First, the name. Microsoft Entra ID is what Azure Active Directory became, so if you have been searching “Azure AD P1 vs P2,” you are in the right place; same product, new badge. Entra ID is the identity system behind every Microsoft 365 login your company makes, and since stolen logins are how most modern breaches start, the tier you license here is arguably the most consequential security decision in your whole Microsoft stack.
The plain-English split: P1 gives you control over how people sign in. P2 adds intelligence about how risky each sign-in is, plus governance over your most powerful accounts. Rules versus rules plus radar.
What each tier includes
| Capability | Free (included) | P1 | P2 |
|---|---|---|---|
| Single sign-on and core MFA | Yes | Yes | Yes |
| Conditional Access policies | No | Yes | Yes |
| Group-based access and dynamic groups | No | Yes | Yes |
| Self-service password reset with on-prem writeback | No | Yes | Yes |
| Application Proxy (secure access to on-prem apps) | No | Yes | Yes |
| Identity Protection (risk-based sign-in detection) | No | No | Yes |
| Risk-based Conditional Access | No | No | Yes |
| Privileged Identity Management (PIM) | No | No | Yes |
| Access reviews and entitlement management | No | No | Yes |
| List price (approx., per user/month) | Included | ~$6 | ~$9 |
| Bundled in | All M365 plans | Business Premium, E3 | E5 |
P1: the control layer
The headline feature of P1 is Conditional Access, and it is hard to overstate how central it is. Conditional Access is the policy engine that lets you say things like: require MFA on every sign-in, block logins from countries where you have no staff, refuse access from unmanaged devices, and require stronger proof when someone connects from an unfamiliar location. Without P1, your identity security is essentially on or off. With it, you have a bouncer with judgment.
This is also, quietly, a compliance and insurance issue. The MFA-everywhere and access-control requirements that cyber insurance carriers now demand, which we detailed in our 2026 carrier requirements guide, are implemented in practice through Conditional Access. If you hold Business Premium or E3, you already own P1; the question is whether it is actually configured, because an unconfigured P1 protects exactly nothing.
P1 also brings dynamic groups (access that assigns itself based on department or role), self-service password reset that syncs back to on-prem AD, and Application Proxy for publishing legacy internal apps securely.
P2: the intelligence and governance layer
P2 includes everything in P1 and adds two things that change the game for higher-risk organizations.
The first is Identity Protection: Microsoft’s machine learning watching every sign-in for signals of compromise, leaked credentials, impossible travel, anonymized networks, unfamiliar patterns, and scoring the risk in real time. Paired with risk-based Conditional Access, your policies stop being static rules and start reacting: a risky sign-in gets challenged or blocked automatically, even if the password was correct. Given that attackers usually log in rather than break in, this is the radar that catches them doing it.
The second is Privileged Identity Management, which solves the standing-admin problem. Instead of admins holding god-rights around the clock, PIM makes privileged roles just-in-time: you request elevation, it is approved and time-boxed, and everything is logged. Add access reviews, which force periodic recertification of who can reach what, and P2 becomes the governance layer auditors and frameworks increasingly expect. If you are working toward SOC 2 or similar, as we covered in our first-time SOC 2 guide, P2’s review and PIM evidence makes those controls dramatically easier to demonstrate.
The honest recommendation
For most SMBs: P1, fully configured, is the highest-value identity spend in Microsoft’s catalog, and you likely already own it inside Business Premium or E3. The scandal of the market is not businesses lacking P1; it is businesses paying for it with three Conditional Access policies half-built. Configuration is the product.
P2 earns its premium in specific situations: regulated industries and firms with real audit obligations, organizations that have already been targeted or hold high-value data, companies with more than a handful of admin accounts (that is what PIM is for), and anyone whose carrier or framework expects risk-based access controls and access reviews. If you are on E5, you already own P2, and the same rule applies twice as hard: unused P2 is the most expensive shelfware in your tenant.
Our role in this, for clients, is both halves: right-sizing the license through our licensing and cost optimization service, then building the Conditional Access, Identity Protection, and PIM configuration through our identity and access management practice, with our in-house 24/7 SOC watching the risky sign-ins that P2 surfaces. The license is potential; the configuration is protection.
FAQ
Is Entra ID P1 included in Microsoft 365 Business Premium? Yes. Business Premium and the E3 plans include P1. P2 is included in the E5 plans, and can be licensed standalone.
Is Entra ID the same as Azure AD? Yes. Microsoft renamed Azure Active Directory to Microsoft Entra ID. Same service, same P1 and P2 tiers.
What is the single biggest reason to have P1? Conditional Access. It is the policy engine behind requiring MFA everywhere, blocking risky locations, and restricting unmanaged devices, and it is how carrier and compliance access requirements get implemented in practice.
What does P2 add over P1? Identity Protection with risk-based Conditional Access (machine learning that scores every sign-in and reacts automatically), Privileged Identity Management for just-in-time admin rights, and access reviews for governance.
Do I need P2 for every user or just admins? Features like PIM center on privileged users, but risk-based protection applies per licensed user, and Microsoft’s licensing expects users who benefit from a feature to be licensed for it. Many organizations license P2 broadly via E5 or target it deliberately; this is exactly the kind of right-sizing worth doing with eyes open.
Own it? Then configure it.
If you hold Business Premium or E3 right now, you are already paying for P1. The only question is whether it is protecting you. We help businesses across Los Angeles, Orange County, San Diego, and now New York City turn the identity licenses they already own into the control layer they were supposed to be, and make the P2 call with real numbers. Reach out and we will review your tenant.