Is a P1/P2 Entra ID license per user or per tenant?

Mike Baker 15 Reputation points
2024-04-18T23:28:33.71+00:00

I am reading various articles about Microsoft cloud security features. Many of them list having a Entra ID P1 / P2 license as a prerequisite. But I am unclear on exactly what that means.

On the Azure portal, the "All Services > Licenses" page, my organization shows as having a single Entra ID P2 license. It's assigned to a single admin user, leaving "available" licenses at zero. The pricing page for Entra ID also lists everything as per-user.

However, on the "All Services > Licenses > Licensed Features" page there is a big blue box that appears to be saying it's the tenant that has the license.

User's image

Additionally, there are services we have been using for a long time (e.g., Risk-Based Conditional Access) that are listed as only being available with an Entra ID P2 license -- yet these services are administered by more than my one P2 license assignee and are deployed at the tenant level.

So, I guess my question is: For a service that both applies to all users and requires an Entra ID P2 license, would my tenant qualify or not?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,993 questions
{count} vote

2 answers

Sort by: Most helpful
  1. Andy David - MVP 151.5K Reputation points MVP
    2024-04-18T23:35:53.1766667+00:00

    Each account that consumes a P2 service requires a license. You can have one P2 to light up the feature and enable it but each user that takes advantage of that service needs to be licensed to be compliant. The docs arent very clear about that sometimes.

    https://learn.microsoft.com/en-us/entra/id-protection/overview-identity-protection#license-requirements

    User's image


  2. Deepak Tiwari 0 Reputation points
    2025-01-12T03:10:24.6+00:00

    Yes, this is per user licensing.

    one approach to use the license effectively is to identify privileged and important credentials and have license for those.

    • privilege can be easily identified
    • important can be senior management & users who uses critical data (can be an Azure file share in finance department) to whom access provided via group
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.