Conditional Access requires this Entra licence, as does protecting on-premises AD with Password Protection.
Also called P1 / P2.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Entra ID P1 in context, with comparison tables and the common traps.
Terms in this definition
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Licence
What entitles one particular user to the services a subscription offers. Each product licence is made up of several service plans (one per app or service), and before giving it to someone an admin has to record that user's usage location.
Related terms
- App launchers
Here administrators group related apps into My Apps collections, each appearing as a separate tab for users. It sits in the Enterprise apps blade, needs Entra ID P1 or P2, and only organises apps people could already open rather than granting new access.
- Conditional Access insights and reporting
Using sign-in data sent to a Log Analytics workspace, this workbook estimates what all your Conditional Access policies, report-only ones included, would do together over a chosen window between 4 hours and 90 days. It needs an Entra ID P1 licence and a role of Security Reader or above.
- F1
A licence for frontline staff that lets them open, but not edit, documents in the browser or on mobile; desktop Office apps aren't included. Entra ID P1 comes bundled.
- F3
A frontline plan giving fully editable Microsoft 365 apps in browsers and on small-screen mobile devices, without desktop versions. Entra ID P1 is bundled.
- Group-based licensing
Licence assignment made to the direct members of a security-enabled group, requiring Entra ID P1 or P2. Members of nested groups are not included, and a licence a user inherits cannot be removed from that user directly.
- MDM user scope
Set to All, Some or None in Microsoft Entra, it governs automatic Intune enrolment: whose Windows devices get enrolled once they are joined, or once a work account is added. Entra ID P1 or P2 is required.
- Microsoft Graph activity logs
With Entra ID P1 or P2, a diagnostic setting can stream a record of each HTTP request your tenant makes to the Microsoft Graph API into the MicrosoftGraphActivityLogs table.
- Role-assignable group
Entra group, requiring Entra ID P1, that can be given directory roles because it was created with
isAssignableToRole = true. Membership must be assigned, groups cannot nest, and the flag cannot be set afterwards.