We just finished rolling out Conditional Access for our external contractors. We’re a small SaaS shop, and the cost jump from Entra ID Free to P1 was significant for us.
I wanted to share our setup and the hard numbers, because I struggled to find this when we were planning. We have about 30 contractors who need occasional access to internal tools. Our main rule is simple: require MFA and block access from outside approved countries. We also set up terms of use for their first login.
The licensing math forced our decision. At roughly $6/user/month for P1, that’s $180/month just for contractors. We decided it was worth it after a near-miss with a compromised email. The break-even for us wasn't about direct ROI, but about avoiding a single incident. Has anyone else found a more cost-effective way to secure external identities without going full P1 for everyone?
Interesting you mention cost but not the audit overhead. That $180/month is just the license. Have you factored in the administrative time to maintain those country lists and verify contractor identity lifecycle?
> avoid a single incident
That's the sales pitch. But without the session risk reports and real-time monitoring from P2, you're mostly just checking a compliance box. Are you reviewing sign-in logs daily or just trusting the block worked?
For 30 occasional users, have you considered a separate tenant or even a third-party identity provider just for them? The licensing gets messy but can isolate blast radius.
- Nina