To improve the Identity Secure Score, is Microsoft Entra ID Premium P2 required for all users, or is it only needed for the Global Administrator to implement the recommendations?

Sunday Edeh 0 Reputation points
2026-08-05T17:19:07.8566667+00:00

Dear Support Team,

We would like to clarify whether Microsoft Entra ID Premium P2 licenses are required for all users in order to improve the Identity Secure Score, or if the license is only required for the Global Administrator to implement the recommended security controls.

Kindly advise.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

3 answers

Sort by: Most helpful
  1. Sunday Edeh 0 Reputation points
    2026-08-05T19:10:50.8233333+00:00

    Enable Microsoft Entra ID Identity Protection sign-in risk policies

    Enable Microsoft Entra ID Identity Protection user risk policies

    Ensure 'External sharing' of calendars is not available

    Ensure additional storage providers are restricted in Outlook on the web

    Ensure all forms of mail forwarding are blocked and/or disabled

    Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domains

    Ensure MailTips are enabled for end users

    Ensure mailbox auditing for all users is Enabled

    Ensure Exchange Online Spam Policies are set to notify administrators

    Ensure users installing Outlook add-ins is not allowed

    Publish M365 sensitivity label data classification policies

    Ensure that no sender domains are allowed for anti-spam policies

    Ensure multifactor authentication is enabled for all users in administrative roles

    Ensure multifactor authentication is enabled for all users

    Configure which users are allowed to present in Teams meetings

    Ensure the customer lockbox feature is enabled

    Restrict anonymous users from joining meetings

    Don't add allowed IP addresses in the connection filter policy

    Set automatic email forwarding rules to be system controlled

    Block users who reached the message limit

    Sign out inactive users in SharePoint Online

    Ensure modern authentication for SharePoint applications is required

    Deploy a log collector to discover shadow IT activity

    Ensure 'Self service password reset enabled' is set to 'All'

    Enable Conditional Access policies to block legacy authentication

    Create Safe Links policies for email messages

    Turn on Safe Attachments in block mode

    Ensure that mailbox intelligence is enabled

    Ensure that intelligence for impersonation protection is enabled

    Move messages that are detected as impersonated users by mailbox intelligence

    Enable impersonated domain protection

    Set the phishing email level threshold at 2 or higher

    Enable impersonated user protection

    Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'

    Create zero-hour auto purge policies for malware

    Quarantine messages that are detected from impersonated domains

    Quarantine messages that are detected from impersonated users

    Turn on Microsoft Defender for Office 365 in SharePoint, OneDrive, and Microsoft Teams

    Turn on Safe Documents for Office Clients

    Ensure the Common Attachment Types Filter is enabled

    Ensure DLP policies are enabled

    Set action to take on high confidence spam detection

    Set action to take on phishing detection

    Set action to take on high confidence phishing detection

    Set action to take on spam detection

    Ensure that password hash sync is enabled for hybrid deployments

    Ensure Safe Attachments policy is enabled

    Ensure third party integrated applications are not allowed

    Ensure user consent to apps accessing company data on their behalf is not allowed

    Create zero-hour auto purge policies for phishing messages

    Set action to take on bulk spam detection

    Enable the domain impersonation safety tip

    Enable the user impersonation safety tip

    Enable the user impersonation unusual characters safety tip 

    Ensure modern authentication for Exchange Online is enabled

    Ensure Microsoft 365 audit log search is Enabled

    Ensure Safe Links for Office Applications is Enabled

    Ensure that an anti-phishing policy has been created

    Only invited users should be automatically admitted to Teams meetings

    Create zero-hour auto purge policies for spam messages

    Restrict dial-in users from bypassing a meeting lobby

    Limit external participants from having control in a Teams meeting

    Restrict anonymous users from starting Teams meetings

    Retain spam in quarantine for 30 days

    Set the email bulk complaint level (BCL) threshold to be 6 or lower

    Set maximum number of external recipients that a user can email per hour

    Set maximum number of internal recipients that a user can send to within an hour

    Set a daily message limit

    Designate more than one global admin

    Use least privileged administrative roles

    Was this answer helpful?

