Skip to main content
Entra ID P1 vs P2, India

P1 is conditional access for everyone. P2 is risk policies, PIM and reviews for the audited.

That is the whole decision in one line. Entra ID P1, which most Indian organisations already own inside Microsoft 365 Business Premium or E3, gives you conditional access, hybrid identity and self-service password reset with writeback. P2 adds Identity Protection risk policies, Privileged Identity Management and access review capability, and it earns its keep when a regulator, an auditor or a mature security programme will actually use those three. We help you establish which side of that line you are on before anyone quotes you an upgrade.

Microsoft
Microsoft
Entra ID
Cloud Solution Partner
  • P1Already in Business Premium and E3
  • P2In E5, or standalone per user
  • 2 featuresGenuinely new at P2
  • Most tenantsNever enable what P1 includes
What the licence actually decides

Eight things to establish before you buy either plan.

Everything below follows the Microsoft Entra licensing documentation rather than reseller comparison charts, which matters because Microsoft has moved capabilities between editions and a lot of circulating advice describes an arrangement that no longer holds. Read these eight and you will know more than most of the people selling the upgrade.

Where P1 comes from, usually a plan you already pay for

Entra ID P1 is included in Microsoft 365 Business Premium, in E3 and E5, in the frontline F1 and F3 plans, and in Enterprise Mobility and Security E3. If your organisation runs Business Premium, which is the default for Indian SMBs on Microsoft, every licensed user already holds P1. The first question in any P1 vs P2 conversation is therefore not "which should we buy" but "what do we already own", and the answer surprises most of the organisations that ask us.

Where P2 comes from, E5 or a standalone add-on

Entra ID P2 is included in Microsoft 365 E5 and Enterprise Mobility and Security E5, and is available as a standalone per-user licence on top of whatever you run today. That standalone route matters in India, where many organisations sit on Business Premium or E3 and need P2 capabilities for a subset of users only. You do not need to move the whole company to E5 to get PIM for twelve administrators, and anyone proposing that should be asked to justify it.

What P1 gives you: conditional access, the control that matters most

Conditional access is the policy engine that evaluates every sign-in against user, location, device and application, and then blocks it, requires MFA, or requires a compliant device. It is the single highest-value identity control in the Microsoft stack, it is the backbone of every zero-trust rollout, and it is a P1 feature. So are self-service password reset with on-premises writeback, dynamic groups, group-based application assignment, and Entra Connect Health for monitoring hybrid sync.

The first genuine P2 addition: Identity Protection risk policies

Identity Protection scores every sign-in and every user for risk, using signals like impossible travel, anonymised IP addresses, leaked credentials and unfamiliar sign-in properties. At P2 you can build conditional access policies on those scores, so a high-risk sign-in is blocked or forced through MFA and a password reset automatically, without an engineer watching a dashboard. At P1 you get a limited view of risky users with no detail drawer and no history, which tells you something happened without telling you what.

The second: Privileged Identity Management

PIM replaces standing administrator access with eligible access. An engineer holds no admin rights until they activate a role, the activation is time-bound, optionally approved, justified in writing and fully logged. For any organisation whose auditor asks "who has Global Administrator and why", PIM converts an awkward conversation into a report. It is the strongest single argument for P2 in audited environments, and it is licensed for the administrators it touches rather than the whole organisation.

Access reviews and entitlement management have moved, check before buying

Microsoft now states that using access reviews requires an Entra ID Governance subscription for member users, with some capabilities operating under a P2 subscription, and the same wording covers entitlement management. Much published guidance still lists both as plain P2 features, which is now at best partial. If your reason for upgrading is an access certification programme for an RBI or SEBI audit, establish exactly what P2 alone will give you before committing, because the honest answer is conditional.

How many licences you need, which is not everyone

For PIM, licences are needed for users holding eligible or time-bound role assignments, members and owners under PIM for Groups, approvers, and access review participants. Microsoft's own worked example licenses 53 people in an organisation far larger than that. Access reviews work the other way and need licences for reviewers and for every user being reviewed. This arithmetic is why a scoped P2 purchase for the administrative population is usually the right shape, and a blanket upgrade usually is not.

