Identity and access management dashboard on a corporate display
Microsoft Identity Pricing

Entra ID pricing decoded for buyers.

The Entra ID tier map, the metrics behind the price, and the buyer side moves that hold back the over provisioning trap.

Contact Us Microsoft Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

A buyer side guide to Entra ID licensing tiers, add ons, and the line items that most enterprises do not see until the renewal proposal lands.

Key takeaways

  • Entra ID Free covers the basics but ships no conditional access. Most enterprises end up on P1 or P2 the day they take security seriously.
  • Entra ID P1 versus P2 is mostly a Privileged Identity Management and Identity Protection conversation. The price gap rarely justifies P2 across all users.
  • Mixed tier licensing is supported and very common. Buy P2 for admins and high risk roles, P1 for everyone else.
  • Entra External ID is metered differently. Pricing is by monthly active user, not per seat. A bulk of low traffic external users can still cost a lot.
  • Add ons like Verified ID and Permissions Management are licensed separately. They are often missed in renewal forecasts.
  • Entra ID is bundled inside M365 E3 and E5. Stand alone purchase still happens, mostly in larger or regulated estates.

Entra ID is the new Active Directory. It is also the front door to almost every Microsoft cost decision.

The pricing looks simple on the product page. It is not. The decisions that matter sit between tiers, between add ons, and between human identities and workload identities.

This buyer side guide walks through the structure, calls out the line items that surprise people at renewal, and shows where to land in a mixed tier setup.

The Entra ID tier map for 2026

Entra ID Free

Bundled with every Microsoft cloud subscription. Provides core directory, SSO to thousands of SaaS apps, and basic security defaults.

No conditional access policies. No risk based sign in. No PIM. Acceptable for very small estates only.

Entra ID P1

Conditional access, group based licensing, advanced security reports, and access reviews for the basic groups.

P1 is where most enterprises sit for the bulk of their user base. Bundled inside M365 E3.

Entra ID P2

Adds Identity Protection, Privileged Identity Management, and the full access review surface. Bundled inside M365 E5.

P2 is rarely needed across every user. It is needed across every admin and every high risk role.

Entra External ID

Used to manage customer or partner identities. Priced by monthly active users with a free tier of 50,000 MAU, then per MAU bands above that.

A retailer or media business with millions of low engagement users can still hit material costs. Model it carefully.

What you actually pay for

Human identities versus workload identities

Workload identities are licensed separately. Service principals, managed identities, and application identities are billed via the Entra Workload Identities SKU.

Enterprises with hundreds of automated workloads often discover this line for the first time at renewal.

Guest users and B2B collaboration

Each paying tenant gets a generous block of guest user allowance before any incremental charge. The exact ratio depends on the tenant SKU and current Microsoft policy.

Large partner ecosystems should model guest usage explicitly. It is rarely the dominant cost but it is rarely zero either.

Authentications and tokens

Token issuance is not metered for normal Entra ID usage. Heavy workload identity scenarios can hit limits that drive an upgrade decision.

Entra ID tier comparison for 2026 buyers

Tier Best for Headline features Sits inside
FreeVery small estatesDirectory, SSO, basic security defaultsAny M365 plan
P1General workforceConditional access, group licensing, access reviewsM365 E3
P2Admins, high risk rolesIdentity Protection, PIM, full access reviewsM365 E5
External IDCustomer or partner identityPer MAU pricing, social and federated identityStand alone SKU
ID GovernanceLifecycle and certificationWorkflows, access packages, certificationsAdd on to P1 or P2
P2 across every user is almost never the right answer. P2 on the admins and a clean access review program usually is.

Add ons that show up in the renewal proposal

Entra Verified ID

Decentralized identity issuance. Licensed by issuance volume, not per seat. Used today mostly in HR onboarding and partner verification scenarios.

Entra Permissions Management

Multi cloud entitlement management across Azure, AWS, and Google Cloud. Licensed per resource. Often pitched into the security renewal conversation.

Entra ID Governance

Adds lifecycle workflows, access certifications, and entitlement management. Sits on top of P1 or P2.

Often missed in renewal forecasts and then bolted on later at a worse discount.

The hidden costs that surprise buyers

Shadow upgrades through E5 bundles

When the M365 E3 to E5 upgrade is sold, P2 comes along for the ride. Some organizations end up paying for P2 on every user when only a few hundred admins actually need it.

Mixed tier licensing solves this. Buy E5 for the people who use the security stack. Buy E3 for everyone else. Layer P2 separately on the admin and high risk users in the E3 group.

Workload identity blind spots

Service principals and managed identities can carry a per identity charge if they exceed the included free pool. Enterprises with deep DevOps automation often discover this only at renewal.

Audit log retention

Default Entra audit log retention is short. Extending retention to meet regulatory needs requires Microsoft Sentinel or a long term storage subscription.

Suggested reading

What to do next

  1. Pull your current Entra ID user count by SKU. Reconcile to your M365 plan mix.
  2. List the roles that genuinely need P2. PIM eligibility and Identity Protection are the practical tests.
  3. Model the cost gap between full P2 coverage and a mixed tier setup.
  4. Map your workload identity count. Identify whether the workload identities SKU applies.
  5. If External ID is in scope, run a MAU forecast for the next 24 months under realistic growth.
  6. Audit your add on subscriptions. Verified ID and Permissions Management often go unused.
  7. Brief Microsoft on the target mix at least 90 days before the EA renewal opens.
  8. Book a working session with our Microsoft team to validate the mix and the commercial posture.

Frequently asked questions

Do we need P2 for every user?

Almost never. P2 carries Privileged Identity Management and Identity Protection. Both are valuable but only on a defined population. Admins, high risk roles, executive accounts, and developers with elevated rights are the practical targets.

Can we mix P1 and P2 in the same tenant?

Yes. Mixed tier licensing has been supported for years. Group based licensing makes it operationally clean.

Is Entra ID included in M365 E3 and E5?

P1 is bundled with E3. P2 is bundled with E5. The bundling is the most common reason organizations end up over licensed on the identity side.

How is Entra External ID priced for customer scenarios?

By monthly active users, with a generous free tier and per MAU bands above it. Volume matters more than headcount because many customer estates have a long tail of low engagement users.

What about workload identities?

Service principals and managed identities can sit inside a free pool. Above the pool, the Entra Workload Identities SKU applies. Estate sizes vary widely so model it from your own data.

Does Entra ID Governance cover SOX access certifications?

It provides the workflow and certification engine. It does not replace the policy work or the auditor sign off. Many regulated estates use it as the system of record for periodic reviews.

Microsoft EA Renewal Playbook

The full microsoft ea renewal playbook framework from the Microsoft Practice.

Microsoft renewal moves, the EA framework, the M365 SKU framework, the Copilot framework, and the buyer side moves across the full Microsoft estate.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

No spam. We will only email you about this download. Privacy.
Run the Microsoft 365 license optimizer against your estate in under five minutes.
Open the Tool →
4
Core Tiers
3
Common Add Ons
60%
Typical Mixed Tier
90 days
Pre Renewal Move
100%
Buyer Side

When an enterprise upgrades to E5 for the security suite, P2 comes along. The price story only works if the security features actually get used.

IAM Lead
Global services firm
Deep Library

More on this topic.

Microsoft Practice →
Microsoft EA renewal playbook on a desk
Microsoft
Microsoft EA Renewal Playbook
Twelve month sequence, leverage points and clause posture for the next Microsoft EA renewal.
12 min read
Microsoft EA discount negotiation
Microsoft
Microsoft EA Discount Levers
The discount bands buyers actually achieve by spend tier, SKU mix and renewal posture.
10 min read
Microsoft 365 E3 vs E5 comparison
Microsoft
Microsoft 365 E3 vs E5
Where E5 actually pays back, where it does not, and how to mix tiers without overpaying.
9 min read
Microsoft 365 Copilot licensing
Microsoft
M365 Copilot Licensing
How Copilot is metered, where the cost surprises hide, and how to phase the rollout.
11 min read
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Get Microsoft identity intelligence in your inbox

Buyer side Microsoft updates every fortnight. No spam. Independent and unfiltered.