than permanent, with an approval step and an audit trail, is almost word for word what those requirements describe. The licenses you need are the eligible administrators plus the approvers plus the reviewers, not the whole firm, which is usually what makes it affordable.

An organization already on E5 for other reasons

You hold P2 and there is a fair chance neither ID Protection nor Privileged Identity Management has ever been enabled. This is the most common waste we find in American Microsoft estates: capability paid for, never turned on, and then a separate security product bought to solve a problem the existing license already covered. What is needed here is configuration work, and it costs nothing further.

A business planning an access certification program

Check carefully before buying. Microsoft now states that access reviews require an Entra ID Governance subscription for member users, with some capabilities operating at P2. The license arithmetic is also unusual, since reviewers and reviewed users both need licenses. A program scoped as a P2 purchase may need re-costing, and it is much better to find that out now.

A company with a small IT team and no security operations

P2 gives you risk detection, and detection with nobody to act on it changes nothing. If there is no realistic responder for a risky sign-in alert at nine on a Friday evening, the honest recommendation is to spend on the controls that prevent rather than detect, meaning strong conditional access and device compliance at P1, and revisit P2 when there is somebody to receive the signal.

An organization weighing the Entra Suite

The Suite requires P1 or a package including P1, is available standalone or within Microsoft 365 E7, and bundles Private Access, Internet Access, ID Governance, ID Protection and Verified ID premium capabilities. If you want ID Governance for access reviews and also want to replace remote access infrastructure, the Suite arithmetic can beat buying the parts, and it is worth modeling rather than assuming either way.

Three positions

How US organizations actually sit on Entra licensing.

The middle column is both the most common and by far the most wasteful, because the company is already paying for capability nobody ever enabled. Upgrading from there simply buys more of the same.
Knows which editions its users hold
Licensed to fitYes
Entitled but unconfiguredRoughly
Upgraded without a reasonYes, after buying
Conditional access configured
Licensed to fitYes
Entitled but unconfiguredNo
Upgraded without a reasonSometimes
P2 scoped to the population that needs it
Licensed to fitYes
Entitled but unconfiguredNot applicable
Upgraded without a reasonBought for everyone
PIM in use with eligible access
Licensed to fitYes
Entitled but unconfiguredNo
Upgraded without a reasonRarely enabled
Risk policies actioned by somebody
Licensed to fitYes
Entitled but unconfiguredNot available
Upgraded without a reasonAlerts nobody reads
Access review expectations checked against Governance
Licensed to fitYes
Entitled but unconfiguredNot applicable
Upgraded without a reasonAssumed P2 covered it
Renewal implications understood
Licensed to fitYes
Entitled but unconfiguredNot applicable
Upgraded without a reasonNo
Spend matches capability actually used
Licensed to fitYes
Entitled but unconfiguredUnderused
Upgraded without a reasonOverspent
Would survive a licensing true-up comfortably
Licensed to fitYes
Entitled but unconfiguredYes
Upgraded without a reasonYes, expensively
Frequency in the US mid-market
Licensed to fitUncommon
Entitled but unconfiguredVery common
Upgraded without a reasonCommon
Feature
Licensed to fit
Entitled but unconfigured
Upgraded without a reason
Knows which editions its users hold
YesRoughlyYes, after buying
Conditional access configured
YesNoSometimes
P2 scoped to the population that needs it
YesNot applicableBought for everyone
PIM in use with eligible access
YesNoRarely enabled
Risk policies actioned by somebody
YesNot availableAlerts nobody reads
Access review expectations checked against Governance
YesNot applicableAssumed P2 covered it
Renewal implications understood
YesNot applicableNo
Spend matches capability actually used
YesUnderusedOverspent
Would survive a licensing true-up comfortably
YesYesYes, expensively
Frequency in the US mid-market
UncommonVery commonCommon
Feature by edition

What Free, P1 and P2 each give you.

Taken directly from the licensing documentation. Where a capability is described as limited rather than absent, that word is reproduced rather than tidied away, because the gap between limited and none is precisely what a decision turns on.

