P1 is conditional access for everyone. P2 is risk policies, PIM and reviews for the audited.
That is the whole decision in one line. Entra ID P1, which most Indian organisations already own inside Microsoft 365 Business Premium or E3, gives you conditional access, hybrid identity and self-service password reset with writeback. P2 adds Identity Protection risk policies, Privileged Identity Management and access review capability, and it earns its keep when a regulator, an auditor or a mature security programme will actually use those three. We help you establish which side of that line you are on before anyone quotes you an upgrade.
- P1Already in Business Premium and E3
- P2In E5, or standalone per user
- 2 featuresGenuinely new at P2
- Most tenantsNever enable what P1 includes
Eight things to establish before you buy either plan.
Where P1 comes from, usually a plan you already pay for
Entra ID P1 is included in Microsoft 365 Business Premium, in E3 and E5, in the frontline F1 and F3 plans, and in Enterprise Mobility and Security E3. If your organisation runs Business Premium, which is the default for Indian SMBs on Microsoft, every licensed user already holds P1. The first question in any P1 vs P2 conversation is therefore not "which should we buy" but "what do we already own", and the answer surprises most of the organisations that ask us.
Where P2 comes from, E5 or a standalone add-on
Entra ID P2 is included in Microsoft 365 E5 and Enterprise Mobility and Security E5, and is available as a standalone per-user licence on top of whatever you run today. That standalone route matters in India, where many organisations sit on Business Premium or E3 and need P2 capabilities for a subset of users only. You do not need to move the whole company to E5 to get PIM for twelve administrators, and anyone proposing that should be asked to justify it.
What P1 gives you: conditional access, the control that matters most
Conditional access is the policy engine that evaluates every sign-in against user, location, device and application, and then blocks it, requires MFA, or requires a compliant device. It is the single highest-value identity control in the Microsoft stack, it is the backbone of every zero-trust rollout, and it is a P1 feature. So are self-service password reset with on-premises writeback, dynamic groups, group-based application assignment, and Entra Connect Health for monitoring hybrid sync.
The first genuine P2 addition: Identity Protection risk policies
Identity Protection scores every sign-in and every user for risk, using signals like impossible travel, anonymised IP addresses, leaked credentials and unfamiliar sign-in properties. At P2 you can build conditional access policies on those scores, so a high-risk sign-in is blocked or forced through MFA and a password reset automatically, without an engineer watching a dashboard. At P1 you get a limited view of risky users with no detail drawer and no history, which tells you something happened without telling you what.
The second: Privileged Identity Management
PIM replaces standing administrator access with eligible access. An engineer holds no admin rights until they activate a role, the activation is time-bound, optionally approved, justified in writing and fully logged. For any organisation whose auditor asks "who has Global Administrator and why", PIM converts an awkward conversation into a report. It is the strongest single argument for P2 in audited environments, and it is licensed for the administrators it touches rather than the whole organisation.
Access reviews and entitlement management have moved, check before buying
Microsoft now states that using access reviews requires an Entra ID Governance subscription for member users, with some capabilities operating under a P2 subscription, and the same wording covers entitlement management. Much published guidance still lists both as plain P2 features, which is now at best partial. If your reason for upgrading is an access certification programme for an RBI or SEBI audit, establish exactly what P2 alone will give you before committing, because the honest answer is conditional.
How many licences you need, which is not everyone
For PIM, licences are needed for users holding eligible or time-bound role assignments, members and owners under PIM for Groups, approvers, and access review participants. Microsoft's own worked example licenses 53 people in an organisation far larger than that. Access reviews work the other way and need licences for reviewers and for every user being reviewed. This arithmetic is why a scoped P2 purchase for the administrative population is usually the right shape, and a blanket upgrade usually is not.
What happens on lapse, and it differs sharply between features
If P1 or P2 lapses, conditional access policies are not automatically disabled or deleted, they can be viewed and deleted but not updated, so your posture freezes rather than collapsing. PIM does not degrade gracefully: eligible role assignments are removed, ongoing access reviews end, and PIM configuration settings are removed. An organisation that builds its entire administrative model on eligible access and later drops P2 loses that model, which belongs in the decision before you build, not at a renewal three years later.
Most Indian P1 tenants have never enabled conditional access.
Before any conversation about upgrading, an honest reading of the market: the most common Entra licensing problem in India is not under-licensing, it is paid-for capability sitting switched off. In the majority of Business Premium and E3 tenants we assess remotely from Hyderabad, the P1 features are unconfigured.
- Conditional access unconfigured or reduced to a single default policy, which means the tenant is relying on per-user MFA settings or security defaults while paying for a full policy engine. Blocking legacy authentication, requiring MFA outside trusted networks and requiring compliant devices for sensitive apps are all available today at P1 and cost nothing further to enable.
