We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Entra ID P1 or P2
Entra ID P1 or P2, UAE

P2 buys you two things. Most advice about it is out of date.

The genuine P2 additions are risk-based policies through Identity Protection and Privileged Identity Management. Access reviews and entitlement management have moved toward requiring Entra ID Governance, which a lot of published guidance has not caught up with. We work the decision from the licensing article itself.

Book a licensing and capability reviewSee what actually changes
Microsoft Entra ID P1 versus P2 licensing decision for UAE organisations
  • P2 adds two thingsID Protection and PIM
  • Governance movedAccess reviews are not simply P2
  • Not everyonePIM licenses eligible admins only
  • Expiry differsPIM removes assignments, CA does not
What the licence actually determines

Eight things to establish before anybody quotes you for an upgrade.

Everything below is taken from the Microsoft Entra licensing article rather than from commentary. That matters here more than on most subjects, because Microsoft has moved several capabilities between editions and a great deal of published advice describes an arrangement that no longer holds.

What you already hold, which is usually more than you think

Microsoft states that Entra ID P1 is included with Microsoft 365 E3, E5 and E7, with F1 and F3, with Enterprise Mobility and Security E3, and in Microsoft 365 Business Premium. P2 is included with Microsoft 365 E5 and E7, with the Microsoft Defender Suite formerly called Microsoft 365 E5 Security, and with Enterprise Mobility and Security E5. A surprising number of UAE organisations are entitled to capabilities they have never enabled.

The first genuine P2 addition: Identity Protection

Risk-based conditional access, meaning sign-in risk and user risk policies, requires Entra ID Protection, which is a P2 feature. This is the capability most often assumed to be present at P1 and it is not. If your security plan includes blocking risky sign-ins automatically, that plan requires P2 and no amount of configuration at P1 will produce it.

The second: Privileged Identity Management

PIM provides eligible rather than permanent administrative access, so a role is activated when needed and expires afterwards, with approval and an audit trail. Microsoft states you need either Entra ID Governance or Entra ID P2 licences to use PIM and all its settings. For an organisation with a meaningful number of administrators this is usually the strongest single argument for P2.

Access reviews and entitlement management have moved

This is the change most published guidance has missed. Microsoft now states that using access reviews requires an Entra ID Governance subscription for member users, and that some capabilities might operate with a P2 subscription. The same wording appears for entitlement management. If you are considering P2 specifically to get access reviews, check what you would actually receive rather than relying on an article written two years ago.

What P1 gives you of Identity Protection, which is not nothing

A useful nuance. At P1 the risky users report shows only medium and high risk users with no details drawer and no risk history, and risky sign-ins show no risk detail or risk level. Risk detections at P1 are limited with no details drawer. So P1 tells you something is happening without telling you what. Whether that partial view is enough is a real question rather than a formality.

How many licences you actually need, which is not everyone

For PIM, licences are needed for users with eligible or time-bound role assignments, members and owners under PIM for Groups, anybody who can approve or reject activation requests, and anyone assigned to or performing an access review. Microsoft own worked example totals 42 eligible roles plus 5 approvers plus 6 reviewers, which is 53, not the whole organisation. Access reviews work the opposite way and require licences for reviewers and for the users being reviewed.

What happens when the licence lapses, which differs sharply

Conditional Access degrades gracefully: policies are not automatically disabled or deleted, and can be viewed and deleted but not updated. PIM does not. Microsoft states that eligible role assignments are removed, ongoing access reviews end and configuration settings are removed, though permanent role assignments are unaffected. That asymmetry belongs in any renewal decision and almost nobody raises it.

The smaller items that decide edge cases

Custom RBAC roles require P1 for every user holding one, while built-in roles are free. Administrative unit administrators need P1 while members do not. Entra Connect is free but Connect Health requires P1. Provisioning logs, Health, Graph activity logs and usage insights need P1, though audit and sign-in logs are free. Verified ID is included even at Free. These rarely drive a decision alone and they frequently settle a close one.

Two things worth knowing before you decide

The guidance you have read may describe a licensing model that has changed.

Microsoft has moved capabilities between editions, and the material circulating about P1 against P2 has not uniformly kept up. These two points change decisions.

