Knowledge for better technology decisions
Knowledge BaseMicrosoft licensing

MICROSOFT LICENSING · MODULE 3 · ENTRA ID

Microsoft Entra ID: Free, P1, P2, or Entra Suite
Which licence do you actually need?

Microsoft Entra ID protects sign-ins and manages identities. This guide clearly explains when Free is enough, when P1 or P2 is required, and why governance, guests, and application identities follow different rules.

The feature, identity, and scope decide—not the tenant alone.

One Premium licence may make settings technically visible, but it does not automatically license every user. Define the required capability first, then the affected people or identities, and only then calculate the correct licence quantity.

  1. 01Free provides the identity foundation and Security Defaults.
  2. 02Conditional Access requires at least Entra ID P1.
  3. 03Risk-based policies require P2; PIM works with P2 or ID Governance.
  4. 04Employees, guests, and application identities use different billing rules.

Three terms for secure access

Entra ID decides who signs in and under which conditions an application may be used.

Conditional Access

If-then rules for sign-ins—for example, requiring MFA when someone connects from an unfamiliar location.

PIM

A process that activates powerful administrator rights only when needed and for a limited time.

Identity Governance

Rules and workflows that grant access, review it regularly, and remove it again.

A practical example: An administrator needs a highly privileged role only for one change. With PIM, she activates it for one hour, completes MFA, and automatically loses the extra right afterwards.

01

What is Microsoft Entra ID?

Microsoft Entra ID was previously called Azure Active Directory. In simple terms, it is the digital sign-in and access control for Microsoft 365, Azure, and many other applications.

IDENTITY

Who is signing in?

Entra ID manages users, groups, guests, applications, and other digital identities.

ACCESS

What may they access?

Sign-in rules determine which applications and resources an identity can reach.

PROTECTION

Under which conditions?

MFA, device, location, risk, and other signals can allow, limit, or block access.

IMPORTANT

Visible does not mean licensed

An administrator seeing or enabling a feature in the portal does not prove that the organisation owns sufficient rights.

02

Free, P1, P2, Governance, and Suite at a glance

Some levels build on each other. Identity Governance and the Entra Suite are separate products with prerequisites—not merely new names for P2.

ProductTypical purposeImportant examples
Entra ID FreeIdentity foundationUsers and groups, SSO, basic reports, Security Defaults, and basic MFA
Entra ID P1Targeted access controlConditional Access, dynamic groups, App Proxy, and advanced identity management
Entra ID P2Risk protection and privileged accessIdentity Protection, risk-based policies, and Privileged Identity Management (PIM)
Entra ID GovernanceLifecycle and access decisionsAccess Reviews, Lifecycle Workflows, access packages, and further governance capabilities
Microsoft Entra SuiteIdentity and network access togetherP2 identity protection, ID Governance, Private Access, Internet Access, and Verified ID Premium
No comparison table replaces a feature-level check.

Individual capabilities can have different prerequisites or scopes. Current Microsoft documentation, Product Terms, the exact SKU, and contract conditions remain decisive.

03

Check the existing Microsoft 365 plan before buying more

Many organisations already own P1 or P2 through a suite. Buying the same standalone entitlement again would often mean paying twice.

P1 INCLUDED

Microsoft 365 E3 and Business Premium

Microsoft lists Entra ID P1 as included in Microsoft 365 E3 and Microsoft 365 Business Premium. Other eligible bundles can include it too.

P2 INCLUDED

Microsoft 365 E5

Microsoft 365 E5 includes Entra ID P2. That does not automatically mean every new governance capability is also part of P2.

SUITE INCLUDED

Microsoft 365 E7

Microsoft lists the Entra Suite as included in Microsoft 365 E7. Availability, contract, and actual service plans still need checking.

SPECIAL CASES

Frontline, education, government, and step-ups

F plans, education, government, and existing P2 rights have dedicated variants and step-up products. The exact orderable SKU matters.

Check the service plan—not only the marketing name.

Billing > Licences in the Entra or Microsoft 365 admin centre shows which products and service plans are actually present in the tenant.

04

Security Defaults, Conditional Access, and risk-based policies are different

All three protect sign-ins, but their control and licensing differ significantly.

FREE

Security Defaults

A free security baseline with predefined protections. It is deliberately simple and less granular than Conditional Access.

P1

Conditional Access

If-then policies based on user, group, app, location, device, or other signals. Every user to whom a Premium policy applies or who benefits from it needs the relevant entitlement.

P2

Risk-based access

Sign-in Risk and User Risk from Identity Protection can trigger controls. Risk-based Conditional Access requires P2 or a suite containing that right.

One P1 licence for the administrator is not enough.

If a Conditional Access policy protects 500 users, all 500 affected users need P1 or a higher included entitlement—not only the person who created the policy.

05

Identity Protection and PIM solve two different problems

Identity Protection evaluates risk. PIM limits highly privileged administrator rights in time. Both support security, but they are not licensed identically.

IDENTITY PROTECTION

Is the sign-in or user risky?

Full risk details, alerts, and risk-based policies require Entra ID P2 or Entra Suite.

PIM

Must an admin role remain permanently active?

PIM activates roles for a limited period and can require MFA, justification, or approval. PIM is available with P2 or Entra ID Governance.

PIM SCOPE

Who needs a licence?

The count includes eligible or time-bound role holders, approvers, and people performing or undergoing access reviews in the PIM context.

A PIM licence expiry has security consequences.

Microsoft explains that eligible assignments and ongoing reviews can be removed or stopped. Treat expiry as a planned security change, not a routine purchasing event.