What happens on lapse, and it differs sharply between features

If P1 or P2 lapses, conditional access policies are not automatically disabled or deleted, they can be viewed and deleted but not updated, so your posture freezes rather than collapsing. PIM does not degrade gracefully: eligible role assignments are removed, ongoing access reviews end, and PIM configuration settings are removed. An organisation that builds its entire administrative model on eligible access and later drops P2 loses that model, which belongs in the decision before you build, not at a renewal three years later.

The problem nobody quotes for

Most Indian P1 tenants have never enabled conditional access.

Before any conversation about upgrading, an honest reading of the market: the most common Entra licensing problem in India is not under-licensing, it is paid-for capability sitting switched off. In the majority of Business Premium and E3 tenants we assess remotely from Hyderabad, the P1 features are unconfigured.

  • Conditional access unconfigured or reduced to a single default policy, which means the tenant is relying on per-user MFA settings or security defaults while paying for a full policy engine. Blocking legacy authentication, requiring MFA outside trusted networks and requiring compliant devices for sensitive apps are all available today at P1 and cost nothing further to enable.
  • Self-service password reset with on-premises writeback disabled, so every forgotten password in a hybrid estate still lands on the helpdesk. This is a P1 capability that typically removes a fifth or more of ticket volume on its own, and most tenants running Entra Connect have never turned it on.
  • Dynamic groups unused, with licence assignment and app access managed by hand-maintained static groups that drift the moment someone changes department. Dynamic membership rules are P1 and they are the difference between a joiner getting the right access on day one and getting it after three tickets.
  • The practical consequence: if your P1 estate is unconfigured, the correct next spend is configuration work, not a P2 upgrade. An organisation that is not using conditional access will not use Identity Protection either, it will just own two unused policy engines instead of one. We say this as a company that would happily sell you the configuration work for either.
Ask us what your tenant already includes
How we advise on this

Four disciplines that make the advice worth having.

Licensing advice usually comes from whoever benefits from the upgrade. We configure and manage Entra tenants for a living, so the incentive exists for us too, which is exactly why the discipline below is stated rather than assumed.

We check what you own first

A large share of organisations asking about P2 have unconfigured P1, and some already hold P2 inside an E5 plan bought for other reasons. Establishing that first regularly ends the conversation without a purchase, which is the correct outcome.

We work from the licensing article

Microsoft moves features between editions, and the access reviews shift toward the Governance SKU is a live example most published advice has missed. Every inclusion claim we make traces to Microsoft's own licensing documentation, conditions reproduced, not simplified.

We scope P2 to the people who need it

PIM licenses eligible administrators, approvers and reviewers, not the organisation. For most Indian businesses the right shape is P1 broadly with standalone P2 for the administrative population, and we do that arithmetic against your actual admin count.

Remote-first from Gachibowli, Hyderabad

The whole engagement, tenant assessment, licence mapping, conditional access and PIM configuration, runs remotely from our Gachibowli, Hyderabad base for clients across India, with a written recommendation you can hand to finance or an auditor.

Decision scenarios

Six Indian situations and what we would usually recommend.

In half of these the recommendation is not to buy P2, which is roughly the honest real-world ratio once you establish what an organisation already holds and whether anyone would use the additions.

A 50-person SMB on Business Premium

P1 is already in the plan. The recommendation is almost never P2: it is to enable conditional access, block legacy authentication, turn on SSPR with writeback and use what is already paid for. Buying P2 before configuring P1 purchases a second unused policy engine.

An audited BFSI or fintech firm

Where RBI, SEBI or IRDAI expectations cover privileged access and periodic access certification, P2 justifies itself through PIM and review capability, licensed for the administrative population. Check the Governance SKU position on access reviews before finalising scope.

A hybrid estate still running on-premises AD

P1 is the minimum sensible position, for conditional access in front of cloud apps, SSPR writeback so password resets flow back to AD, and Connect Health watching the sync layer. P2 becomes relevant once the admin population and audit exposure grow.

An organisation already on E5

You own P2 and quite possibly have never enabled Identity Protection or PIM. This is the most common waste we see in Indian Microsoft estates: capability paid for, switched off, and a separate security purchase proposed to solve a problem the existing licence covers. The work is configuration, not procurement.