  • Access reviews and entitlement management are no longer straightforwardly a P2 feature. Microsoft states that using access reviews requires an Entra ID Governance subscription for member users, and that some capabilities might operate with a P2 subscription. The same wording covers entitlement management. Organisations upgrading to P2 specifically to run access certification campaigns should establish exactly what they will get before committing, because the answer is now conditional rather than a yes.
  • The failure modes on expiry are not the same, and this belongs in a renewal conversation. Conditional Access policies survive a lapse: they are not automatically disabled or deleted, and you can view and delete them but not update them. Privileged Identity Management does not survive it. Eligible role assignments are removed, ongoing access reviews end and configuration settings are removed. An organisation that builds its administrative model on eligible access and later lets P2 lapse loses that model rather than freezing it.
  • A third point that saves money rather than costing it: PIM is licensed for the people it touches, not for everyone. Microsoft own worked example covers 42 administrators managed through PIM, 5 approvers and 6 reviewers, totalling 53 licences in an organisation with far more staff than that. Access reviews are the reverse, requiring licences for reviewers and for the users being reviewed, which is why an access review programme scales differently from PIM and needs separate arithmetic.
  • The practical consequence is that P1 against P2 is rarely an organisation-wide decision. For many UAE businesses the sensible answer is P1 broadly, with P2 or Governance for the small population who hold administrative access, and we would rather work that out with you than quote for a blanket upgrade.
Ask us to work the licence count against your actual admin population
How we advise on this

Four things that make this advice worth having.

Licensing advice usually arrives from somebody who benefits from the upgrade. We resell Microsoft licensing, so that applies to us too, and the discipline that follows is worth stating rather than assuming.

We check what you already own before recommending anything

A large share of the organisations that ask us about P2 have not configured the P1 capabilities they already hold, and in several cases already have P2 sitting unused inside an E5 plan bought for other reasons. Establishing that first regularly ends the conversation without a purchase, which is the correct outcome and one we would rather reach quickly.

We work from the licensing article, not from a comparison chart

Microsoft moves capabilities between editions, and the access reviews change is a live example that a great deal of published guidance has not absorbed. Every claim we make about what an edition includes is traceable to Microsoft own licensing documentation, and where the wording is conditional we reproduce the condition rather than simplifying it into a yes.

We scope P2 to the population that needs it

P1 against P2 is rarely an organisation-wide decision. For most UAE businesses the sensible answer is P1 broadly with P2 or Governance for the small group holding administrative access, and Microsoft own worked examples support exactly that arithmetic. A blanket upgrade is easier to quote and usually wrong.

We tell you what happens if you stop paying

Conditional access policies survive a lapse in a frozen state. PIM eligible role assignments are removed. That asymmetry matters if you are building an administrative model on eligible access, and it belongs in the decision rather than surfacing at a renewal three years later. Nobody raises this, and it is exactly the kind of thing that should be raised.

Where the answer differs

Six UAE situations and what we would usually recommend.

In three of these the recommendation is not to upgrade, which is roughly the real-world ratio once you establish what an organisation already holds.

A small business on Business Premium with nothing configured

Microsoft states P1 is included in Business Premium. The recommendation here is almost never P2. It is to configure conditional access, block legacy authentication, enable SSPR with writeback if you have on-premises identities, and use what you are already paying for. Upgrading before doing that buys more unused capability at a higher price.

A regulated firm with a real administrative population

Where supervisory expectations cover privileged access, PIM is the strongest argument for P2, because eligible rather than permanent administrative access with approval and an audit trail is exactly what those requirements describe. The licence count is the eligible administrators plus approvers plus reviewers rather than the whole firm, which usually makes it affordable.

An organisation already on E5 for other reasons

You have P2 and quite possibly have never enabled Identity Protection or PIM. This is the most common form of waste we see in UAE Microsoft estates: capability paid for, never switched on, and then a separate security purchase made to solve a problem the existing licence already covers. The work here is configuration and it costs nothing additional.

A business planning an access certification programme

Check carefully before buying. Microsoft now states that access reviews require an Entra ID Governance subscription for member users, with some capabilities operating at P2. The licence arithmetic is also unusual, since reviewers and reviewed users both need licences. A programme scoped as a P2 purchase may need re-costing, and it is much better to find that out now.

A company with a small IT team and no security operations

P2 gives you risk detection, and detection with nobody to act on it changes nothing. If there is no realistic responder for a risky sign-in alert at nine on a Friday evening, the honest recommendation is to spend on the controls that prevent rather than detect, meaning strong conditional access and device compliance at P1, and revisit P2 when there is somebody to receive the signal.

An organisation weighing the Entra Suite

The Suite requires P1 or a package including P1, is available standalone or within Microsoft 365 E7, and bundles Private Access, Internet Access, ID Governance, ID Protection and Verified ID premium capabilities. If you want ID Governance for access reviews and also want to replace remote access infrastructure, the Suite arithmetic can beat buying the parts, and it is worth modelling rather than assuming either way.