Capability

Conditional Access policies

Free
No
P1
Yes
P2
Yes

Capability

Risk-based Conditional Access

Free
No
P1
No
P2
Yes

Capability

Privileged Identity Management

Free
No
P1
No
P2
Yes, or ID Governance

Capability

Access reviews

Free
No
P1
No
P2
Some capabilities, ID Governance for the feature

Capability

Entitlement management

Free
No
P1
No
P2
Some capabilities, ID Governance for the feature

Capability

Risky users report

Free
Limited
P1
Limited, no details or history
P2
Full access

Capability

Risky sign-ins report

Free
Limited, no risk level
P1
Limited, no risk level
P2
Full access

Capability

Users at risk alerts and weekly digest

Free
No
P1
No
P2
Yes

Capability

Self-service password reset

Free
Yes
P1
Yes
P2
Yes

Capability

SSPR with on-premises writeback

Free
No
P1
Yes
P2
Yes

Capability

Custom RBAC roles

Free
No
P1
Yes, per user holding one
P2
Yes

Capability

Entra Connect Health

Free
No
P1
Yes
P2
Yes

Capability

Audit and sign-in logs

Free
Yes
P1
Yes
P2
Yes

Capability

Provisioning logs, Health, usage insights

Free
No
P1
Yes
P2
Yes

Capability

Verified ID core capability

Free
Yes
P1
Yes
P2
Yes
CapabilityFreeP1P2
Conditional Access policiesNoYesYes
Risk-based Conditional AccessNoNoYes
Privileged Identity ManagementNoNoYes, or ID Governance
Access reviewsNoNoSome capabilities, ID Governance for the feature
Entitlement managementNoNoSome capabilities, ID Governance for the feature
Risky users reportLimitedLimited, no details or historyFull access
Risky sign-ins reportLimited, no risk levelLimited, no risk levelFull access
Users at risk alerts and weekly digestNoNoYes
Self-service password resetYesYesYes
SSPR with on-premises writebackNoYesYes
Custom RBAC rolesNoYes, per user holding oneYes
Entra Connect HealthNoYesYes
Audit and sign-in logsYesYesYes
Provisioning logs, Health, usage insightsNoYesYes
Verified ID core capabilityYesYesYes
How we work the decision

Five steps, and it frequently ends at step two.

Typically a week or two of elapsed time, most of which is establishing what you already hold and whether it is configured. That is deliberately the cheapest question and it is asked first.
  1. 1

    Establish what your users are actually licensed for

    Which plans exist, how many of each, and whether some group somewhere already holds P2 through E5, E7, the top mobility bundle or a Defender Suite. This turns up entitlement nobody knew about with some regularity, and it is the unavoidable baseline for any comparison, because an upgrade cannot be evaluated against an unknown starting point.

  2. 2

    Check whether the P1 capabilities are configured

    Conditional access, closing off legacy authentication, self-service password reset with writeback, health monitoring on the sync, custom roles, provisioning logs. If none of that is configured, then that is the work, and you will hear that rather than being walked toward a P2 conversation. A company not using what it has will not suddenly use more of it.

  3. 3

    Test the P2 case honestly against two questions

    Would anybody act on a risk signal, and do you have enough administrators for eligible access to mean anything. If no one would respond to a risk alert, ID Protection buys you reporting rather than protection. If there are three administrators and all of them genuinely need access most days, Privileged Identity Management is pure overhead. Both of those are perfectly legitimate answers.

  4. 4

    Do the arithmetic on the population that needs it

    For Privileged Identity Management it is the eligible administrators, the approvers and the reviewers. For access reviews it is the reviewers plus everybody being reviewed, which scales in an entirely different direction, along with a check on whether Governance rather than P2 is what that feature now demands. The result is nearly always a smaller and far more defensible number than upgrading everybody.

