Entra ID P1 vs P2 comes down to £2.30 per user per month, £5.40 against £7.70 on annual commitment. Every comparison you will read answers that by listing what P2 unlocks, which is the wrong question. The bill is decided by how many P2 licences Microsoft’s own documentation obliges you to buy, and by the fact that several capabilities still filed under P2 in those tables now require a separate Entra ID Governance subscription.
What the two plans cost
Prices from the Microsoft Entra plans and pricing page, checked on 14 August 2026. Every figure is quoted as “paid yearly (annual commitment)”.
| Plan | Per user per month (GBP) | Per user per month (USD) |
|---|---|---|
| Microsoft Entra ID Free | Included with a Microsoft cloud subscription | Included |
| Microsoft Entra ID P1 | £5.40 | $7.00 |
| Microsoft Entra ID P2 | £7.70 | $10.00 |
| Microsoft Entra ID Governance | £5.40 | $7.00 |
| Microsoft Entra Suite | £9.20 | $12.00 |
Two things in that table are more important than the P1 to P2 gap. Governance costs the same as P1 and is an add-on rather than a replacement, so a governance programme is P1 plus Governance at £10.80, not a step up to P2 at £7.70. And Entra Suite requires a P1 subscription underneath it, so £9.20 is an uplift on a base you are already paying for. If you are designing Zero Trust architecture on Microsoft Entra ID, the plan boundary is the first constraint on the design, not an afterthought at renewal.
Check whether you already own P2
Per Microsoft Entra licensing on Microsoft Learn, last updated 18 June 2026:
- P1 is included with Microsoft 365 E3, E5 and E7, Microsoft 365 F1 and F3, Enterprise Mobility + Security E3, and Microsoft 365 Business Premium.
- P2 is included with Microsoft 365 E5 and E7, Microsoft Defender Suite (formerly Microsoft 365 E5 Security), Microsoft Defender Suite FLW, Microsoft Defender + Purview Suite FLW, and Enterprise Mobility + Security E5.
If your tenant is on E5, this comparison is already settled and the money is spent. The people who need an answer are on E3, on Business Premium, or holding a mixed estate. That decision sits next to the one covered in Microsoft 365 E3 vs E5, because buying E5 for the identity features alone is usually the more expensive route to the same P2 entitlement.
Worth knowing
Any comparison table that lists “Microsoft 365 E5 Security” and has never heard of E7 is describing a bundle list Microsoft has since changed. That is the quickest staleness test you can run on someone else’s licensing post, including the ones currently ranking for this term.
Entra ID P1 vs P2: what the uplift actually buys
P1 buys Conditional Access, single sign-on, multifactor authentication, advanced group management including dynamic groups, and the advanced security and usage reports. The Conditional Access overview on Microsoft Learn, last updated 27 April 2026, states plainly that “Using this feature requires Microsoft Entra ID P1 licenses”, and confirms Business Premium customers can use it too.
P2 adds Microsoft Entra ID Protection and Privileged Identity Management. The distinction most tables get wrong is that P1 is not blind to risk, it is partially sighted. From the ID Protection overview, last updated 30 October 2025:
| Capability | Free | P1 | P2 |
|---|---|---|---|
| Risk policies (sign-in risk and user risk) | No | No | Yes |
| Risky users report | Medium and high only, no detail | Medium and high only, no detail | Full |
| Risky sign-ins report | No risk detail or level | No risk detail or level | Full |
| Risk detections | No | Limited, no details drawer | Full |
| Users at risk alerts and weekly digest | No | No | Yes |
| MFA registration policy | No | No | Yes |
| Risk data through Microsoft Graph | No | No | Yes |
So on P1 you can see that a user is at medium or high risk. You cannot see why, you cannot pull the risk state through Graph to feed a SIEM, and you cannot make Conditional Access act on it without a human in the loop. Risk-based Conditional Access requires ID Protection, which is a P2 feature. That single automation gap, not the reporting detail, is what people are actually buying.
P2 also carries the whole of Privileged Identity Management: PIM for Microsoft Entra roles, PIM for Azure resources, PIM for Groups, and the PIM Conditional Access controls. If your Azure estate is built on Entra ID centric RBAC, PIM is the control that turns a standing subscription Owner assignment into an activation with an approval and an expiry, and there is no P1 equivalent.