06

Governance follows the feature scope—not merely technical assignment

Identity Governance controls who receives access, reviews it regularly, and removes it automatically when appropriate.

ExampleLicences requiredWhy?
Access Review for 500 members, reviewed by 3 group owners503 member usersReviewed people and reviewers are in the governance scope.
An access package can be requested by all 2,000 employees2,000 member usersWho can request it matters—not only who has already requested it.
PIM for 14 administrators plus 3 approvers17 usersRole holders and approvers need a valid P2 or Governance entitlement.
Governance for B2B guestsMAU billingGuests use Monthly Active Users and a linked Azure subscription.
A Governance licence does not always need to be technically assigned to each user.

The organisation must still own enough licences for every member user in scope of, or configuring, a Governance capability. A small quantity with a large policy scope is not a valid optimisation.

07

When is the Suite useful—and when is it not?

The Entra Suite combines identity protection, governance, and identity-centric network access. It becomes attractive when several of these building blocks are genuinely needed.

PREREQUISITE

P1 remains the foundation

The Entra Suite requires Entra ID P1 or a bundle containing P1. The Suite does not replace that prerequisite.

INCLUDED

More than P2

The Suite includes ID Protection, ID Governance, Private Access, Internet Access, and Verified ID premium capabilities.

COMPARE

Consider existing rights

Step-up or special pricing may apply to P2 and Microsoft 365 E5 customers. Compare standalone products and Suite against the existing baseline.

SCOPE

Licence benefiting users

Determine which users benefit from each capability. A blanket tenant purchase is not automatically required—but underlicensing is not acceptable either.

08

Guests and applications are not licensed like employees

A common mistake is to treat every directory object as a conventional user.

EXTERNAL ID

Guests and customers

External ID uses a Monthly Active User model for external users. The first 50,000 monthly active external users currently receive core capabilities free; premium add-ons can create additional charges.

GUEST GOVERNANCE

Governance actions for guests

Guest governance requires an Azure subscription for MAU billing. Guests with relevant governance actions in a month are included in the bill.

WORKLOAD ID

Apps, automation, and service principals

Conditional Access for service principals requires Workload Identities Premium. Existing user P1/P2 licences do not automatically cover them.

AGENT IDENTITIES

AI agents

Agents can additionally require Microsoft Agent 365, P1/P2, and other product rights. Preview and rollout rules need a separate check.

09

Which licence fits which need?

This table offers orientation for common situations. Mixed scenarios may require several products at once.

NeedTypical minimum approachAlso check
Users, groups, SSO, and a simple security baselineEntra ID FreeAre Security Defaults granular enough?
Targeted MFA and access policies for usersEntra ID P1Licence every user in policy scope
Risk-based policies and full risk detailsEntra ID P2 or Entra SuiteEvery protected user needs the entitlement
Time-limited admin roles with PIMP2 or ID GovernanceRole holders, approvers, and reviewers count
Lifecycle Workflows, Access Reviews, and advanced access packagesID Governance or Entra SuiteP1/P2 prerequisite and full feature scope
Identity-centric private and internet accessEntra Suite or suitable standalone productsP1 baseline and benefiting users
Conditional Access for service principalsWorkload Identities PremiumNumber of protected workload identities
External guests or customersExternal ID by MAUAzure link and premium add-ons
10

Public list prices make the scope visible immediately

Examples use Microsoft's public German list prices on 22 August 2026 with annual billing, excluding VAT. Contract pricing may differ.

ProductList priceExample for 100
Entra ID P1€6.10 / user / month€610 monthly · €7,320 annually
Entra ID P2€8.70 / user / month€870 monthly · €10,440 annually
Entra ID Governance€6.10 / user / month€610 monthly · €7,320 annually, plus prerequisite
Microsoft Entra Suite€10.40 / user / month€1,040 monthly · €12,480 annually, plus P1 baseline
Microsoft Entra Workload ID€2.60 / workload / month€260 monthly · €3,120 annually
Do not buy P1 or P2 twice.

If Microsoft 365 E3, Business Premium, E5, E7, or another bundle already includes the entitlement, evaluate only the missing component. Existing P2 customers may have different step-up prices.

11

The Entra licensing checklist

These questions turn a technical request into a defensible licensing decision.

  1. 01Which exact capability is required—not merely which product name?
  2. 02Are employees, guests, workload identities, or agents affected?
  3. 03Which users are fully inside the policy, review, or governance scope?
  4. 04Which Entra service plans already exist in Microsoft 365, EMS, or other bundles?
  5. 05Does the add-on require P1, P2, F2, or another active base plan?
  6. 06Must role holders, approvers, reviewers, or administrators be counted too?
  7. 07Is an Azure subscription linked for guest MAU billing?
  8. 08Are price, SKU, Product Terms, agreement, and purchase date documented?
A portal switch is not licensing evidence.

Document the capability, scope, identity types, existing prerequisites, and licence quantity together. That connection makes the decision auditable.

Entra licensing follows the protected identity in the capability scope—not the switch in the portal.

Free provides the foundation, P1 controls access, P2 evaluates risk, Governance manages the access lifecycle, and the Suite connects identity with network access. Guests and application identities use their own models.

Checked against current Microsoft documentation.

This article reflects the publicly documented position on 22 August 2026. Product names, feature mappings, prices, and prerequisites can change.

Note: This article provides clear practical orientation and does not replace checking current Microsoft Product Terms, the specific agreement, orderable SKU, purchase date, and actual tenant configuration.