Microsoft Entra ID P2 [New Commerce Experience]
Microsoft Entra ID P2
Microsoft Entra ID P2 contains everything in Entra ID Free and P1 and adds the two capabilities that define it: Microsoft Entra ID Protection, which brings risk detection and risk-based Conditional Access, and Privileged Identity Management, which makes administrative roles eligible and time-bound rather than permanently assigned. It also adds access reviews, entitlement management and the wider identity governance features. P2 is included in Microsoft 365 E5 and E7, in Microsoft Defender Suite, and in Enterprise Mobility plus Security E5. The standalone licence is for organisations on E3, Business Premium or another plan that carries only P1.
What it is
Microsoft Entra ID P2 is the top tier of Microsoft's identity and access management service. Where P1 gives you Conditional Access, P2 gives you risk as an input to it, and time-bound privilege as an output.
Who it is for
Organisations that need to remove standing administrative access, detect compromised identities from signals rather than reports, or evidence periodic access review to an auditor or regulator.
Key capabilities
- Everything in Microsoft Entra ID P1, including Conditional Access, multifactor authentication, dynamic groups, self-service password reset with on-premises writeback and Application Proxy
- Microsoft Entra ID Protection: risk detection on users and sign-ins, and risk-based Conditional Access policies
- Privileged Identity Management: eligible rather than permanent role assignment, just-in-time elevation, approval and time limits on administrative access
- Access reviews: periodic recertification of who holds what
- Entitlement management: access packages and lifecycle for granting and removing access
- Identity governance features built on the above
Why this matters beyond the feature list
Two of these map directly onto controls that EU operators are asked to evidence. Privileged Identity Management is how you demonstrate that administrative rights are limited in scope and in duration rather than standing. Access reviews are how you demonstrate that entitlement is checked rather than assumed. Both are far easier to evidence from a product that records them than from a spreadsheet.
Check whether you already have it
Entra ID P2 is included in Microsoft 365 E5 and E7, in Microsoft Defender Suite, and in Enterprise Mobility plus Security E5. It is also included in the Defender Suite add-ons for Microsoft 365 Business Premium. The standalone licence is for tenants on Microsoft 365 E3 or Business Premium, both of which carry P1 only.
Requirements
Risk-based Conditional Access depends on Entra ID Protection and therefore on P2. When P2 licences lapse, existing Conditional Access policies are not deleted; they remain visible and can be removed, but not updated.
What does P2 add over Microsoft Entra ID P1?
Microsoft Entra ID Protection with risk detection and risk-based Conditional Access, Privileged Identity Management, access reviews, entitlement management and the wider identity governance features. P1 has none of these.
Do I need P2 for risk-based Conditional Access?
Yes. Risk-based Conditional Access depends on Microsoft Entra ID Protection, which is a P2 feature. Conditional Access itself, based on user, device and location, is available with P1.
Which plans already include P2?
Microsoft 365 E5 and E7, Microsoft Defender Suite, Microsoft Defender Suite FLW, Defender plus Purview Suite FLW, and Enterprise Mobility plus Security E5. Microsoft 365 E3 and Business Premium include P1 only.
What happens to policies if P2 licences lapse?
Conditional Access policies are not automatically disabled or deleted. You can view and delete the remaining policies but you cannot update them, which is a deliberate grace state so security posture does not change suddenly.
What does Privileged Identity Management actually change?
Administrative roles become eligible rather than permanently assigned. A user activates the role when needed, optionally with approval and always for a limited time, so there is no standing administrative access to steal.
- Vendor
- Microsoft
- Category
- Security
- Type
- SaaS
- Billing
- Monthly
- Commitment
- 1-Year
- Available terms
- Monthly, 1-Year
- Unit price
- €7.30 /mo
- SKU
- MST-NCE-122-C100
Attachable SKUs from the same category. Check each add-on's prerequisites for base-licence eligibility.
- 1You prepay through ITSailor (Malta) — VAT handled, reverse-charge for valid EU VAT IDs.
- 2We provision through Pax8 wholesale into your Microsoft tenant — no third-party MSP markup.
- 3You keep the tenant. Sovereign by default — every engagement closes with an Exit Kit.
Pax8 wholesale, margin in the price
Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.
Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,
Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz
Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.