Azure Active Directory Premium P2 Licenses

Joel Prescilla 66 Reputation points
2022-06-21T01:16:24.857+00:00

Hi, stupid question what is this license for? Is this a default no of licence for AD Premium 2? At the moment, we have not assigned any, so can we decrease the number of license to save cost?

213138-image.png

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. risolis 8,741 Reputation points
    2022-06-21T02:27:19.757+00:00

    Hello @Joel Prescilla

    Thank for your question.

    I would say that it is a good one : )

    For now, let me gather you the following article below so you will realize that difference between P1,P2 and free license for Azure AD.

    https://www.microsoft.com/en-gb/security/business/identity-access-management/azure-ad-pricing

    Looking forward to your feedback,

    Best Regards,

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


  2. David Broggy 6,376 Reputation points MVP Volunteer Moderator
    2022-06-21T03:03:38.653+00:00

    Hi @Joel Prescilla
    If you’re not using Azure for production use and just for learning then your question is understandable.
    If you’re using it for production then there are some important features you should consider before throwing away your P2 because of costs. Eg:

    • PIM - Privileged Identity Management - limits your admins to only have ‘god roles’ - like global admin - for just a few hours before they have to ask for it again.
    • JIT - Just in Time access - like PIM, it allows users access to services (like logging into a VM) for a limited period of time. Any users not provided JIT won’t even be able to knock on the server’s door!
    • User and Role Review - Report on who had the ‘god roles’. Without this capability you’ll be endlessly searching through Azure AD every time someone makes a role change.
    • Conditional Access - this is a P1 feature but without it you’re basically allowing anyone from anywhere to at least attempt to login to your Azure services.

    Those are the coolest features. I spend a lot of time working with the security features in Azure/O365 so hopefully I’m not sounding overzealous!


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.