An IT services or SaaS company facing client security reviews

Client due-diligence questionnaires increasingly ask how privileged access is controlled and whether access is periodically reviewed. PIM plus a scoped review process answers both with evidence, and a subset P2 purchase for the engineering admin population is usually enough.

A small team with no security operations

P2 buys risk detection, and detection with no responder changes nothing. If nobody would act on a risky sign-in alert on a Friday night, spend on prevention instead: strong conditional access and device compliance at P1, and revisit P2 when someone can receive the signal.

Feature by feature

What each plan includes, with no prices attached.

Plan inclusion is a published Microsoft product fact. The rows below are the ones that actually decide the P1 vs P2 question for Indian organisations, and the access review rows carry Microsoft's current conditional wording rather than the simplified yes you will find in older comparisons.
Feature
Entra ID P1
Inside Business Premium and E3
Entra ID P2
Inside E5, or standalone
Conditional access
Policy engine for every sign-in: block, require MFA, require compliant device.
IncludedIncluded
SSPR with on-premises writeback
Self-service password reset that syncs back to on-premises AD.
IncludedIncluded
Dynamic groups
Rule-based group membership for licensing and app assignment.
IncludedIncluded
Hybrid identity with Entra Connect Health
Monitoring and alerting for the sync layer in hybrid AD estates.
IncludedIncluded
Identity Protection risk policies
Risk-based conditional access on sign-in risk and user risk signals.
Not included, P2 onlyIncluded
Full risk reports and alerting
Risky users and sign-ins with detail, history, alerts and weekly digest.
Limited view onlyIncluded
Privileged Identity Management
Just-in-time, time-bound, approved and logged admin elevation.
Not included, P2 onlyIncluded
Access reviews
Periodic certification of who holds which access.
Not includedSome capabilities, full feature needs the Governance SKU
Entitlement management
Access packages with approval workflows and expiry.
Not includedSome capabilities, full feature needs the Governance SKU
Feature by edition

Free, P1 and P2 side by side.

Taken from the Microsoft Entra licensing documentation. Where Microsoft describes a capability as limited rather than absent, the table says limited, because the difference between limited and none is exactly what this decision turns on.
CapabilityFreeP1P2
Cloud SSO and basic MFAYesYesYes
Conditional access policiesNoYesYes
Risk-based conditional accessNoNoYes
Identity Protection risk reportsLimitedLimited, no detail or historyFull
Privileged Identity ManagementNoNoYes
Access reviewsNoNoSome capabilities, Governance SKU for the full feature
Entitlement managementNoNoSome capabilities, Governance SKU for the full feature
Self-service password resetCloud onlyWith on-premises writebackWith on-premises writeback
Dynamic groupsNoYesYes
Entra Connect (hybrid sync)YesYesYes
Entra Connect HealthNoYesYes
Custom RBAC rolesNoYesYes
Audit and sign-in logsYesYesYes
How we work the decision

Five steps, and it often ends at step two.

Typically one to two weeks of elapsed time, delivered remotely from Hyderabad, and most of it is spent establishing what you already hold and whether it is configured. That is deliberately the cheapest question, so it is asked first.
  1. 1

    Map what your users actually hold

    2-3 days

    Which plans, how many of each, and whether any group already carries P2 through E5 or EMS E5. This regularly surfaces entitlement nobody knew about, and it is the necessary baseline, you cannot evaluate an upgrade without knowing the starting point.

  2. 2

    Check whether P1 is configured

    2-3 days

    Conditional access coverage, legacy authentication blocking, SSPR writeback, dynamic groups, Connect Health. If these are unconfigured, that is the work, and we say so rather than proceeding to a P2 conversation.

  3. 3

    Test the P2 case honestly

    1-2 days

    Two questions decide it: would anyone act on risk signals, and are there enough administrators for eligible access to be meaningful. If either answer is no, P2 buys reporting rather than protection, and that is a legitimate finding.

  4. 4

    Do the licence arithmetic

    1-2 days

    For PIM, the eligible admins plus approvers plus reviewers. For access reviews, reviewers plus reviewed users, and a check on whether the Governance SKU rather than P2 is what the feature now requires. This usually produces a smaller number than a blanket upgrade.