Three positions

How UAE organisations actually sit on Entra licensing.

The middle column is the most common and the most wasteful, because the organisation is paying for capability it has never switched on. Upgrading from there buys more unused capability.
Knows which editions its users hold
Licensed to fitYes
Entitled but unconfiguredRoughly
Upgraded without a reasonYes, after buying
Conditional access configured
Licensed to fitYes
Entitled but unconfiguredNo
Upgraded without a reasonSometimes
P2 scoped to the population that needs it
Licensed to fitYes
Entitled but unconfiguredNot applicable
Upgraded without a reasonBought for everyone
PIM in use with eligible access
Licensed to fitYes
Entitled but unconfiguredNo
Upgraded without a reasonRarely enabled
Risk policies actioned by somebody
Licensed to fitYes
Entitled but unconfiguredNot available
Upgraded without a reasonAlerts nobody reads
Access review expectations checked against Governance
Licensed to fitYes
Entitled but unconfiguredNot applicable
Upgraded without a reasonAssumed P2 covered it
Renewal implications understood
Licensed to fitYes
Entitled but unconfiguredNot applicable
Upgraded without a reasonNo
Spend matches capability actually used
Licensed to fitYes
Entitled but unconfiguredUnderused
Upgraded without a reasonOverspent
Would survive a licensing true-up comfortably
Licensed to fitYes
Entitled but unconfiguredYes
Upgraded without a reasonYes, expensively
Frequency in the UAE market
Licensed to fitUncommon
Entitled but unconfiguredVery common
Upgraded without a reasonCommon
Feature
Licensed to fit
Entitled but unconfigured
Upgraded without a reason
Knows which editions its users hold
YesRoughlyYes, after buying
Conditional access configured
YesNoSometimes
P2 scoped to the population that needs it
YesNot applicableBought for everyone
PIM in use with eligible access
YesNoRarely enabled
Risk policies actioned by somebody
YesNot availableAlerts nobody reads
Access review expectations checked against Governance
YesNot applicableAssumed P2 covered it
Renewal implications understood
YesNot applicableNo
Spend matches capability actually used
YesUnderusedOverspent
Would survive a licensing true-up comfortably
YesYesYes, expensively
Frequency in the UAE market
UncommonVery commonCommon
Feature by edition

What Free, P1 and P2 each give you.

Taken from the Microsoft Entra licensing article. Where Microsoft describes a capability as limited rather than absent, that is reproduced rather than simplified, because the difference between limited and none is exactly what a decision turns on.
CapabilityFreeP1P2
Conditional Access policiesNoYesYes
Risk-based Conditional AccessNoNoYes
Privileged Identity ManagementNoNoYes, or ID Governance
Access reviewsNoNoSome capabilities, ID Governance for the feature
Entitlement managementNoNoSome capabilities, ID Governance for the feature
Risky users reportLimitedLimited, no details or historyFull access
Risky sign-ins reportLimited, no risk levelLimited, no risk levelFull access
Users at risk alerts and weekly digestNoNoYes
Self-service password resetYesYesYes
SSPR with on-premises writebackNoYesYes
Custom RBAC rolesNoYes, per user holding oneYes
Entra Connect HealthNoYesYes
Audit and sign-in logsYesYesYes
Provisioning logs, Health, usage insightsNoYesYes
Verified ID core capabilityYesYesYes
How we work the decision

Five steps, and it frequently ends at step two.

Typically a week or two of elapsed time, most of which is establishing what you already hold and whether it is configured. That is deliberately the cheapest question and it is asked first.
  1. 1

    Establish what your users are actually licensed for

    Which plans, how many of each, and whether any group already holds P2 through E5, E7, EMS E5 or a Defender Suite. This regularly surfaces entitlement nobody knew about, and it is the necessary baseline for any comparison, because you cannot evaluate an upgrade without knowing the starting point.

  2. 2

    Check whether the P1 capabilities are configured

    Conditional access, legacy authentication blocking, SSPR with writeback, Connect Health, custom roles, provisioning logs. If these are unconfigured, that is the work, and we will say so rather than proceeding to a P2 conversation. An organisation not using what it has will not use more of it.

  3. 3

    Test the P2 case honestly against two questions

    Would you act on risk signals, and do you have enough administrators for eligible access to be meaningful. If nobody would respond to a risk alert, Identity Protection buys reporting rather than protection. If you have three administrators who all need permanent access anyway, PIM is overhead. Both are legitimate answers.