  5. 5

    Decide, implement, and record why

    A written recommendation carrying the reasoning and the license counts, in a form somebody can hand to finance or pull out again at the next renewal. Where the answer turns out to be do not upgrade, that is the deliverable and there is no shame in it. Where it is upgrade, we configure what you buy, because a P2 license with both marquee features left switched off is precisely the waste this whole exercise exists to prevent.

Straight answers

What US organizations ask about Entra ID licensing.

Two capabilities, genuinely, and both are worth having. ID Protection, which makes conditional access respond to sign-in risk and user risk and brings the full reporting and alerting with it. And Privileged Identity Management, which turns permanent administrative access into eligible access with approval and an audit trail behind it. Everything else people associate with P2 is either already in P1 or has drifted toward requiring Governance, and that drift is the change most guidance has entirely missed.

Not simply, and this is the most important correction anywhere on this page. Running access reviews requires a Governance subscription covering your own staff, with the qualification that some capabilities within it might work on P2. Entitlement management carries identical wording. Plenty of published comparisons still list access reviews flatly as a P2 feature. If certification is your reason for upgrading, pin down exactly what you would receive before any budget is committed.

P1 arrives with Microsoft 365 E3, E5 and E7, with the frontline worker plans, with Enterprise Mobility and Security E3, and with Business Premium. P2 arrives with E5 and E7, with the Defender Suite that used to be called E5 Security, with its frontline variants and the combined Defender and Purview frontline bundle, and with Enterprise Mobility and Security E5. Check what your people genuinely hold before assuming anything needs buying.

Probably not, and you would hear that from us. Privileged Identity Management turns permanent administrative access into eligible access, activated when needed, approved, expiring and logged. That is genuinely valuable once a large administrative population is creating standing risk. With three administrators who all legitimately need access most working days, the overhead exceeds the benefit, and the effort is far better spent separating their administrative accounts from the ones they use for email, which costs nothing at all.

Fewer than most people assume, and it depends entirely on which feature you are buying. For Privileged Identity Management, licenses cover anybody holding an eligible or time-limited role assignment, the members and owners where it is applied to groups, anybody able to approve or refuse an activation, and anybody assigned to or running a review. The published example totals 53 for a company with 50 administrators, 42 of them managed this way, plus 5 approvers and 6 reviewers. Access reviews invert that entirely and need licenses for the reviewers and for every single person under review.

Considerably worse than letting conditional access lapse, and worth understanding before building anything on top of it. Conditional access policies are neither disabled nor deleted, and can be read and removed though not edited, so your posture freezes rather than falling over. Privileged Identity Management behaves quite differently: eligible role assignments are removed, reviews in progress end, and the configuration goes with them, though anything permanently assigned is untouched. An administrative model resting on eligible access therefore does not survive a lapse at all.

No, and the nuance is worth carrying. At P1 the risky users list covers only medium and high accounts with nothing behind the row and no history, risky sign-ins arrive with neither a level nor a reason, and risk detections are similarly cut down. So P1 tells you something happened without telling you what or how bad. For some companies that is a perfectly useful prompt to go and look manually. For others it is annoying enough on its own to justify the upgrade.

Usually only some. The features that justify it concentrate on a small group: the administrators who would hold eligible access, the people approving activations, and whoever does the reviewing. The exception is risk-based conditional access, which benefits from covering everybody because it protects ordinary staff, so the shape of the answer turns on which capability is driving the purchase in the first place. We would rather work that through against your real numbers than recommend an upgrade covering everyone, which is far easier to quote and usually wrong.

A bundle sitting on top of P1, either bought on its own or arriving inside Microsoft 365 E7. It contains five products: Private Access, Internet Access, ID Governance, ID Protection and the premium half of Verified ID. It becomes interesting the moment you want more than one of them, and particularly where you want Governance for access reviews and are simultaneously thinking about replacing remote access infrastructure, because the parts bought separately can easily exceed the bundle.

Almost certainly. In most tenants we open, conditional access is either absent or minimal, self-service password reset with writeback to the local directory has never been enabled, health monitoring on the sync was never configured, the provisioning logs and usage insights have not been opened once, and custom roles sit unused while everybody holds a broad built-in one instead. Every item on that list comes with P1 and costs nothing further to switch on. Working through it is a considerably better first project than a license upgrade.