    0 comments No comments

  2. Sunday Edeh 0 Reputation points
    2026-08-05T19:09:45.31+00:00

    Which amongst the following requires P2 license
    Enable Microsoft Entra ID Identity Protection sign-in risk policies

    Enable Microsoft Entra ID Identity Protection user risk policies

    Ensure 'External sharing' of calendars is not available

    Ensure additional storage providers are restricted in Outlook on the web

    Ensure all forms of mail forwarding are blocked and/or disabled

    Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domains

    Ensure MailTips are enabled for end users

    Ensure mailbox auditing for all users is Enabled

    Ensure Exchange Online Spam Policies are set to notify administrators

    Ensure users installing Outlook add-ins is not allowed

    Publish M365 sensitivity label data classification policies

    Ensure that no sender domains are allowed for anti-spam policies

    Ensure multifactor authentication is enabled for all users in administrative roles

    Ensure multifactor authentication is enabled for all users

    Configure which users are allowed to present in Teams meetings

    Ensure the customer lockbox feature is enabled

    Restrict anonymous users from joining meetings

    Don't add allowed IP addresses in the connection filter policy

    Set automatic email forwarding rules to be system controlled

    Block users who reached the message limit

    Sign out inactive users in SharePoint Online

    Ensure modern authentication for SharePoint applications is required

    Deploy a log collector to discover shadow IT activity

    Ensure 'Self service password reset enabled' is set to 'All'

    Enable Conditional Access policies to block legacy authentication

    Create Safe Links policies for email messages

    Turn on Safe Attachments in block mode

    Ensure that mailbox intelligence is enabled

    Ensure that intelligence for impersonation protection is enabled

    Move messages that are detected as impersonated users by mailbox intelligence

    Enable impersonated domain protection

    Set the phishing email level threshold at 2 or higher

    Enable impersonated user protection

    Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'

    Create zero-hour auto purge policies for malware

    Quarantine messages that are detected from impersonated domains

    Quarantine messages that are detected from impersonated users

    Turn on Microsoft Defender for Office 365 in SharePoint, OneDrive, and Microsoft Teams

    Turn on Safe Documents for Office Clients

    Ensure the Common Attachment Types Filter is enabled

    Ensure DLP policies are enabled

    Set action to take on high confidence spam detection

    Set action to take on phishing detection

    Set action to take on high confidence phishing detection

    Set action to take on spam detection

    Ensure that password hash sync is enabled for hybrid deployments

    Ensure Safe Attachments policy is enabled

    Ensure third party integrated applications are not allowed

    Ensure user consent to apps accessing company data on their behalf is not allowed

    Create zero-hour auto purge policies for phishing messages

    Set action to take on bulk spam detection

    Enable the domain impersonation safety tip

    Enable the user impersonation safety tip

    Enable the user impersonation unusual characters safety tip 

    Ensure modern authentication for Exchange Online is enabled

    Ensure Microsoft 365 audit log search is Enabled

    Ensure Safe Links for Office Applications is Enabled

    Ensure that an anti-phishing policy has been created

    Only invited users should be automatically admitted to Teams meetings

    Create zero-hour auto purge policies for spam messages

    Restrict dial-in users from bypassing a meeting lobby

    Limit external participants from having control in a Teams meeting

    Restrict anonymous users from starting Teams meetings

    Retain spam in quarantine for 30 days

    Set the email bulk complaint level (BCL) threshold to be 6 or lower

    Set maximum number of external recipients that a user can email per hour

    Set maximum number of internal recipients that a user can send to within an hour

    Set a daily message limit

    Designate more than one global admin

    Use least privileged administrative roles

    Was this answer helpful?

    0 comments No comments

  3. AI answer

    2026-08-05T17:19:27.66+00:00

    Identity Secure Score itself is available to free and paid customers. Microsoft Entra ID Premium P2 is not required for all users just to view or improve the score.

    What is required depends on the specific recommendation:

    • Viewing Identity Secure Score: available to free and paid customers.
    • Viewing improvement actions: at least the Service Support Administrator role is required to view an improvement action without updating it.
    • Updating the status of an improvement action: at least the SharePoint Administrator role is required.
    • Implementing recommendations: some recommendations are available to all customers, while others require Microsoft Entra ID P1 or P2.

    So the requirement is not simply “P2 for the Global Administrator only” and also not “P2 for every user” by default. It depends on which Secure Score recommendations are being implemented:

    • If a recommendation uses a feature that is included in free capabilities, no P2 license is needed for all users.
    • If a recommendation depends on Microsoft Entra ID Protection capabilities such as sign-in risk policies or user risk policies, those capabilities require Microsoft Entra ID P2.

    Examples from Identity Secure Score recommendations that map to P2-only capabilities include:

    • Protect all users with a sign-in risk policy
    • Protect all users with a user risk policy

    Because those recommendations target all users, the users covered by those policies would need the appropriate P2 licensing for that feature.

    In summary:

    • Identity Secure Score can be improved without assigning P2 to every user.
    • P2 is only needed for recommendations that rely on P2 features.
    • If the recommendation is scoped to all users and uses a P2 feature, then all users in scope need P2.
    • Administrative role assignment controls who can view or update recommendations, but it does not replace the licensing requirement of the underlying feature.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.