Entra ID Premium P1 vs. P2: Is the Upgrade Worth It?
Disclosure and evaluation basis
This comparison is written for authorised IT administrators evaluating tools for business environments. Editorial conclusions are independent: advertisers, sponsors, and vendors do not control ratings, rankings, verdicts, or recommendations.
We evaluate operational fit, deployment effort, permissions and security model, supportability, rollback options, documentation quality, and licensing clarity. Pricing, packaging, features, support terms, and availability can change, so verify current details with the vendor before purchasing or renewing.
P2 is worthwhile when privileged access, external access reviews, or compliance evidence are owned operational processes. For smaller tenants without those drivers, P1 covers Conditional Access and SSPR fundamentals well.
This page is an operator decision framework based on documented product capabilities and the facts already in this article. It is not a lab test, benchmark, or fabricated evaluation.
What P1 Gives You
Entra ID Premium P1 is included in Microsoft 365 Business Premium and E3. For most organisations on these plans, P1 is already licensed without an additional spend decision.
P1 includes the features that most enterprise tenants consider baseline:
- Conditional Access (full policy engine including named locations, sign-in risk basics, compliance requirements)
- Self-Service Password Reset with writeback to on-premises AD
- Hybrid identity with seamless SSO and pass-through authentication
- Entra Application Proxy for publishing on-premises web apps
- Group-based licensing and dynamic group membership
- MFA registration and enforcement via Conditional Access
For organisations managing a Microsoft 365 tenant with standard identity requirements, P1 covers the fundamentals well.
Who P1 Is Usually Enough For
P1 is often enough for smaller or moderately mature tenants that need Conditional Access, SSPR, dynamic groups, and hybrid identity but do not yet have a formal privileged access or access certification process.
It is also a sensible starting point when the tenant still needs basic hygiene work: emergency access accounts, MFA coverage, legacy authentication blocks, admin role clean-up, and reliable sign-in monitoring. P2 does not remove the need to do those jobs properly.
What P2 Adds
Entra ID Premium P2 is included in Microsoft 365 E5 and the Entra ID P2 standalone licence.
The three meaningful additions are:
1. Privileged Identity Management (PIM)
PIM provides just-in-time (JIT) privileged access to Entra ID and Azure roles. Instead of users having permanent Global Administrator or Privileged Role Administrator assignment, they request elevation for a time-limited window.
Features include:
- JIT activation: Eligible role assignments that require approval or MFA to activate
- Activation duration limits: Roles expire automatically after a configured window
- Approval workflows: High-privilege roles can require a second approver
- Activation history and alerts: Full audit trail of who elevated, when, and for how long
For any organisation with more than one Global Administrator, PIM is the most impactful security control in P2.
2. Identity Protection Risk Policies
Identity Protection adds automated response to risky sign-in and risky user events. It analyses sign-in patterns and flags:
- Atypical travel (impossible travel between sign-ins)
- Leaked credentials (matched against breach databases)
- Anomalous token usage
- Malicious IP addresses
With P2, you can create Conditional Access policies based on sign-in risk level (Low, Medium, High) and user risk level, triggering MFA step-up or password change requirements automatically.
3. Access Reviews
Access reviews allow you to schedule periodic certifications of group membership, application assignments, and privileged role assignments. Reviewers (managers or resource owners) are prompted to confirm that each access is still appropriate.
This is a compliance feature as much as a security feature. Many audit frameworks (SOC 2, ISO 27001, HIPAA) require evidence of access certification.
P1 vs P2 Feature Table
| Feature | P1 | P2 |
|---|---|---|
| Conditional Access (standard) | ✓ | ✓ |
| Self-Service Password Reset | ✓ | ✓ |
| MFA per user and CA | ✓ | ✓ |
| Privileged Identity Management | ✗ | ✓ |
| Identity Protection risk policies | ✗ | ✓ |
| Access Reviews | ✗ | ✓ |
| Entitlement Management (access packages) | ✗ | ✓ |
| Conditional Access: sign-in risk | Partial | Full |
The Upgrade Decision
P2 is worth the upgrade if your organisation has any of:
- More than one person with Global Administrator or Privileged Role Administrator
- External guests or contractors who need periodic access certification
- Compliance requirements (SOC 2, ISO 27001, NIS2, HIPAA) that mandate JIT privileged access or access reviews
- A history of credential-based attacks or account takeover incidents
For small tenants with a single IT administrator and no compliance framework requirements, P1 provides adequate identity controls.
Cost Consideration
If you are on Microsoft 365 E3, adding P2 to your entire tenant can be significant. Consider a targeted P2 licensing approach: licence P2 only for users in privileged roles (Global Admins, Privileged Role Admins, Security Admins) and leave standard users on E3 (which includes P1). This is a supported licensing configuration.
What to Check Before Upgrading
Before buying P2 across the tenant, check:
- How many permanent privileged role assignments exist today
- Whether Global Administrator accounts can be reduced before introducing PIM
- Which guest users, groups, apps, and privileged roles actually need access reviews
- Whether the security team will review Identity Protection alerts and risky user events
- How P2 licensing will be assigned to admins, reviewers, and users in scope
- Whether audit evidence needs to come from PIM, access reviews, sign-in logs, or a SIEM
P2 is most valuable when someone owns the process. PIM without regular role review, stale eligible assignments, and no alert handling can become another control that looks good on paper but does little in practice.
Operational Caveats
Start PIM with a small set of high-impact roles, such as Global Administrator, Privileged Role Administrator, Exchange Administrator, and Security Administrator. Add approval and justification requirements after confirming admins can still perform urgent work.
For access reviews, begin with privileged groups and external guest access. Reviewing every group in the tenant at once usually creates fatigue and poor reviewer decisions.
Pilot Plan Before Buying Tenant-Wide P2
Do not buy P2 for every user because a security framework document mentions JIT admin access. Run a short pilot that proves ownership, alert handling, and helpdesk impact first.
Suggested pilot scope
- Identify 10–30 privileged identities: Global Administrator, Privileged Role Administrator, Security Administrator, Exchange Administrator, and any break-glass accounts that should remain permanent exceptions.
- Licence P2 only for those identities and the reviewers who will approve activations or access reviews.
- Convert permanent privileged roles to eligible assignments in PIM for one non-emergency admin cohort.
- Enable a medium/high sign-in risk Conditional Access policy in report-only mode before enforcement.
- Run one access review cycle for a privileged group and one guest-access group.
Pilot success criteria
- Admins can still complete urgent work within the approved activation window
- Approvers respond within the SLA you set for production
- Risky sign-in alerts are reviewed by a named owner, not an unwatched mailbox
- Access review decisions are completed with fewer than a small percentage of “approve by fatigue”
- Break-glass accounts remain excluded from risky MFA experiments and are monitored separately
If those criteria fail, fix the process before expanding licences. P2 without ownership is an expensive checkbox.
When Not To Upgrade Yet
Delay a broad P2 purchase when:
- Permanent Global Administrator sprawl has not been cleaned up
- There is no on-call owner for Identity Protection alerts
- Conditional Access baselines, MFA registration, and legacy authentication blocks are still incomplete
- Managers or resource owners have never completed an access review successfully
- The only driver is “E5 marketing includes it” with no control design
In those cases, finish P1 hygiene first. P2 multiplies process maturity; it does not create it.
Operational Cost Beyond Licence Price
Budget time for:
- PIM role design, approval groups, and emergency access exceptions
- Access review cadence, reviewer training, and evidence export for audits
- Identity Protection tuning to reduce false positives that cause password-reset storms
- Conditional Access report-only evaluation and staged enforcement
- SIEM or log retention if auditors require longer history than the default portal view
A realistic estimate for a mid-size tenant is several weeks of design and pilot work, then ongoing weekly review of activations, risky users, and overdue access reviews.
Evidence To Keep For Auditors And Change Control
Keep a simple evidence pack:
- Role inventory before and after PIM conversion
- Sample activation and approval records
- Access review completion reports for privileged and guest scopes
- Conditional Access report-only results for risk-based policies
- Break-glass account list, storage method for credentials, and monitoring alert proof
That pack is often more useful in an audit conversation than a feature comparison table alone.
Verdict
P2 is worth it if you have privileged accounts, external access to certify, or compliance requirements and a team ready to operate PIM, risk policies, and access reviews. For smaller tenants without those drivers, P1 covers the Conditional Access and SSPR fundamentals adequately. Prefer targeted P2 licensing for privileged identities before tenant-wide expansion.
Primary Sources
- Microsoft Entra ID Governance / PIM overview
- Microsoft Entra ID Protection overview
- Access reviews overview
- Microsoft Entra ID editions and feature comparison
Related Reading
Jack Hadcroft
LinkedInEndpoint specialist and author of AdminSignal
Jack Hadcroft is an endpoint specialist working with Microsoft Intune, Windows clients, Microsoft Entra ID, Group Policy, and PowerShell in Microsoft 365 estates. He publishes independent, source-backed guidance that focuses on prerequisites, validation evidence, operational risk, and safe rollout decisions, with examples and limitations labelled clearly.
AdminSignal content is produced independently. Editorial policy