  5. 5

    Decide, configure, record why

    3-5 days

    A written recommendation with reasoning and licence counts for finance or your auditor. Where the answer is to upgrade, we configure what you buy, because P2 with Identity Protection and PIM left switched off is exactly the waste this exercise exists to prevent.

Straight answers

Entra ID P1 vs P2, frequently asked.

Yes, comfortably. Conditional access is a P1 feature, and it is the right way to enforce MFA: require it outside trusted locations, block legacy authentication that bypasses it, and demand compliant devices for sensitive applications. Nothing about MFA enforcement requires P2. What P2 changes is that the MFA challenge can be triggered by a calculated risk score instead of a static rule, which is valuable but is a refinement of an already strong control, not a prerequisite for it.

Two capabilities genuinely. First, Identity Protection: machine-scored sign-in risk and user risk, full risk reports with history and alerting, and the ability to build conditional access policies on those scores so risky sign-ins are blocked or remediated automatically. Second, Privileged Identity Management: administrators hold eligible rather than permanent roles, activate them time-bound with approval and justification, and every elevation is logged. Access review and entitlement management capability also surfaces at P2, but Microsoft now ties the full feature to the separate Entra ID Governance subscription, so treat that one as conditional.

Yes, and it is usually the right answer. Entra licensing is per user, so a company on Business Premium or E3 can add standalone P2 for the specific people who need it: the administrators managed through PIM, approvers and access reviewers. Microsoft's own PIM licensing example covers a subset of the organisation, not all of it. The one capability that argues for broad P2 coverage is risk-based conditional access, since it protects ordinary users, so the shape of the split depends on which feature is driving the purchase.

Entra ID Governance is a separate subscription that Microsoft now positions as the home of identity governance: access reviews, entitlement management and lifecycle workflows. The licensing documentation states that using access reviews requires a Governance subscription for member users, with some capabilities operating under P2. If your driver is an access certification programme rather than risk detection, the comparison you actually need is P1 plus Governance versus P2, not P1 versus P2, and our sister page on Entra ID Governance covers that decision in full.

No, and it is worth being precise about this. ISO 27001 access control requirements ask you to restrict privileged access, review access rights periodically and remove access on role change, they do not name any Microsoft SKU. A well-run P1 tenant with documented conditional access, disciplined group management and a manual quarterly access review can pass. What P2 changes is the cost of evidence: PIM turns "who has admin and why" into a report, and automated reviews replace spreadsheet certification. Auditors accept both, one just takes far more of your time every cycle.

In order: confirm you hold P1, which you do if you run Business Premium. Enable security defaults or, better, build three conditional access policies: require MFA for everyone outside trusted networks, block legacy authentication, require compliant or registered devices for email and files. Turn on SSPR, with writeback if you have on-premises AD. Then stop and run on that for a quarter. If afterwards you have a real administrative population, client security questionnaires or an audit on the horizon, revisit P2 for that subset. Most small Indian companies never need to go past step four.

Three places, ten minutes. In the Microsoft 365 admin centre under Billing and Licenses, look at which plans your users hold, Business Premium and E3 mean P1, E5 means P2. In the Entra admin centre, the Overview page states the tenant licence level. And under Protection, if Identity Protection shows full risk reports rather than a limited view, P2 is present. We do this as the first step of every engagement, and for a meaningful share of clients this single check reveals either unused P2 inside E5 or unconfigured P1, and redirects the whole conversation.

Yes, and it is the most common engagement this page produces. Configuration-only work covers conditional access policy design and rollout, legacy authentication blocking, SSPR with writeback, dynamic group builds, and at P2, Identity Protection risk policies tuned so they protect without locking people out, and PIM with eligible roles, approvers and break-glass accounts. Delivered remotely from our Gachibowli, Hyderabad base, phased so users are never surprised, with a response SLA of 30 minutes if you move onto a managed identity arrangement afterwards.

Worse than most people assume, and unevenly. Conditional access policies survive a lapse in a frozen state, they are not disabled or deleted, and can be viewed and removed but not updated. PIM does not survive it: eligible role assignments are removed, ongoing access reviews end and PIM configuration settings are removed. So an administrative model built on eligible access does not freeze, it unwinds, and the administrators quietly need permanent roles again. If P2 is going onto a one-year budget line, that asymmetry belongs in the renewal plan from day one.