- Self-service password reset with on-premises writeback disabled, so every forgotten password in a hybrid estate still lands on the helpdesk. This is a P1 capability that typically removes a fifth or more of ticket volume on its own, and most tenants running Entra Connect have never turned it on.
- Dynamic groups unused, with licence assignment and app access managed by hand-maintained static groups that drift the moment someone changes department. Dynamic membership rules are P1 and they are the difference between a joiner getting the right access on day one and getting it after three tickets.
- The practical consequence: if your P1 estate is unconfigured, the correct next spend is configuration work, not a P2 upgrade. An organisation that is not using conditional access will not use Identity Protection either, it will just own two unused policy engines instead of one. We say this as a company that would happily sell you the configuration work for either.
Four disciplines that make the advice worth having.
We check what you own first
A large share of organisations asking about P2 have unconfigured P1, and some already hold P2 inside an E5 plan bought for other reasons. Establishing that first regularly ends the conversation without a purchase, which is the correct outcome.
We work from the licensing article
Microsoft moves features between editions, and the access reviews shift toward the Governance SKU is a live example most published advice has missed. Every inclusion claim we make traces to Microsoft's own licensing documentation, conditions reproduced, not simplified.
We scope P2 to the people who need it
PIM licenses eligible administrators, approvers and reviewers, not the organisation. For most Indian businesses the right shape is P1 broadly with standalone P2 for the administrative population, and we do that arithmetic against your actual admin count.
Remote-first from Gachibowli, Hyderabad
The whole engagement, tenant assessment, licence mapping, conditional access and PIM configuration, runs remotely from our Gachibowli, Hyderabad base for clients across India, with a written recommendation you can hand to finance or an auditor.
Six Indian situations and what we would usually recommend.
A 50-person SMB on Business Premium
P1 is already in the plan. The recommendation is almost never P2: it is to enable conditional access, block legacy authentication, turn on SSPR with writeback and use what is already paid for. Buying P2 before configuring P1 purchases a second unused policy engine.
An audited BFSI or fintech firm
Where RBI, SEBI or IRDAI expectations cover privileged access and periodic access certification, P2 justifies itself through PIM and review capability, licensed for the administrative population. Check the Governance SKU position on access reviews before finalising scope.
A hybrid estate still running on-premises AD
P1 is the minimum sensible position, for conditional access in front of cloud apps, SSPR writeback so password resets flow back to AD, and Connect Health watching the sync layer. P2 becomes relevant once the admin population and audit exposure grow.
An organisation already on E5
You own P2 and quite possibly have never enabled Identity Protection or PIM. This is the most common waste we see in Indian Microsoft estates: capability paid for, switched off, and a separate security purchase proposed to solve a problem the existing licence covers. The work is configuration, not procurement.
An IT services or SaaS company facing client security reviews
Client due-diligence questionnaires increasingly ask how privileged access is controlled and whether access is periodically reviewed. PIM plus a scoped review process answers both with evidence, and a subset P2 purchase for the engineering admin population is usually enough.
A small team with no security operations
P2 buys risk detection, and detection with no responder changes nothing. If nobody would act on a risky sign-in alert on a Friday night, spend on prevention instead: strong conditional access and device compliance at P1, and revisit P2 when someone can receive the signal.
What each plan includes, with no prices attached.
| Feature | Entra ID P1 Inside Business Premium and E3 | Entra ID P2 Inside E5, or standalone |
|---|---|---|
Conditional access Policy engine for every sign-in: block, require MFA, require compliant device. | Included | Included |
SSPR with on-premises writeback Self-service password reset that syncs back to on-premises AD. | Included | Included |
Dynamic groups Rule-based group membership for licensing and app assignment. | Included | Included |
Hybrid identity with Entra Connect Health Monitoring and alerting for the sync layer in hybrid AD estates. | Included | Included |
Identity Protection risk policies Risk-based conditional access on sign-in risk and user risk signals. | Not included, P2 only | Included |
Full risk reports and alerting Risky users and sign-ins with detail, history, alerts and weekly digest. | Limited view only | Included |
Privileged Identity Management Just-in-time, time-bound, approved and logged admin elevation. | Not included, P2 only | Included |
Access reviews Periodic certification of who holds which access. | Not included | Some capabilities, full feature needs the Governance SKU |
Entitlement management Access packages with approval workflows and expiry. | Not included | Some capabilities, full feature needs the Governance SKU |
Free, P1 and P2 side by side.