What is not in P2, whatever the tables say
This is the section that costs money. A large amount of what circulates as “P2 gives you identity governance” has been carved into the separate Microsoft Entra ID Governance subscription. From the Entra ID Governance licensing fundamentals page, last updated 29 July 2026:
| Capability | P2 | Governance |
|---|---|---|
| Entitlement management for groups, teams, applications, SharePoint sites | Yes | Yes |
| Entra roles in access packages, auto-assignment policies, custom extensions, sponsors as approvers, mark guest as governed | No | Yes |
| Access reviews of users, groups and applications | Yes | Yes |
| Access reviews scoped to inactive users only | No | Yes |
| Machine learning assisted certifications, PIM for Groups reviews, catalog access reviews | No | Yes |
| Lifecycle Workflows, in full | No | Yes |
| Privileged Identity Management | Yes | Yes |
Lifecycle Workflows is the one that catches people. Joiner, mover and leaver automation is the reason most organisations start looking at P2 in the first place, and it is not in P2 at all. The access reviews overview page, last updated 12 March 2026, is blunter still: “This feature requires Microsoft Entra ID Governance or Microsoft Entra Suite subscriptions, for your organization’s users. Some capabilities, within this feature, may operate with a Microsoft Entra ID P2 subscription.” That sentence has the default the wrong way round from where most comparison posts leave it.
The licence maths nobody does before the renewal
Microsoft’s governance licensing page does something unusual: it counts for you, with worked examples. Every one of them counts the population in scope, not the administrators.
- Access reviews. “An administrator creates an access review of Group A with 75 member users and 1 group owner, and assigns the group owner as the reviewer.” The stated answer is 76 licences. Reviewers count, and so does everyone being reviewed.
- Entitlement management. A policy that says all 2,000 employees can request an access package needs 2,000 licences, even though only 150 employees actually requested it. The entitlement to request is what is licensed, not the request.
- Lifecycle Workflows. One administrator plus 400 new hires processed across the year is 401 licences.
- PIM. The requirement covers users with eligible or time-bound assignments, users able to approve or reject activation requests, users assigned to an access review, and users who perform access reviews.
Guests are billed differently again. Entra ID Governance uses monthly active user billing for guest users, which requires an Azure subscription, and the monthly bill carries a record for each guest with one or more governance actions that month. If you run a large external collaboration estate, that is a separate line item with a separate owner, and it behaves nothing like the per-seat model. The same warning applies to any tenant leaning on Entra External ID for customer-facing applications, where the guest population can be larger than the employee population by an order of magnitude.
The Conditional Access documentation does not enumerate who must be licensed the way the governance pages do. I would not read the silence as permission. When one product family spells out that reviewers and approvers count and the neighbouring one says nothing, the safe assumption is that the counting unit is whoever benefits from the feature, and the place to settle it is your licensing desk rather than a blog.
The failure modes
I have not run any of these at scale. My tenant is a lab with no enrolled devices, so what follows is what the documentation commits Microsoft to, and where I would expect it to bite.
P2 bought for the admins, risk policy scoped to All users. Nothing stops you. The portal is not a licence enforcement engine, so the policy saves, applies and works. The failure surfaces at a licensing audit, months later, priced retrospectively across the whole population the policy touched. This is the single most common way the P1 to P2 decision goes wrong, and it goes wrong silently.
The licence lapses and nothing breaks. The Conditional Access overview is explicit: “When the licenses required for Conditional Access expire, policies aren’t automatically disabled or deleted. This graceful state lets customers migrate away from Conditional Access policies without a sudden change in their security posture. You can view and delete remaining policies, but you can’t update them.” Read that carefully. You do not discover the lapse when protection stops, because it does not stop. You discover it during an incident, when you try to edit a policy and cannot.
Designing joiner, mover and leaver on P2. The design review passes, the budget is approved, and Lifecycle Workflows turns out to need a second subscription at £5.40 per user per month across everyone the workflows touch. Price Governance at design time or the project stalls at procurement.
Business Premium mistaken for P2. Business Premium includes P1 and can use Conditional Access. It does not include P2, so there is no risk-based Conditional Access, no PIM and no full ID Protection reporting. The gap is easy to miss because Conditional Access works perfectly well right up until you try to add a sign-in risk condition.
What I would do differently
Decide by driver, not by feature count.
If the driver is risk-based Conditional Access, buy P2 for the population you will genuinely scope the policy to, and accept that in most tenants that is everyone. A risk policy limited to administrators protects the accounts least likely to be phished at volume and leaves the rest of the tenant exactly where it was. Partial P2 here is a false economy dressed as prudence.
If the driver is PIM for a handful of privileged accounts, partial P2 is defensible, and it is the only case where it clearly is. Licence the eligible users, the approvers and the reviewers, and stop there.
If the driver is governance, joiner mover leaver, access certification, entitlement management at any depth, price Microsoft Entra ID Governance first and treat P2 as the secondary question. Governance is where the capability lives and where the per-head cost lands.
The £2.30 gap is not the decision. The decision is whether you are about to buy a second subscription you have not budgeted for, and whether you have counted the reviewers.
Last verified: 14 August 2026, against microsoft.com and learn.microsoft.com.