  4. 4

    Do the arithmetic on the population that needs it

    For PIM, the eligible administrators plus approvers plus reviewers. For access reviews, the reviewers plus the users being reviewed, which scales very differently, and a check on whether Entra ID Governance rather than P2 is what the feature now requires. This usually produces a smaller and more defensible number than a blanket upgrade.

  5. 5

    Decide, implement, and record why

    A written recommendation with the reasoning and the licence counts, so it can be handed to finance or revisited at renewal. Where the answer is not to upgrade, that is the deliverable. Where it is, we configure what you buy, because a P2 licence with Identity Protection and PIM left switched off is exactly the waste this exercise exists to prevent.

Straight answers

What organisations ask about Entra ID licensing.

Two capabilities genuinely, and both matter. Microsoft Entra ID Protection, which enables risk-based conditional access using sign-in risk and user risk, plus full risk reporting and alerting. And Privileged Identity Management, which provides eligible rather than permanent administrative access with approval and an audit trail. Everything else people associate with P2 is either also in P1, or has moved toward requiring Entra ID Governance, which is the change most guidance has missed.

Not straightforwardly, and this is the most important correction on this page. Microsoft states that using access reviews requires an Entra ID Governance subscription for your organisation member users, and that some capabilities within the feature might operate with a P2 subscription. The same wording covers entitlement management. Plenty of published comparisons still list access reviews as a P2 feature. If access certification is your reason for upgrading, establish exactly what you would receive before committing budget.

Microsoft lists P1 as included with Microsoft 365 E3, E5 and E7, with F1 and F3, with Enterprise Mobility and Security E3, and in Microsoft 365 Business Premium. P2 is listed as included with Microsoft 365 E5 and E7, with the Microsoft Defender Suite formerly called Microsoft 365 E5 Security, with the Defender Suite FLW and Defender plus Purview Suite FLW variants, and with Enterprise Mobility and Security E5. Check what your users actually hold before assuming you need to buy anything.

Probably not, and we would say so. PIM converts permanent administrative access into eligible access that is activated when needed, approved, time-bound and logged. That is genuinely valuable at scale, where a large administrative population creates standing risk. With three administrators who all legitimately need access most days, the operational overhead outweighs the benefit, and the effort is better spent on separating their administrative accounts from their daily accounts, which costs nothing.

Fewer than you probably think, and the answer depends which feature you are buying it for. For PIM, licences are needed for users with eligible or time-bound role assignments, members and owners under PIM for Groups, anyone able to approve or reject activation requests, and anyone assigned to or performing an access review. Microsoft own worked example totals 53 for an organisation with 50 administrators of which 42 are managed through PIM, plus 5 approvers and 6 reviewers. Access reviews are the opposite and need licences for reviewers and for every user being reviewed.

Considerably worse than letting conditional access lapse, and it is worth understanding before you build on it. For Conditional Access, Microsoft states policies are not automatically disabled or deleted and can be viewed and deleted but not updated, so your posture freezes rather than collapsing. For PIM, Microsoft states that eligible role assignments are removed, ongoing access reviews end and configuration settings are removed, although permanent role assignments are unaffected. So an administrative model built on eligible access does not survive a lapse.

No, and this nuance is worth having. At P1 the risky users report shows only medium and high risk users with no details drawer and no risk history, risky sign-ins show no risk detail or risk level, and risk detections are limited with no details drawer. So P1 tells you that something is happening without telling you what it was or how serious. For some organisations that is a useful prompt to investigate manually. For others it is frustrating enough to justify P2 on its own.

Usually just some. The features that justify P2 concentrate on a small population: the administrators who would hold eligible access, the people who approve activations, and whoever reviews access. Risk-based conditional access is the one that benefits from broad coverage, since it protects ordinary users, so the shape of the answer depends on which capability is driving the purchase. We would rather work that out against your actual numbers than recommend a blanket upgrade, which is easier to quote and usually wrong.

A bundle that requires P1 or a package including P1, available standalone or included in Microsoft 365 E7. Microsoft lists it as including five products: Entra Private Access, Entra Internet Access, Entra ID Governance, Entra ID Protection and the premium capabilities of Entra Verified ID. It becomes interesting when you want more than one of those, particularly if you want ID Governance for access reviews and are also considering replacing remote access infrastructure, because buying the parts separately can cost more than the bundle.

Almost certainly. In most UAE tenants we look at, conditional access is unconfigured or minimal, self-service password reset with on-premises writeback is not enabled, Entra Connect Health is not set up, provisioning logs and usage insights have never been opened, and custom roles are unused while everyone holds broad built-in roles. Each of those is included at P1 and each costs nothing further to enable. Working through that list is a better first project than a licence upgrade.