| Capability | Free | P1 | P2 | |
|---|---|---|---|---|
| Cloud SSO and basic MFA | Yes | Yes | Yes | |
| Conditional access policies | No | Yes | Yes | |
| Risk-based conditional access | No | No | Yes | |
| Identity Protection risk reports | Limited | Limited, no detail or history | Full | |
| Privileged Identity Management | No | No | Yes | |
| Access reviews | No | No | Some capabilities, Governance SKU for the full feature | |
| Entitlement management | No | No | Some capabilities, Governance SKU for the full feature | |
| Self-service password reset | Cloud only | With on-premises writeback | With on-premises writeback | |
| Dynamic groups | No | Yes | Yes | |
| Entra Connect (hybrid sync) | Yes | Yes | Yes | |
| Entra Connect Health | No | Yes | Yes | |
| Custom RBAC roles | No | Yes | Yes | |
| Audit and sign-in logs | Yes | Yes | Yes |
Five steps, and it often ends at step two.
- 1
Map what your users actually hold
2-3 days
Which plans, how many of each, and whether any group already carries P2 through E5 or EMS E5. This regularly surfaces entitlement nobody knew about, and it is the necessary baseline, you cannot evaluate an upgrade without knowing the starting point.
- 2
Check whether P1 is configured
2-3 days
Conditional access coverage, legacy authentication blocking, SSPR writeback, dynamic groups, Connect Health. If these are unconfigured, that is the work, and we say so rather than proceeding to a P2 conversation.
- 3
Test the P2 case honestly
1-2 days
Two questions decide it: would anyone act on risk signals, and are there enough administrators for eligible access to be meaningful. If either answer is no, P2 buys reporting rather than protection, and that is a legitimate finding.
- 4
Do the licence arithmetic
1-2 days
For PIM, the eligible admins plus approvers plus reviewers. For access reviews, reviewers plus reviewed users, and a check on whether the Governance SKU rather than P2 is what the feature now requires. This usually produces a smaller number than a blanket upgrade.
- 5
Decide, configure, record why
3-5 days
A written recommendation with reasoning and licence counts for finance or your auditor. Where the answer is to upgrade, we configure what you buy, because P2 with Identity Protection and PIM left switched off is exactly the waste this exercise exists to prevent.
Entra ID P1 vs P2, frequently asked.
Fifteen questions that settle P1 vs P2.
What you already have
- Which Microsoft 365 plans do your users hold?Business Premium, E3, F1 and F3 all include P1.
- Does any group already hold E5 or EMS E5?Those include P2, and it may be sitting unused.
- Is conditional access configured beyond defaults?If not, you have unused P1 before P2 enters the picture.
- Is SSPR with writeback enabled for your hybrid users?A P1 feature that cuts helpdesk volume immediately.
- Are dynamic groups driving licence and app assignment?P1, and the cure for hand-maintained group drift.
Would you use what P2 adds
- Do you want risky sign-ins blocked automatically, not just reported?That is Identity Protection, and it is the P2 headline.
- Would anybody act on a risk alert at 11pm on a Friday?Detection without a responder changes nothing.
- Do you have enough administrators for eligible access to mean something?PIM earns its place at scale, not at two admins.
- Does an auditor ask who holds privileged access and why?RBI, SEBI and ISO 27001 audits all do. PIM answers with a report.
- Are you buying P2 specifically for access reviews?Check the Governance SKU position first, that feature has moved.
The arithmetic
- How many administrators would PIM actually manage?Licence the eligible admins, approvers and reviewers, not the company.
- If reviewing access, how many users would be reviewed?Reviewed users need licences too, which changes the count sharply.
- Could P2 cover a subset instead of everyone?Standalone P2 on top of Business Premium or E3 is a supported shape.
- Is E5 already justified for other reasons?If Defender and Purview arguments stack up, P2 rides along.
- What breaks if P2 lapses at renewal?PIM eligible assignments are removed, not frozen. Plan for it.
The pages around this decision.
Microsoft Entra ID
The identity platform itself: SSO, MFA, conditional access design, hybrid sync and managed identity operations, whichever plan you land on.
Learn moreEntra ID Governance
Access reviews, entitlement management and lifecycle workflows, and when the Governance SKU rather than P2 is the licence your programme actually needs.
Learn moreMicrosoft Licence Audit
The wider estate question: unused seats, plan right-sizing and add-on overlap across your whole Microsoft agreement, not just the Entra line.
Learn moreFind out what you already own before comparing anything.
A meaningful share of the organisations that ask us about P2 already hold it inside an E5 plan, or have never configured the P1 they pay for. That first answer is free, takes one conversation, and frequently ends the question without a purchase. We reply within 4 business hours.
Related Services
Explore more solutions that work great with this service