It sets the floor at P1. A hybrid estate needs conditional access in front of cloud applications, SSPR with on-premises writeback so resets flow back to AD, and Entra Connect Health watching the sync layer, all P1 features. Entra Connect itself is free, but running hybrid without Connect Health means sync failures surface as user complaints rather than alerts. P2 remains a separate question about risk policies and privileged access, and hybrid neither requires it nor rules it out.

The frameworks that govern audited sectors describe outcomes that P2 features map to directly. RBI guidance for banks and NBFCs expects privileged access to be restricted, monitored and logged. SEBI's cyber framework for regulated entities expects periodic review of access rights. CERT-In directions expect log retention that identity audit trails feed. None of these name a Microsoft SKU, and each can be met other ways, but PIM and structured access reviews are the lowest-friction Microsoft-native answer, which is why audited BFSI is the clearest P2 case in India.

Staged, not switched. First, exhaust P1: full conditional access coverage, legacy authentication blocked, SSPR writeback live, dynamic groups driving assignment. Second, add standalone P2 for the administrative population only and stand up PIM with eligible roles, approvers and two break-glass accounts, since privileged access is where audit pressure lands first. Third, extend P2 to ordinary users if and when risk-based conditional access is genuinely wanted and someone will own the risk queue. Fourth, if access certification becomes a programme, price the Governance SKU against your review population before assuming P2 covers it. Each stage is reversible except the PIM dependency, so treat that one as the commitment it is.

One to two weeks of elapsed time for the full review, most of it establishing what you hold and whether it is configured. The first conversation costs nothing: tell us your plan mix and admin headcount and we will tell you which side of the P1 vs P2 line you likely sit on, and whether the Governance SKU belongs in your comparison at all. We reply to enquiries within 4 business hours, and every engagement ends with a written recommendation you can act on with or without us.
Work the decision properly

Fifteen questions that settle P1 vs P2.

The first group establishes what you already hold, the second tests whether P2 capability would actually be used, and the third is the arithmetic. In our experience the first group ends the conversation for a meaningful share of Indian organisations, in the direction of configuring what they own.

What you already have

  • Which Microsoft 365 plans do your users hold?
    Business Premium, E3, F1 and F3 all include P1.
  • Does any group already hold E5 or EMS E5?
    Those include P2, and it may be sitting unused.
  • Is conditional access configured beyond defaults?
    If not, you have unused P1 before P2 enters the picture.
  • Is SSPR with writeback enabled for your hybrid users?
    A P1 feature that cuts helpdesk volume immediately.
  • Are dynamic groups driving licence and app assignment?
    P1, and the cure for hand-maintained group drift.

Would you use what P2 adds

  • Do you want risky sign-ins blocked automatically, not just reported?
    That is Identity Protection, and it is the P2 headline.
  • Would anybody act on a risk alert at 11pm on a Friday?
    Detection without a responder changes nothing.
  • Do you have enough administrators for eligible access to mean something?
    PIM earns its place at scale, not at two admins.
  • Does an auditor ask who holds privileged access and why?
    RBI, SEBI and ISO 27001 audits all do. PIM answers with a report.
  • Are you buying P2 specifically for access reviews?
    Check the Governance SKU position first, that feature has moved.

The arithmetic

  • How many administrators would PIM actually manage?
    Licence the eligible admins, approvers and reviewers, not the company.
  • If reviewing access, how many users would be reviewed?
    Reviewed users need licences too, which changes the count sharply.
  • Could P2 cover a subset instead of everyone?
    Standalone P2 on top of Business Premium or E3 is a supported shape.
  • Is E5 already justified for other reasons?
    If Defender and Purview arguments stack up, P2 rides along.
  • What breaks if P2 lapses at renewal?
    PIM eligible assignments are removed, not frozen. Plan for it.
References

Official documentation

Next step

Find out what you already own before comparing anything.

A meaningful share of the organisations that ask us about P2 already hold it inside an E5 plan, or have never configured the P1 they pay for. That first answer is free, takes one conversation, and frequently ends the question without a purchase. We reply within 4 business hours.