It can, particularly on privileged access. Requirements applying to payment service providers under Central Bank regulation are specific about restricting the number of privileged users, controlling remote privileged access and logging privileged activity, and PIM addresses several of those directly with evidence attached. Sector frameworks including ADHICS in Abu Dhabi healthcare have similar access control expectations. That said, a well-configured P1 tenant meets more of these requirements than an unconfigured P2 one.

It is increasingly the answer where access reviews, entitlement management and lifecycle workflows are the objective, since Microsoft now describes those as requiring a Governance subscription with some capabilities operating at P2. It is also included in the Entra Suite and in Microsoft 365 E7. If your driver is identity governance rather than risk detection, the comparison you actually need is P1 plus Governance against P2, not P1 against P2, and framing it the usual way produces the wrong answer.

Microsoft states that there are no licensing requirements for managed identities for Azure resources, and that Verified ID is included with any Entra ID subscription including Free at no extra cost, with Face Check available as a premium add-on. External ID core features are described as free for the first fifty thousand monthly active users. These are worth knowing because they occasionally get bundled into an upgrade proposal as though they were premium capabilities.

A week or two, most of which is establishing what your users already hold and whether the P1 capabilities are configured. The comparison itself is quick once the baseline is known. The stage that takes longest is usually the honest conversation about whether anybody would act on risk signals, because that is a resourcing question rather than a licensing one and it needs somebody senior to answer it truthfully.

We scope it small, because its purpose is to prevent a much larger and possibly unnecessary spend. What we will tell you free in the first conversation is which editions your users hold and whether the P1 capabilities you already own are switched on. For a meaningful number of organisations that single answer ends the question without a purchase, which is a perfectly good outcome for a conversation about licensing.
Work the decision properly

Fifteen questions that settle P1 against P2.

The first group establishes what you already hold. The second tests whether the P2 capabilities would actually be used. The third is the arithmetic, which usually shows the upgrade is smaller than expected.

What you already have

  • Which Microsoft 365 or EMS plans do your users hold?
    E3 and Business Premium both include P1.
  • Does anyone already hold E5, E7 or EMS E5?
    Those include P2, and it may be unused.
  • Have you configured conditional access at all?
    If not, you have unused P1 before considering P2.
  • Are provisioning logs and usage insights being used?
    P1 capabilities most tenants never open.
  • Is Entra Connect Health configured?
    Requires P1, and it is free to enable if you have it.

Would you use what P2 adds

  • Do you want risky sign-ins blocked automatically, not just reported?
    That is P2, via Identity Protection.
  • Is the limited P1 risk view genuinely insufficient for you?
    P1 shows something is wrong without saying what.
  • Do you have enough administrators to justify eligible access?
    PIM earns its place at scale, not at three admins.
  • Would anybody actually action a risk alert?
    Detection with no responder changes nothing.
  • Are you buying P2 for access reviews specifically?
    Check what you get. That capability has moved toward Governance.

The arithmetic

  • How many administrators would be managed through PIM?
    Licence the eligible admins, not the organisation.
  • How many approvers and reviewers would there be?
    They need licences too, per Microsoft own example.
  • If running access reviews, how many users would be reviewed?
    Those users need licences, which changes the count sharply.
  • Could you licence P2 for a subset rather than everyone?
    Usually yes, and usually the right answer.
  • What happens to your admin model if P2 lapses?
    Eligible role assignments are removed, not frozen.
Related reading

The pages around this one.

Entra Conditional Access

The P1 capability most organisations already own and have not configured, including why exclusions rather than policies are where these deployments fail.

Learn more

Microsoft Entra

The wider identity platform and the practice around it, for the broader picture before drilling into a licensing decision.

Learn more

Access rights review

The recurring certification process itself, which is worth designing properly whichever licence you end up running it on.

Learn more
Next step

Find out what your users already hold before comparing anything.

A meaningful share of the organisations that ask us about P2 already have it inside an E5 plan, or have never configured the P1 capabilities they are paying for. That answer is free, it takes one conversation, and it frequently ends the question without a purchase.

Book a licensing and capability reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Entra Conditional Access

The control that decides who reaches your data

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

Access Rights Review

Certification that removes access, not one that gets approved

Learn more

M365 Licensing

Optimize your Microsoft 365 licensing costs

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Active Directory Audit

Privilege paths, service accounts and local admin passwords

Learn more

CBUAE IT Requirements

Which Rulebook articles actually bind your licence

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy