P2 buys you two things. Most advice about it is out of date.
The genuine P2 additions are risk-based policies through Identity Protection and Privileged Identity Management. Access reviews and entitlement management have moved toward requiring Entra ID Governance, which a lot of published guidance has not caught up with. We work the decision from the licensing article itself.

- P2 adds two thingsID Protection and PIM
- Governance movedAccess reviews are not simply P2
- Not everyonePIM licenses eligible admins only
- Expiry differsPIM removes assignments, CA does not
Eight things to establish before anybody quotes you for an upgrade.
What you already hold, which is usually more than you think
Microsoft states that Entra ID P1 is included with Microsoft 365 E3, E5 and E7, with F1 and F3, with Enterprise Mobility and Security E3, and in Microsoft 365 Business Premium. P2 is included with Microsoft 365 E5 and E7, with the Microsoft Defender Suite formerly called Microsoft 365 E5 Security, and with Enterprise Mobility and Security E5. A surprising number of UAE organisations are entitled to capabilities they have never enabled.
The first genuine P2 addition: Identity Protection
Risk-based conditional access, meaning sign-in risk and user risk policies, requires Entra ID Protection, which is a P2 feature. This is the capability most often assumed to be present at P1 and it is not. If your security plan includes blocking risky sign-ins automatically, that plan requires P2 and no amount of configuration at P1 will produce it.
The second: Privileged Identity Management
PIM provides eligible rather than permanent administrative access, so a role is activated when needed and expires afterwards, with approval and an audit trail. Microsoft states you need either Entra ID Governance or Entra ID P2 licences to use PIM and all its settings. For an organisation with a meaningful number of administrators this is usually the strongest single argument for P2.
Access reviews and entitlement management have moved
This is the change most published guidance has missed. Microsoft now states that using access reviews requires an Entra ID Governance subscription for member users, and that some capabilities might operate with a P2 subscription. The same wording appears for entitlement management. If you are considering P2 specifically to get access reviews, check what you would actually receive rather than relying on an article written two years ago.
What P1 gives you of Identity Protection, which is not nothing
A useful nuance. At P1 the risky users report shows only medium and high risk users with no details drawer and no risk history, and risky sign-ins show no risk detail or risk level. Risk detections at P1 are limited with no details drawer. So P1 tells you something is happening without telling you what. Whether that partial view is enough is a real question rather than a formality.
How many licences you actually need, which is not everyone
For PIM, licences are needed for users with eligible or time-bound role assignments, members and owners under PIM for Groups, anybody who can approve or reject activation requests, and anyone assigned to or performing an access review. Microsoft own worked example totals 42 eligible roles plus 5 approvers plus 6 reviewers, which is 53, not the whole organisation. Access reviews work the opposite way and require licences for reviewers and for the users being reviewed.
What happens when the licence lapses, which differs sharply
Conditional Access degrades gracefully: policies are not automatically disabled or deleted, and can be viewed and deleted but not updated. PIM does not. Microsoft states that eligible role assignments are removed, ongoing access reviews end and configuration settings are removed, though permanent role assignments are unaffected. That asymmetry belongs in any renewal decision and almost nobody raises it.
The smaller items that decide edge cases
Custom RBAC roles require P1 for every user holding one, while built-in roles are free. Administrative unit administrators need P1 while members do not. Entra Connect is free but Connect Health requires P1. Provisioning logs, Health, Graph activity logs and usage insights need P1, though audit and sign-in logs are free. Verified ID is included even at Free. These rarely drive a decision alone and they frequently settle a close one.
The guidance you have read may describe a licensing model that has changed.
Microsoft has moved capabilities between editions, and the material circulating about P1 against P2 has not uniformly kept up. These two points change decisions.
- Access reviews and entitlement management are no longer straightforwardly a P2 feature. Microsoft states that using access reviews requires an Entra ID Governance subscription for member users, and that some capabilities might operate with a P2 subscription. The same wording covers entitlement management. Organisations upgrading to P2 specifically to run access certification campaigns should establish exactly what they will get before committing, because the answer is now conditional rather than a yes.
- The failure modes on expiry are not the same, and this belongs in a renewal conversation. Conditional Access policies survive a lapse: they are not automatically disabled or deleted, and you can view and delete them but not update them. Privileged Identity Management does not survive it. Eligible role assignments are removed, ongoing access reviews end and configuration settings are removed. An organisation that builds its administrative model on eligible access and later lets P2 lapse loses that model rather than freezing it.
- A third point that saves money rather than costing it: PIM is licensed for the people it touches, not for everyone. Microsoft own worked example covers 42 administrators managed through PIM, 5 approvers and 6 reviewers, totalling 53 licences in an organisation with far more staff than that. Access reviews are the reverse, requiring licences for reviewers and for the users being reviewed, which is why an access review programme scales differently from PIM and needs separate arithmetic.
- The practical consequence is that P1 against P2 is rarely an organisation-wide decision. For many UAE businesses the sensible answer is P1 broadly, with P2 or Governance for the small population who hold administrative access, and we would rather work that out with you than quote for a blanket upgrade.
Four things that make this advice worth having.
We check what you already own before recommending anything
A large share of the organisations that ask us about P2 have not configured the P1 capabilities they already hold, and in several cases already have P2 sitting unused inside an E5 plan bought for other reasons. Establishing that first regularly ends the conversation without a purchase, which is the correct outcome and one we would rather reach quickly.
We work from the licensing article, not from a comparison chart
Microsoft moves capabilities between editions, and the access reviews change is a live example that a great deal of published guidance has not absorbed. Every claim we make about what an edition includes is traceable to Microsoft own licensing documentation, and where the wording is conditional we reproduce the condition rather than simplifying it into a yes.
We scope P2 to the population that needs it
P1 against P2 is rarely an organisation-wide decision. For most UAE businesses the sensible answer is P1 broadly with P2 or Governance for the small group holding administrative access, and Microsoft own worked examples support exactly that arithmetic. A blanket upgrade is easier to quote and usually wrong.
We tell you what happens if you stop paying
Conditional access policies survive a lapse in a frozen state. PIM eligible role assignments are removed. That asymmetry matters if you are building an administrative model on eligible access, and it belongs in the decision rather than surfacing at a renewal three years later. Nobody raises this, and it is exactly the kind of thing that should be raised.
Six UAE situations and what we would usually recommend.
A small business on Business Premium with nothing configured
Microsoft states P1 is included in Business Premium. The recommendation here is almost never P2. It is to configure conditional access, block legacy authentication, enable SSPR with writeback if you have on-premises identities, and use what you are already paying for. Upgrading before doing that buys more unused capability at a higher price.
A regulated firm with a real administrative population
Where supervisory expectations cover privileged access, PIM is the strongest argument for P2, because eligible rather than permanent administrative access with approval and an audit trail is exactly what those requirements describe. The licence count is the eligible administrators plus approvers plus reviewers rather than the whole firm, which usually makes it affordable.
An organisation already on E5 for other reasons
You have P2 and quite possibly have never enabled Identity Protection or PIM. This is the most common form of waste we see in UAE Microsoft estates: capability paid for, never switched on, and then a separate security purchase made to solve a problem the existing licence already covers. The work here is configuration and it costs nothing additional.
A business planning an access certification programme
Check carefully before buying. Microsoft now states that access reviews require an Entra ID Governance subscription for member users, with some capabilities operating at P2. The licence arithmetic is also unusual, since reviewers and reviewed users both need licences. A programme scoped as a P2 purchase may need re-costing, and it is much better to find that out now.
A company with a small IT team and no security operations
P2 gives you risk detection, and detection with nobody to act on it changes nothing. If there is no realistic responder for a risky sign-in alert at nine on a Friday evening, the honest recommendation is to spend on the controls that prevent rather than detect, meaning strong conditional access and device compliance at P1, and revisit P2 when there is somebody to receive the signal.
An organisation weighing the Entra Suite
The Suite requires P1 or a package including P1, is available standalone or within Microsoft 365 E7, and bundles Private Access, Internet Access, ID Governance, ID Protection and Verified ID premium capabilities. If you want ID Governance for access reviews and also want to replace remote access infrastructure, the Suite arithmetic can beat buying the parts, and it is worth modelling rather than assuming either way.
How UAE organisations actually sit on Entra licensing.
| Feature | Licensed to fit | Entitled but unconfigured | Upgraded without a reason |
|---|---|---|---|
Knows which editions its users hold | Yes | Roughly | Yes, after buying |
Conditional access configured | Yes | No | Sometimes |
P2 scoped to the population that needs it | Yes | Not applicable | Bought for everyone |
PIM in use with eligible access | Yes | No | Rarely enabled |
Risk policies actioned by somebody | Yes | Not available | Alerts nobody reads |
Access review expectations checked against Governance | Yes | Not applicable | Assumed P2 covered it |
Renewal implications understood | Yes | Not applicable | No |
Spend matches capability actually used | Yes | Underused | Overspent |
Would survive a licensing true-up comfortably | Yes | Yes | Yes, expensively |
Frequency in the UAE market | Uncommon | Very common | Common |
What Free, P1 and P2 each give you.
| Capability | Free | P1 | P2 | |
|---|---|---|---|---|
| Conditional Access policies | No | Yes | Yes | |
| Risk-based Conditional Access | No | No | Yes | |
| Privileged Identity Management | No | No | Yes, or ID Governance | |
| Access reviews | No | No | Some capabilities, ID Governance for the feature | |
| Entitlement management | No | No | Some capabilities, ID Governance for the feature | |
| Risky users report | Limited | Limited, no details or history | Full access | |
| Risky sign-ins report | Limited, no risk level | Limited, no risk level | Full access | |
| Users at risk alerts and weekly digest | No | No | Yes | |
| Self-service password reset | Yes | Yes | Yes | |
| SSPR with on-premises writeback | No | Yes | Yes | |
| Custom RBAC roles | No | Yes, per user holding one | Yes | |
| Entra Connect Health | No | Yes | Yes | |
| Audit and sign-in logs | Yes | Yes | Yes | |
| Provisioning logs, Health, usage insights | No | Yes | Yes | |
| Verified ID core capability | Yes | Yes | Yes |
Five steps, and it frequently ends at step two.
- 1
Establish what your users are actually licensed for
Which plans, how many of each, and whether any group already holds P2 through E5, E7, EMS E5 or a Defender Suite. This regularly surfaces entitlement nobody knew about, and it is the necessary baseline for any comparison, because you cannot evaluate an upgrade without knowing the starting point.
- 2
Check whether the P1 capabilities are configured
Conditional access, legacy authentication blocking, SSPR with writeback, Connect Health, custom roles, provisioning logs. If these are unconfigured, that is the work, and we will say so rather than proceeding to a P2 conversation. An organisation not using what it has will not use more of it.
- 3
Test the P2 case honestly against two questions
Would you act on risk signals, and do you have enough administrators for eligible access to be meaningful. If nobody would respond to a risk alert, Identity Protection buys reporting rather than protection. If you have three administrators who all need permanent access anyway, PIM is overhead. Both are legitimate answers.
- 4
Do the arithmetic on the population that needs it
For PIM, the eligible administrators plus approvers plus reviewers. For access reviews, the reviewers plus the users being reviewed, which scales very differently, and a check on whether Entra ID Governance rather than P2 is what the feature now requires. This usually produces a smaller and more defensible number than a blanket upgrade.
- 5
Decide, implement, and record why
A written recommendation with the reasoning and the licence counts, so it can be handed to finance or revisited at renewal. Where the answer is not to upgrade, that is the deliverable. Where it is, we configure what you buy, because a P2 licence with Identity Protection and PIM left switched off is exactly the waste this exercise exists to prevent.
What organisations ask about Entra ID licensing.
Fifteen questions that settle P1 against P2.
What you already have
- Which Microsoft 365 or EMS plans do your users hold?E3 and Business Premium both include P1.
- Does anyone already hold E5, E7 or EMS E5?Those include P2, and it may be unused.
- Have you configured conditional access at all?If not, you have unused P1 before considering P2.
- Are provisioning logs and usage insights being used?P1 capabilities most tenants never open.
- Is Entra Connect Health configured?Requires P1, and it is free to enable if you have it.
Would you use what P2 adds
- Do you want risky sign-ins blocked automatically, not just reported?That is P2, via Identity Protection.
- Is the limited P1 risk view genuinely insufficient for you?P1 shows something is wrong without saying what.
- Do you have enough administrators to justify eligible access?PIM earns its place at scale, not at three admins.
- Would anybody actually action a risk alert?Detection with no responder changes nothing.
- Are you buying P2 for access reviews specifically?Check what you get. That capability has moved toward Governance.
The arithmetic
- How many administrators would be managed through PIM?Licence the eligible admins, not the organisation.
- How many approvers and reviewers would there be?They need licences too, per Microsoft own example.
- If running access reviews, how many users would be reviewed?Those users need licences, which changes the count sharply.
- Could you licence P2 for a subset rather than everyone?Usually yes, and usually the right answer.
- What happens to your admin model if P2 lapses?Eligible role assignments are removed, not frozen.
The pages around this one.
Entra Conditional Access
The P1 capability most organisations already own and have not configured, including why exclusions rather than policies are where these deployments fail.
Microsoft Entra
The wider identity platform and the practice around it, for the broader picture before drilling into a licensing decision.
Access rights review
The recurring certification process itself, which is worth designing properly whichever licence you end up running it on.
Find out what your users already hold before comparing anything.
A meaningful share of the organisations that ask us about P2 already have it inside an E5 plan, or have never configured the P1 capabilities they are paying for. That answer is free, it takes one conversation, and it frequently ends the question without a purchase.
Related Services
Explore more solutions that work great with this service
Entra Conditional Access
The control that decides who reaches your data
Microsoft Entra
Identity and access management solutions
Access Rights Review
Certification that removes access, not one that gets approved
M365 Licensing
Optimize your Microsoft 365 licensing costs
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Active Directory Audit
Privilege paths, service accounts and local admin passwords
CBUAE IT Requirements
Which Rulebook articles actually bind your licence