A cloud-based identity and access management service for securing user authentication and resource access
Hello SAGA,
Upgrading from Microsoft Entra ID P1 to P2 adds advanced security and governance capabilities while retaining all P1 features.
P1 covers essentials like Conditional Access, MFA, self-service password reset, dynamic groups, and basic access management.
P2 extends this with Identity Protection (detecting risky sign-ins and users), risk-based Conditional Access (enforcing actions based on risk), Privileged Identity Management (just-in-time admin access), Access Reviews (periodic access cleanup), and Entitlement Management (handling access packages, including guest onboarding and approvals).
Overall, P1 is suitable for standard access control, while P2 is better aligned with stronger security, privileged access control, and governance needs.
For advanced lifecycle automation (such as joiner/mover/leaver workflows), the Microsoft Entra ID Governance add-on may still be required.
Reference: https://learn.microsoft.com/en-us/entra/fundamentals/licensing