Skip to content
Notifications
Clear all

Is Microsoft Entra ID Premium P2 worth the price for 500 users?

2 Posts
2 Users
0 Reactions
3 Views
(@adams)
Estimable Member
Joined: 1 week ago
Posts: 64
Topic starter   [#7561]

Looking at a renewal. Current cost for Entra ID P2 for 500 users is significant. Need to justify the premium over P1 or even free tier.

We use conditional access, identity protection, and privileged identity management. But are we actually using them to their full potential? The risk reports are useful, but the automated remediation in P2 feels limited. PIM is good for audit but adds overhead for admins.

Is the tangible risk reduction worth the price? Specifically for a 500-seat org. Would like to hear from others on actual ROI, not vendor feature sheets. What are you actually blocking with CA that P1 couldn't do? Are the identity protection alerts leading to real actions?



   
Quote
(@chrisg)
Estimable Member
Joined: 1 week ago
Posts: 75
 

I'm a platform engineer at a 400-person fintech, we've run Entra ID P2 in prod for 3 years with full CA, PIM, and identity protection.

* **Target audience**: This is an enterprise compliance/security play. For a 500-seat org, it's justifiable if you're in a regulated space (finance, healthcare). If you're a low-risk SaaS shop, P1 likely covers your needs.
* **Real cost vs. P1**: At 500 users, P2 is roughly $9/user/month vs. $6 for P1. That's ~$18k/year extra. The hidden cost is the 0.5 FTE of security admin time to manage PIM workflows and review identity protection alerts.
* **Where P2 clearly wins**: Automated risk remediation. P1 only gives reports; P2 lets you enforce CA policies on risky sign-ins automatically. We block legacy auth and force MFA on medium+ risk, which stops about 10-15 suspicious attempts per week that P1 would have just reported on.
* **Honest limitation**: The automated remediation *is* limited. You can't write custom playbooks. The out-of-box policies are basic (require MFA, block access). For advanced response, you still need a SIEM.

I'd renew P2 if you have compliance audits (SOC2, ISO27001) or handle any sensitive customer data. The PIM audit trail alone satisfies many control requirements. If you're just using it for basic SSO and MFA, drop to P1. Tell us your industry and whether you've had a security incident in the last 24 months.


YAML all the things.


   
ReplyQuote