Microsoft Entra ID P1 vs P2: Conditional Access, PIM, Identity Protection, Access Reviews and Entitlement Management, and Which Compliance Frameworks Push You to Which Tier
Every Microsoft 365 plan above Business Basic carries some tier of Microsoft Entra ID, and most tenants never look at which. The difference between P1 and P2 decides whether you can react to a leaked credential automatically, whether your Global Administrators hold their role permanently, and whether an auditor's request for a quarterly access review is a report or a project.
P1: Conditional Access and the controls around it
Microsoft Entra ID P1 is the tier that makes access conditional. Microsoft's Conditional Access documentation puts the license requirement at P1 and adds that Microsoft 365 Business Premium customers can use the feature too. Our Microsoft Entra ID P1 page lists what rides with it: Conditional Access on user, group, device, location, application and sign-in conditions; single sign-on to Microsoft and third-party cloud apps; self-service password reset with writeback for hybrid tenants; dynamic groups; and Application Proxy for on-premises web apps. Microsoft's governance table adds HR-driven provisioning and terms-of-use attestation at P1.
What P1 does not do is react to risk. Risk-based policies, the ones that step up authentication when a sign-in looks like a password spray or a leaked credential, require Microsoft Entra ID Protection, which is a P2 feature. A P1 tenant sees the risky users report only for medium and high risk, with no detail drawer or history, and a limited risk detections report.
Two operational facts from the same documentation are worth knowing. When the licenses behind Conditional Access expire, the policies are not disabled or deleted; they keep running and can be viewed and deleted, but not updated. And security defaults, the no-charge baseline, remain available to every tenant, which is what you fall back to below P1. Our Conditional Access Policy Implementation service builds the P1 baseline; the design patterns article explains the choices inside it.
P2: Identity Protection and Privileged Identity Management
P2 adds two things, and Microsoft's licensing tables are precise about both.
Identity Protection. With P2 the risky users, risky sign-ins and risk detections reports open fully, users-at-risk alerts and the weekly digest switch on, the MFA registration policy becomes available, and sign-in-risk and user-risk policies can be enforced through Conditional Access. Some detections come from Defender products, so the signal depends on what else is licensed. Our Risky Users and Risky Sign-ins Monitoring service watches those reports for tenants without a security operations team.
Privileged Identity Management. PIM makes role assignments eligible rather than permanent: just-in-time activation, time-bound assignments, approval, MFA on activation, justification, notifications, access reviews of roles, exportable audit history, and a guard that prevents removing the last active Global Administrator or Privileged Role Administrator. Licensing is per person in scope, not per tenant. Microsoft lists who must hold P2 or Governance: users with eligible or time-bound assignments to Entra or Azure roles, members and owners in PIM for Groups, approvers, users assigned to an access review and the people who perform reviews. Microsoft's own worked example: 14 administrators managed through PIM plus three approvers means 17 licenses.
If the P2 or Governance license lapses, permanent assignments stay, eligible assignments are removed, time-bound assignments become permanent, ongoing role reviews end and PIM stops sending notifications. Our Microsoft Entra PIM and Privileged Access Hardening service is where most 20-to-500-seat organizations start with P2: a handful of administrators, not the whole company.
Access reviews and entitlement management: P2, or Entra ID Governance?
Microsoft's governance licensing table splits both features into capabilities previously generally available in P2, which P2 still covers, and newer capabilities that need the Microsoft Entra ID Governance add-on or the Entra Suite. Microsoft has also stated that no new identity governance features will be added to the P2 SKU.
With P2 you get access reviews of groups, applications and roles, with inactive-user recommendations for reviewers, and entitlement management access packages with self-service requests, multi-stage and manager approval, expiration, separation of duties and Conditional Access scoping. Governance-only: reviews scoped to inactive users alone, machine-learning-assisted certification, reviews of PIM for Groups, auto-assignment policies, managers requesting on behalf of employees, custom extensions through Logic Apps, Verified ID and Insider Risk integrations, and the whole of Lifecycle Workflows (up to 50 workflows and 100 custom task extensions). Our Entra ID Governance page lists the base SKU, a step-up for tenants that already hold P2, and frontline variants; Microsoft's prerequisite is a tenant subscription carrying the P1 or P2 service plan.
Counting follows the same logic as PIM. Microsoft's example: a review of a group with 75 members and one owner as reviewer needs 76 licenses; a self-review of 500 users needs 500. Licenses do not have to be assigned to each user, but there must be as many as the member users in scope plus the people who configure the features. Governing guest users is different: it is billed per monthly active guest through an Azure subscription, and that meter is yours. The Entra ID Governance Implementation service scopes the add-on to the groups and packages you will actually review, and the Managed Entra ID Identity Hygiene and Access Reviews service runs the reviews so they finish.
How the plans bundle P1 and P2
Microsoft's Entra licensing page and the service plan reference agree.
P1 is included in Microsoft 365 E3, E5 and E7; Microsoft 365 F1 and F3; Enterprise Mobility + Security E3; and Microsoft 365 Business Premium. P2 is included in Microsoft 365 E5 and E7, Microsoft Defender Suite (formerly Microsoft 365 E5 Security), the Defender Suite and Defender + Purview Suite frontline variants, Enterprise Mobility + Security E5, and the Defender Suite add-ons for Business Premium. The standalone Microsoft Entra ID P2 product carries both the P1 and P2 service plans, so it is never stacked on top of P1; our Microsoft 365 E3 page lists an Entra P2 add-on SKU for E3 tenants.
The practical pattern for a mid-size tenant is mixed tiers. Everyone on Business Premium or E3 already has P1 and Conditional Access. P2 goes to the people in scope of what P2 does: the administrators PIM will manage, their approvers and reviewers, and any group you target with a risk policy. The Microsoft 365 Plan Optimizer models identity as a three-level need (none, P1, P2), prices the lowest-cost combination of base plan and add-on, and shows an all-E5 alternative beside it. Our E3 vs E5 article explains why the whole-company E5 route rarely wins on identity alone.
Which compliance frameworks push you to which tier
Frameworks do not name Microsoft SKUs; they name controls. Map the control, then the tier.
- Multifactor authentication and access restricted by user, device or location is the P1 tier. The HIPAA Security Rule's access controls, PCI DSS multifactor requirements, cyber-insurance questionnaires and the CMMC Level 2 practices drawn from NIST SP 800-171 are all satisfiable with Conditional Access on Business Premium or E3, provided the policies are enforced rather than left in report-only mode.
- Least privilege for administrators, with time-limited elevation and an audit trail is P2 through PIM. Any framework that asks how privileged accounts are controlled and reviewed, NIST SP 800-171 and CMMC among them, is easier to evidence with eligible assignments and activation logs than with a spreadsheet of permanent Global Administrators.
- Periodic review of who has access is P2 for the basic reviews and Governance for reviews of inactive users, automated assignment and lifecycle workflows. SOC 2 and ISO 27001 audits and the NYDFS Part 500 access-privilege requirements are the usual drivers.
- Detecting compromised credentials and responding automatically is P2 through Identity Protection.
Evidence, not licensing, is what an assessor grades. A P2 license with PIM unconfigured proves nothing; a P1 tenant with enforced Conditional Access, tested break-glass accounts and retained sign-in logs proves a great deal. Our Conditional Access Policy Review and Break-Glass Validation service produces that evidence for a P1 tenant.
Frequently asked questions
Does Microsoft 365 Business Premium include Entra ID P1 or P2?
P1, per Microsoft's Entra licensing page and the service plan reference. P2 arrives with the Defender Suite add-on for Business Premium or a standalone P2 license.
Can I buy P2 for just my administrators?
Yes. PIM licensing counts the users with eligible or time-bound assignments, the approvers and the reviewers; assign P2 to those people. Everyone else keeps P1 from their base plan.
What happens to Conditional Access if a P1 license lapses?
Policies keep running and can be viewed and deleted, but not updated, until licensing is restored.
Are access reviews still a P2 feature?
The capabilities that were generally available under P2 remain there. Reviews scoped only to inactive users, machine-learning recommendations, PIM for Groups reviews and Lifecycle Workflows need Microsoft Entra ID Governance or the Entra Suite.
How are guests licensed for governance?
Per monthly active guest through an Azure subscription; the charge lands on your Azure bill rather than on a per-user license.
Sources
- Microsoft Learn: Microsoft Entra licensing
- Microsoft Learn: Microsoft Entra ID Governance licensing fundamentals
- Microsoft Learn: What is Conditional Access? (license requirements)
- Microsoft Learn: What is Microsoft Entra ID Protection? (license requirements)
- Microsoft Learn: What is Microsoft Entra Privileged Identity Management?
- Microsoft Learn: What are access reviews? and What is entitlement management?
- Microsoft Learn: Product names and service plan identifiers for licensing
- IT Partner: Microsoft Entra ID P1, P2 and Entra ID Governance subscription pages
The compliance-framework section characterizes each framework's access-control expectations in general terms and does not cite control numbers.
| Capability | Included tier | Entra ID P1 | Entra ID P2 | Entra ID Governance / Entra Suite |
|---|---|---|---|---|
| Security defaults | Yes | Yes | Yes | Yes |
| Conditional Access | No | Yes | Yes | Yes |
| Risk-based Conditional Access (sign-in and user risk) | No | No | Yes | Yes |
| Risky users and risky sign-ins reports | Limited | Limited | Full | Full |
| Privileged Identity Management, PIM for Groups | No | No | Yes | Yes |
| Access reviews (capabilities previously generally available in P2) | No | No | Yes | Yes |
| Reviews scoped to inactive users only; machine-learning recommendations | No | No | No | Yes |
| Entitlement management: access packages, approvals, expiration | No | No | Yes | Yes |
| Auto-assignment policies, custom extensions, requests on behalf | No | No | No | Yes |
| Lifecycle Workflows | No | No | No | Yes |
| HR-driven provisioning, terms of use | No | Yes | Yes | Yes |
Key takeaways
- P1 is Conditional Access, single sign-on, self-service password reset and dynamic groups; Business Premium, E3, F1, F3 and EMS E3 carry it.
- P2 adds Identity Protection and PIM; E5, EMS E5 and the Defender Suite add-ons carry it, and a standalone P2 license already contains P1.
- PIM and access reviews are licensed for the people in scope (eligible admins, approvers, reviewers, reviewed users), so P2 for a subset of users is normal.
- Basic access reviews and entitlement management stay in P2; inactive-user reviews, auto-assignment and Lifecycle Workflows need Entra ID Governance.
- Frameworks grade evidence: MFA and conditional access map to P1; privileged access, periodic review and risk response map to P2 or Governance.
Decide the tier per population, not per tenant. The Microsoft 365 Plan Optimizer prices P1 and P2 as add-ons against a plan change at Microsoft's list price. When the answer is P2 for the administrators, our Microsoft Entra PIM and Privileged Access Hardening service configures eligible roles, approvals and reviews at a fixed price; when the answer is P1 done properly, the Conditional Access Policy Implementation service builds and enforces the baseline.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.