It can, particularly on privileged access. The FTC Safeguards Rule and New York DFS cybersecurity requirements expect access to be limited and periodically reviewed, SOC 2 examinations sample privileged access controls, and CMMC and NIST 800-171 include least-privilege practices. PIM addresses several of those directly with evidence attached, and risk-based policies answer the account compromise questions on cyber insurance applications. That said, a well-configured P1 tenant meets more of these requirements than an unconfigured P2 one.

Increasingly it is the answer wherever access reviews, entitlement management or lifecycle workflows are the actual objective, since all three are now described as requiring a Governance subscription with only some capabilities working at P2. It also arrives inside the Entra Suite and inside Microsoft 365 E7. If what is driving you is governance rather than risk detection, the comparison you genuinely need is P1 plus Governance set against P2, not P1 set against P2, and framing it the conventional way produces the wrong answer.
Work the decision properly

Fifteen questions that settle P1 against P2.

The first block establishes what you already own. The second tests whether the P2 capabilities would genuinely get used. The third is the arithmetic, which almost always shows the upgrade to be smaller than anybody expected.

What you already have

  • Which Microsoft 365 or EMS plans do your users hold?
    E3 and Business Premium both include P1.
  • Does anyone already hold E5, E7 or EMS E5?
    Those include P2, and it may be unused.
  • Have you configured conditional access at all?
    If not, you have unused P1 before considering P2.
  • Are provisioning logs and usage insights being used?
    P1 capabilities most tenants never open.
  • Is Entra Connect Health configured?
    Needs P1, and costs nothing to switch on if you have it.

Would you use what P2 adds

  • Do you want risky sign-ins blocked automatically, not just reported?
    That is P2, via Identity Protection.
  • Is that cut-down P1 risk view genuinely not enough for you?
    P1 shows something is wrong without saying what.
  • Do you have enough administrators to justify eligible access?
    Privileged Identity Management pays for itself at scale, not with three administrators.
  • Would anybody actually action a risk alert?
    Detection with no responder changes nothing.
  • Are you buying P2 for access reviews specifically?
    Establish what you would actually receive. That capability has drifted toward Governance.

The arithmetic

  • How many administrators would be managed through PIM?
    License the eligible admins, not the organization.
  • How many approvers and reviewers would there be?
    They need licenses too, per Microsoft own example.
  • If access reviews are in scope, how many people would be under review?
    Those users need licenses, which changes the count sharply.
  • Could you license P2 for a subset rather than everyone?
    Usually yes, and usually the right answer.
  • What happens to your admin model if P2 lapses?
    Eligible role assignments are removed, not frozen.
Related reading

The pages around this one.

Entra Conditional Access

The P1 capability nearly everybody already owns and nobody has configured, including why these deployments fail on the exclusions rather than on the policies.

Learn more

Microsoft Entra

The identity platform as a whole and the practice around it, for context before narrowing down to a licensing decision.

Learn more

Entra ID Protection

The P2 capability itself: what the risk reports and policies actually do at each tier.

Learn more
Next step

Establish what your people already hold before comparing anything at all.

A meaningful share of the companies that ask us about P2 turn out to already hold it inside an E5 plan, or to have never configured the P1 capabilities they pay for monthly. Finding that out costs nothing, takes one conversation, and quite often ends the question without anybody buying anything.

Book a licensing and capability reviewExplore Microsoft Entra services

Related Services

Explore more solutions that work great with this service

Microsoft Entra ID Protection

Entra ID Protection deployment for US organizations: establishing

Learn more

Microsoft Entra ID Governance

Entra ID Governance implementation for US organizations: automating

Learn more

Microsoft Entra Conditional Access Design

Conditional Access design and review for US organizations:

Learn more

Microsoft Entra Privileged Identity Management

Privileged Identity Management deployment for US organizations:

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

Microsoft Security Services

The Microsoft security stack deployed and managed end to end

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA