Skip to main content
Entra ID P1 vs P2, India

P1 is conditional access for everyone. P2 is risk policies, PIM and reviews for the audited.

That is the whole decision in one line. Entra ID P1, which most Indian organisations already own inside Microsoft 365 Business Premium or E3, gives you conditional access, hybrid identity and self-service password reset with writeback. P2 adds Identity Protection risk policies, Privileged Identity Management and access review capability, and it earns its keep when a regulator, an auditor or a mature security programme will actually use those three. We help you establish which side of that line you are on before anyone quotes you an upgrade.

Microsoft
Microsoft
Entra ID
Cloud Solution Partner
  • P1Already in Business Premium and E3
  • P2In E5, or standalone per user
  • 2 featuresGenuinely new at P2
  • Most tenantsNever enable what P1 includes
What the licence actually decides

Eight things to establish before you buy either plan.

Everything below follows the Microsoft Entra licensing documentation rather than reseller comparison charts, which matters because Microsoft has moved capabilities between editions and a lot of circulating advice describes an arrangement that no longer holds. Read these eight and you will know more than most of the people selling the upgrade.

Where P1 comes from, usually a plan you already pay for

Entra ID P1 is included in Microsoft 365 Business Premium, in E3 and E5, in the frontline F1 and F3 plans, and in Enterprise Mobility and Security E3. If your organisation runs Business Premium, which is the default for Indian SMBs on Microsoft, every licensed user already holds P1. The first question in any P1 vs P2 conversation is therefore not "which should we buy" but "what do we already own", and the answer surprises most of the organisations that ask us.

Where P2 comes from, E5 or a standalone add-on

Entra ID P2 is included in Microsoft 365 E5 and Enterprise Mobility and Security E5, and is available as a standalone per-user licence on top of whatever you run today. That standalone route matters in India, where many organisations sit on Business Premium or E3 and need P2 capabilities for a subset of users only. You do not need to move the whole company to E5 to get PIM for twelve administrators, and anyone proposing that should be asked to justify it.

What P1 gives you: conditional access, the control that matters most

Conditional access is the policy engine that evaluates every sign-in against user, location, device and application, and then blocks it, requires MFA, or requires a compliant device. It is the single highest-value identity control in the Microsoft stack, it is the backbone of every zero-trust rollout, and it is a P1 feature. So are self-service password reset with on-premises writeback, dynamic groups, group-based application assignment, and Entra Connect Health for monitoring hybrid sync.

The first genuine P2 addition: Identity Protection risk policies

Identity Protection scores every sign-in and every user for risk, using signals like impossible travel, anonymised IP addresses, leaked credentials and unfamiliar sign-in properties. At P2 you can build conditional access policies on those scores, so a high-risk sign-in is blocked or forced through MFA and a password reset automatically, without an engineer watching a dashboard. At P1 you get a limited view of risky users with no detail drawer and no history, which tells you something happened without telling you what.

The second: Privileged Identity Management

PIM replaces standing administrator access with eligible access. An engineer holds no admin rights until they activate a role, the activation is time-bound, optionally approved, justified in writing and fully logged. For any organisation whose auditor asks "who has Global Administrator and why", PIM converts an awkward conversation into a report. It is the strongest single argument for P2 in audited environments, and it is licensed for the administrators it touches rather than the whole organisation.

Access reviews and entitlement management have moved, check before buying

Microsoft now states that using access reviews requires an Entra ID Governance subscription for member users, with some capabilities operating under a P2 subscription, and the same wording covers entitlement management. Much published guidance still lists both as plain P2 features, which is now at best partial. If your reason for upgrading is an access certification programme for an RBI or SEBI audit, establish exactly what P2 alone will give you before committing, because the honest answer is conditional.

How many licences you need, which is not everyone

For PIM, licences are needed for users holding eligible or time-bound role assignments, members and owners under PIM for Groups, approvers, and access review participants. Microsoft's own worked example licenses 53 people in an organisation far larger than that. Access reviews work the other way and need licences for reviewers and for every user being reviewed. This arithmetic is why a scoped P2 purchase for the administrative population is usually the right shape, and a blanket upgrade usually is not.

What happens on lapse, and it differs sharply between features

If P1 or P2 lapses, conditional access policies are not automatically disabled or deleted, they can be viewed and deleted but not updated, so your posture freezes rather than collapsing. PIM does not degrade gracefully: eligible role assignments are removed, ongoing access reviews end, and PIM configuration settings are removed. An organisation that builds its entire administrative model on eligible access and later drops P2 loses that model, which belongs in the decision before you build, not at a renewal three years later.

The problem nobody quotes for

Most Indian P1 tenants have never enabled conditional access.

Before any conversation about upgrading, an honest reading of the market: the most common Entra licensing problem in India is not under-licensing, it is paid-for capability sitting switched off. In the majority of Business Premium and E3 tenants we assess remotely from Hyderabad, the P1 features are unconfigured.

  • Conditional access unconfigured or reduced to a single default policy, which means the tenant is relying on per-user MFA settings or security defaults while paying for a full policy engine. Blocking legacy authentication, requiring MFA outside trusted networks and requiring compliant devices for sensitive apps are all available today at P1 and cost nothing further to enable.
  • Self-service password reset with on-premises writeback disabled, so every forgotten password in a hybrid estate still lands on the helpdesk. This is a P1 capability that typically removes a fifth or more of ticket volume on its own, and most tenants running Entra Connect have never turned it on.
  • Dynamic groups unused, with licence assignment and app access managed by hand-maintained static groups that drift the moment someone changes department. Dynamic membership rules are P1 and they are the difference between a joiner getting the right access on day one and getting it after three tickets.
  • The practical consequence: if your P1 estate is unconfigured, the correct next spend is configuration work, not a P2 upgrade. An organisation that is not using conditional access will not use Identity Protection either, it will just own two unused policy engines instead of one. We say this as a company that would happily sell you the configuration work for either.
Ask us what your tenant already includes
How we advise on this

Four disciplines that make the advice worth having.

Licensing advice usually comes from whoever benefits from the upgrade. We configure and manage Entra tenants for a living, so the incentive exists for us too, which is exactly why the discipline below is stated rather than assumed.

We check what you own first

A large share of organisations asking about P2 have unconfigured P1, and some already hold P2 inside an E5 plan bought for other reasons. Establishing that first regularly ends the conversation without a purchase, which is the correct outcome.

We work from the licensing article

Microsoft moves features between editions, and the access reviews shift toward the Governance SKU is a live example most published advice has missed. Every inclusion claim we make traces to Microsoft's own licensing documentation, conditions reproduced, not simplified.

We scope P2 to the people who need it

PIM licenses eligible administrators, approvers and reviewers, not the organisation. For most Indian businesses the right shape is P1 broadly with standalone P2 for the administrative population, and we do that arithmetic against your actual admin count.

Remote-first from Gachibowli, Hyderabad

The whole engagement, tenant assessment, licence mapping, conditional access and PIM configuration, runs remotely from our Gachibowli, Hyderabad base for clients across India, with a written recommendation you can hand to finance or an auditor.

Decision scenarios

Six Indian situations and what we would usually recommend.

In half of these the recommendation is not to buy P2, which is roughly the honest real-world ratio once you establish what an organisation already holds and whether anyone would use the additions.

A 50-person SMB on Business Premium

P1 is already in the plan. The recommendation is almost never P2: it is to enable conditional access, block legacy authentication, turn on SSPR with writeback and use what is already paid for. Buying P2 before configuring P1 purchases a second unused policy engine.

An audited BFSI or fintech firm

Where RBI, SEBI or IRDAI expectations cover privileged access and periodic access certification, P2 justifies itself through PIM and review capability, licensed for the administrative population. Check the Governance SKU position on access reviews before finalising scope.

A hybrid estate still running on-premises AD

P1 is the minimum sensible position, for conditional access in front of cloud apps, SSPR writeback so password resets flow back to AD, and Connect Health watching the sync layer. P2 becomes relevant once the admin population and audit exposure grow.

An organisation already on E5

You own P2 and quite possibly have never enabled Identity Protection or PIM. This is the most common waste we see in Indian Microsoft estates: capability paid for, switched off, and a separate security purchase proposed to solve a problem the existing licence covers. The work is configuration, not procurement.

An IT services or SaaS company facing client security reviews

Client due-diligence questionnaires increasingly ask how privileged access is controlled and whether access is periodically reviewed. PIM plus a scoped review process answers both with evidence, and a subset P2 purchase for the engineering admin population is usually enough.

A small team with no security operations

P2 buys risk detection, and detection with no responder changes nothing. If nobody would act on a risky sign-in alert on a Friday night, spend on prevention instead: strong conditional access and device compliance at P1, and revisit P2 when someone can receive the signal.

Feature by feature

What each plan includes, with no prices attached.

Plan inclusion is a published Microsoft product fact. The rows below are the ones that actually decide the P1 vs P2 question for Indian organisations, and the access review rows carry Microsoft's current conditional wording rather than the simplified yes you will find in older comparisons.
Feature
Entra ID P1
Inside Business Premium and E3
Entra ID P2
Inside E5, or standalone
Conditional access
Policy engine for every sign-in: block, require MFA, require compliant device.
IncludedIncluded
SSPR with on-premises writeback
Self-service password reset that syncs back to on-premises AD.
IncludedIncluded
Dynamic groups
Rule-based group membership for licensing and app assignment.
IncludedIncluded
Hybrid identity with Entra Connect Health
Monitoring and alerting for the sync layer in hybrid AD estates.
IncludedIncluded
Identity Protection risk policies
Risk-based conditional access on sign-in risk and user risk signals.
Not included, P2 onlyIncluded
Full risk reports and alerting
Risky users and sign-ins with detail, history, alerts and weekly digest.
Limited view onlyIncluded
Privileged Identity Management
Just-in-time, time-bound, approved and logged admin elevation.
Not included, P2 onlyIncluded
Access reviews
Periodic certification of who holds which access.
Not includedSome capabilities, full feature needs the Governance SKU
Entitlement management
Access packages with approval workflows and expiry.
Not includedSome capabilities, full feature needs the Governance SKU
Feature by edition

Free, P1 and P2 side by side.

Taken from the Microsoft Entra licensing documentation. Where Microsoft describes a capability as limited rather than absent, the table says limited, because the difference between limited and none is exactly what this decision turns on.
CapabilityFreeP1P2
Cloud SSO and basic MFAYesYesYes
Conditional access policiesNoYesYes
Risk-based conditional accessNoNoYes
Identity Protection risk reportsLimitedLimited, no detail or historyFull
Privileged Identity ManagementNoNoYes
Access reviewsNoNoSome capabilities, Governance SKU for the full feature
Entitlement managementNoNoSome capabilities, Governance SKU for the full feature
Self-service password resetCloud onlyWith on-premises writebackWith on-premises writeback
Dynamic groupsNoYesYes
Entra Connect (hybrid sync)YesYesYes
Entra Connect HealthNoYesYes
Custom RBAC rolesNoYesYes
Audit and sign-in logsYesYesYes
How we work the decision

Five steps, and it often ends at step two.

Typically one to two weeks of elapsed time, delivered remotely from Hyderabad, and most of it is spent establishing what you already hold and whether it is configured. That is deliberately the cheapest question, so it is asked first.
  1. 1

    Map what your users actually hold

    2-3 days

    Which plans, how many of each, and whether any group already carries P2 through E5 or EMS E5. This regularly surfaces entitlement nobody knew about, and it is the necessary baseline, you cannot evaluate an upgrade without knowing the starting point.

  2. 2

    Check whether P1 is configured

    2-3 days

    Conditional access coverage, legacy authentication blocking, SSPR writeback, dynamic groups, Connect Health. If these are unconfigured, that is the work, and we say so rather than proceeding to a P2 conversation.

  3. 3

    Test the P2 case honestly

    1-2 days

    Two questions decide it: would anyone act on risk signals, and are there enough administrators for eligible access to be meaningful. If either answer is no, P2 buys reporting rather than protection, and that is a legitimate finding.

  4. 4

    Do the licence arithmetic

    1-2 days

    For PIM, the eligible admins plus approvers plus reviewers. For access reviews, reviewers plus reviewed users, and a check on whether the Governance SKU rather than P2 is what the feature now requires. This usually produces a smaller number than a blanket upgrade.

  5. 5

    Decide, configure, record why

    3-5 days

    A written recommendation with reasoning and licence counts for finance or your auditor. Where the answer is to upgrade, we configure what you buy, because P2 with Identity Protection and PIM left switched off is exactly the waste this exercise exists to prevent.

Straight answers

Entra ID P1 vs P2, frequently asked.

Work the decision properly

Fifteen questions that settle P1 vs P2.

The first group establishes what you already hold, the second tests whether P2 capability would actually be used, and the third is the arithmetic. In our experience the first group ends the conversation for a meaningful share of Indian organisations, in the direction of configuring what they own.

What you already have

  • Which Microsoft 365 plans do your users hold?
    Business Premium, E3, F1 and F3 all include P1.
  • Does any group already hold E5 or EMS E5?
    Those include P2, and it may be sitting unused.
  • Is conditional access configured beyond defaults?
    If not, you have unused P1 before P2 enters the picture.
  • Is SSPR with writeback enabled for your hybrid users?
    A P1 feature that cuts helpdesk volume immediately.
  • Are dynamic groups driving licence and app assignment?
    P1, and the cure for hand-maintained group drift.

Would you use what P2 adds

  • Do you want risky sign-ins blocked automatically, not just reported?
    That is Identity Protection, and it is the P2 headline.
  • Would anybody act on a risk alert at 11pm on a Friday?
    Detection without a responder changes nothing.
  • Do you have enough administrators for eligible access to mean something?
    PIM earns its place at scale, not at two admins.
  • Does an auditor ask who holds privileged access and why?
    RBI, SEBI and ISO 27001 audits all do. PIM answers with a report.
  • Are you buying P2 specifically for access reviews?
    Check the Governance SKU position first, that feature has moved.

The arithmetic

  • How many administrators would PIM actually manage?
    Licence the eligible admins, approvers and reviewers, not the company.
  • If reviewing access, how many users would be reviewed?
    Reviewed users need licences too, which changes the count sharply.
  • Could P2 cover a subset instead of everyone?
    Standalone P2 on top of Business Premium or E3 is a supported shape.
  • Is E5 already justified for other reasons?
    If Defender and Purview arguments stack up, P2 rides along.
  • What breaks if P2 lapses at renewal?
    PIM eligible assignments are removed, not frozen. Plan for it.
Next step

Find out what you already own before comparing anything.

A meaningful share of the organisations that ask us about P2 already hold it inside an E5 plan, or have never configured the P1 they pay for. That first answer is free, takes one conversation, and frequently ends the question without a purchase. We reply within 4 business hours.