Skip to content

Enterprise Mobility and Security Licensing Guide

Enterprise Mobility + Security (EMS) Licensing Guide

Section titled “Enterprise Mobility + Security (EMS) Licensing Guide”

Microsoft Enterprise Mobility + Security (EMS) is a comprehensive solution that combines identity and access management, mobile device management, and advanced security capabilities. EMS is available in two primary plans: E3 and E5, each offering different levels of security and management capabilities to meet various organizational needs.


FeatureEMS E3EMS E5
Price$8.80 per user/month$14.80 per user/month
Azure AD PremiumP1P2
Microsoft Intune
Azure Information ProtectionP1P2
Advanced Threat Analytics
Cloud App Security
Azure Advanced Threat Protection
Risk-Based Conditional Access

Ideal for: Organizations looking for basic security tools at a lower cost, including mobile device management and manual document protection.

EMS E3 provides essential identity and security capabilities for organizations starting their digital transformation journey.

ComponentCapabilityBusiness Value
Azure Active Directory Premium P1SSO, MFA, basic conditional accessCore identity and access management
Microsoft IntuneMobile device management (MDM) and mobile application management (MAM)Secure data across devices
Azure Information Protection P1Manual classification and labeling of documentsBasic data protection and tracking
Microsoft Advanced Threat AnalyticsUser behavior analysis for threat detectionProtection against insider threats
Windows Server CALDevice access rights for Windows Server servicesServer access licensing

Ideal for: Businesses requiring advanced threat detection, privileged access management, and automated document classification.

EMS E5 includes all E3 features plus advanced security and identity protection capabilities.

ComponentCapabilityBusiness Value
Azure Active Directory Premium P2Risk-based conditional access, Privileged Identity Management (PIM)Advanced identity protection and admin control
Azure Information Protection P2Automatic classification and labeling based on contentEnhanced data protection automation
Microsoft Cloud App Security (CASB)Cloud access security broker for Microsoft and third-party appsComprehensive cloud app security
Azure Advanced Threat ProtectionIdentity-based attack detection and network monitoringSophisticated threat detection
Risk-Based Conditional AccessAutomated responses to risky user behaviorsAdaptive security controls

AreaEMS E3EMS E5
Identity ManagementBasic SSO, MFA, conditional accessAdvanced risk-based access, PIM
Cloud App SecurityNot includedFull CASB capabilities
Information ProtectionManual classification onlyAutomatic classification and enhanced controls
Advanced Threat ProtectionBasic behavioral analysisSophisticated identity and cloud threat detection

Ideal for: Organizations beginning their identity and mobile device management journey.

BenefitDescription
Cost EfficiencyAt $8.80 per user/month, provides cost-effective identity and device management
Basic Identity ManagementCore capabilities like SSO, MFA, and conditional access
Gradual AdoptionAllows organizations to establish identity foundation before adding complexity

Ideal for: Organizations with mature identity frameworks requiring advanced security capabilities.

BenefitDescription
Advanced Security NeedsRisk-based conditional access and PIM for enhanced control
Comprehensive ProtectionCASB for third-party cloud app security
Future-ProofingAdvanced threat protection for evolving security landscape
AutomationAutomatic document classification reduces manual overhead

  1. Cost-Effective Start: Begin with EMS E3 to establish basic identity and device management
  2. Gradual Maturity: Build security processes and user adoption before advanced features
  3. Strategic Upgrade: Move to EMS E5 when security needs become more complex
  4. Maximized ROI: Ensure full utilization of each tier’s capabilities before upgrading

Key Insight: This phased approach allows businesses to start small, optimize their identity management processes, and then expand into more advanced security measures as needed.


  • Needs basic identity management and mobile device control
  • Has limited security budget but requires essential protection
  • Is starting digital transformation initiatives
  • Prefers manual document classification processes
  • Requires advanced threat detection and response
  • Needs privileged access management and audit capabilities
  • Must secure multiple cloud applications with CASB
  • Wants automated data classification and protection
  • Has complex compliance requirements

Key Takeaway: The choice between EMS E3 and EMS E5 depends on your organization’s security maturity, compliance requirements, and budget considerations. E3 provides a solid foundation for identity and device management, while E5 delivers advanced capabilities for sophisticated security environments.

Both plans offer scalable solutions that can grow with your organization’s needs, ensuring you have the right level of protection at every stage of your security journey.