Identra

Solutions / Entra ID P2

Entra ID P2 implementation for tenants paying for it and not using it.

Most tenants on Microsoft 365 E5 or EMS E5 pay for Entra ID P2 every month but only use the P1 subset of features. The three P2-only capabilities (Entra ID Protection, Privileged Identity Management, Access Reviews) are the ones auditors ask about most and the ones IT teams put off implementing because they touch identity policy. Identra runs the full P2 implementation as a fixed-scope engagement so the licensed capabilities become working configuration.

Product
Microsoft Entra ID P2
License requirement
M365 E5, EMS E5, or Entra ID P2 standalone
Delivery mode
Remote-first, US timezone
Delivery
Fixed scope, fixed price

01 / What we configure

Three P2-only capabilities, one implementation engagement.

  • 01

    Entra ID Protection

    Sign-in risk policy and user risk policy configured. Risk detection sources tuned (Entra ID Protection uses signals from Microsoft threat intelligence, Defender for Identity, and Cloud App Security). Weekly review workflow assigned to the security operations lead. Investigation runbook drafted.

    Sign-in riskUser riskRisk investigation
  • 02

    Privileged Identity Management

    PIM turned on for all privileged Entra roles. Activation requires MFA, justification, and (for GA and other high-impact roles) approver decision. Break-glass accounts isolated. Sentinel workbook produces the audit trail. Quarterly access review scheduled.

    PIM eligibleApprovalSentinel workbook
  • 03

    Access Reviews

    Recurring reviews on privileged Entra roles, business-critical applications, and guest accounts. Access packages defined for common request patterns. Entitlement management workflow for cross-group access. Lifecycle Workflows integrated with the HR system so joiner/mover/leaver runs automatically.

    Access reviewsAccess packagesLifecycle

02 / What it looks like

Three P2 implementation engagements.

Different starting states, same underutilised P2 licence.

IT Director at a 1,500-user professional services firm

Situation. M365 E5 in place for two years. Team knows P2 is licensed but has never turned on PIM or ID Protection. Recent phishing incident exposed the gap: no sign-in risk policy to block the compromised account before data exfiltration.

Outcome. ID Protection sign-in and user risk policies configured. Compromised-account playbook wired to Sentinel automation. PIM turned on for privileged roles. Full P2 stack live inside 10 weeks. Post-implementation exercise: identical phishing test blocked automatically.

CISO at a US SaaS company

Situation. SOC 2 Type II auditor asked for evidence of periodic access review on business-critical applications and privileged-role review cadence. Existing evidence was a hand-drafted spreadsheet updated annually.

Outcome. Access Reviews configured on privileged Entra roles (quarterly) and business-critical application groups (semi-annual). PIM turned on with quarterly review of eligible assignments. Auditor accepted the Access Review completion records as evidence.

Security Officer at a US healthcare organisation

Situation. HIPAA audit produced finding on access-review cadence and privileged-access monitoring. Team had M365 E5 but had never used the P2 features to address the findings.

Outcome. ID Protection, PIM, and Access Reviews all live. HIPAA-specific access review packages defined per PHI-adjacent system. Sentinel workbook exports the PIM activation log per §164.312(b) audit control. Finding closed at the next audit cycle.

03 / Frequently asked

What buyers ask first.

What is the difference between Entra ID P1 and P2?
P1 (included with M365 E3, EMS E3, Business Premium) provides Conditional Access, self-service password reset, and basic MFA. P2 (included with M365 E5, EMS E5) adds three capabilities that P1 does not have: Entra ID Protection (risk-based CA), Privileged Identity Management, and Access Reviews. P2 also unlocks Access Packages, Entitlement Management, and Lifecycle Workflows.
If we have M365 E5, do we already have P2?
Yes. Entra ID P2 is included in M365 E5 and EMS E5. If you licensed M365 E5 you already pay for P2. The reason many tenants do not use P2 is that turning it on requires policy work (risk thresholds, approver assignment, review scoping) that IT teams put off because it touches identity policy end-users see.
How does sign-in risk work?
Entra ID Protection scores every sign-in on a real-time risk scale (No risk / Low / Medium / High) based on signals like unfamiliar sign-in properties, malware-linked IP, anonymous IP, and Microsoft threat intelligence. The sign-in risk policy takes an action based on the score: block the sign-in, require step-up MFA, or require password change plus MFA. Threshold tuning is part of the implementation.
Do you cover Access Package design as part of the engagement?
Yes. Access Packages are defined for common request patterns (contractor onboarding, project team access, guest collaboration, developer environment access) as part of the Access Reviews workstream. Access Packages let end users self-service request access via a defined workflow rather than filing IT tickets, which reduces the operational load of access provisioning.
How long does a P2 implementation take?
Typical implementation runs 8 to 12 weeks. Weeks 1 to 2 assess existing P1 configuration and confirm P2 licence coverage. Weeks 3 to 6 configure ID Protection risk policies, PIM eligible role set, and Access Review cadence. Weeks 7 to 12 stage enforcement of risk policies, run the first quarterly access review, and hand over runbooks.

Next step

Book an Entra P2 scoping call.

Thirty minutes on your current P1 configuration, P2 licence coverage, and target rollout timeline. Written scoping note within two business days.