Skip to content

Entra ID Licensing Guide

What is Microsoft Entra ID? (Formerly Azure Active Directory)

Section titled “What is Microsoft Entra ID? (Formerly Azure Active Directory)”

Microsoft Entra ID (formerly known as Azure Active Directory, or Azure AD) is Microsoft’s cloud-based identity and access management service. It provides essential tools for managing users, groups, and access to resources in your organization, such as Microsoft 365, the Azure portal, and thousands of other SaaS applications.

Entra ID serves as the backbone for secure user authentication, identity protection, and access control in the cloud and on-premises environments. It also integrates with your on-premises Active Directory (AD) to provide a seamless experience for hybrid environments.


FeatureCapabilityBusiness Value
User AuthenticationSecure multi-factor authentication (MFA) and single sign-on (SSO)Ensures only authorized users access your resources
Conditional AccessPolicy enforcement based on security conditionsControls access based on device compliance and location
Identity ProtectionMachine learning and behavioral analyticsDetects and responds to identity risks and compromised accounts
Access ManagementPermission control and role-based access control (RBAC)Manages application and resource access effectively
B2B and B2C CapabilitiesExternal collaboration and customer identity managementEnables secure partnerships and customer-facing applications
Self-Service CapabilitiesSelf-service password reset (SSPR) and profile managementReduces IT workload and improves user experience

Microsoft Entra ID offers various licensing tiers to meet different organizational needs and sizes:

Ideal for: Small organizations with minimal identity management needs

Features:

  • Basic user and group management
  • SSO for up to 10 apps
  • Self-service password change for cloud users

Ideal for: SMB customers, usually included with Business Premium or EMS E3

Core Features:

  • Conditional Access
  • Role-based access control (RBAC)
  • Advanced group management (dynamic groups, naming policies, expiration)
  • Cross-tenant user synchronization
  • Multitenant organizations
  • Session lifetime management
  • Global password protection and management
  • Application launch portal and user collections

Entra ID Governance Features:

  • Automated user provisioning to SaaS and on-premises apps
  • HR-driven provisioning
  • Terms-of-use attestation

Entra Verified ID Features:

  • Verifiable credentials issuance and verification

Includes: All P1 features plus advanced security and governance

Advanced Governance Features:

  • Basic access certifications and reviews
  • Basic entitlement management
  • Privileged identity management

Advanced Protection Features:

  • Risk-based conditional access
  • Real-time dynamic sign-in and user assessment
  • Authentication context (step-up authentication)
  • Device and application filters for conditional access
  • Token protection
  • Vulnerabilities and risky account detection
  • Risk event investigation

Requires: Basic Entra ID P1 licenses

Additional Governance Features:

  • Machine learning-assisted access certifications and reviews
  • Entitlement management custom extensions (Azure Logic Apps)
  • Lifecycle workflows
  • Identity governance dashboard

Additional Verified ID Features:

  • High-assurance entitlement management
  • Face Check high-assurance facial matching verification

Internet Access Features:

  • Universal conditional access
  • Traffic logging and policy monitoring
  • Web category and FQDN filtering

Private Access Features:

  • Identity-centric Zero Trust network access (ZTNA)
  • Conditional access across private apps
  • Adaptive multifactor authentication
  • Seamless SSO access

ProductPurposeKey Benefits
Entra ID GovernanceSecure access to internet and SaaS applicationsAutomate approvals, reduce access abuse, ML-powered insights
Entra Workload IDControl workload identity accessReduce risk exposure, comprehensive health-check view
Entra Domain ServicesManage domain services in the cloudNo domain controllers needed, Azure VM integration
Entra Verified IDDigital credential verificationIssue/verify credentials, facial matching, reduce vulnerabilities
Entra External IDExternal identity managementSecure customers/partners, frictionless experiences
Entra Permissions ManagementMulticloud permission managementEnforce least privilege, prevent breaches across AWS/Azure/GCP

  • Basic plans: Include basic Entra ID functionality with SSO and user management
  • Business Premium: Includes Entra ID P1 with advanced conditional access
  • Enterprise E3: Includes Entra ID Premium P1
  • Enterprise E5/E5 Security: Includes Entra ID P2 with advanced security features

Microsoft Entra ID is a powerful cloud-based identity management solution designed to secure user access and protect your organization’s resources. With a comprehensive range of licensing options, it meets the needs of businesses of all sizes, ensuring a flexible, secure, and scalable solution for managing identities in hybrid and multi-cloud environments.

Key Takeaway: Understanding the Entra ID licensing model is essential for leveraging the right tools and security features as your organization grows.