The Entra Suite explained
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Microsoft's Entra Suite bundles Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection into a single per-user licence. What each product does, how the bundle economics work, and when it's the right SKU.
The Microsoft Entra Suite is a single per-user licence that bundles five Entra products: Internet Access, Private Access, Verified ID (premium features), ID Governance, and Identity Protection. It replaces the "buy each one separately" pattern with one line item — the same shape Microsoft 365 E5 uses to bundle productivity plus security plus compliance.
If you have looked at deploying more than two of these products, the Suite is almost certainly cheaper than buying them separately. If you have only ever heard the phrase "Entra Suite" and don't know what's in it, this guide is the tour.
What each product does
Microsoft Entra Internet Access. A Secure Web Gateway (SWG) delivered as part of Global Secure Access. It routes user internet traffic through Microsoft's global edge, applies URL filtering, TLS inspection, and DLP, and enforces conditional access at the network layer. Competes with Zscaler Internet Access and Netskope.
Microsoft Entra Private Access. A Zero Trust Network Access (ZTNA) product, also part of Global Secure Access. It replaces the corporate VPN: users get per-application access to private resources (on-prem or Azure) with identity-based policy, not a network-level tunnel. Competes with Zscaler Private Access and Cloudflare Access.
Microsoft Entra Verified ID (premium). A verifiable-credentials service that lets an organisation issue and verify digital credentials — employment verification, education records, professional certifications. The free tier covers basic issuing; the premium features (in the Suite) add higher-volume verification, more issuer types, and integration into onboarding and IT-help-desk flows.
Microsoft Entra ID Governance. Access reviews, entitlement management (packaged access with approval workflows), lifecycle workflows (joiner/mover/leaver automation), and separation-of-duties enforcement. Competes with SailPoint, Saviynt, and (partially) Okta Identity Governance. This is one of the two heaviest components of the Suite by capability.
Microsoft Entra ID Protection. Real-time risk detection: leaked credentials, anonymous IP, unfamiliar sign-in, atypical travel, malware-linked IP, plus cumulative user-risk scoring. Feeds Conditional Access to enforce step-up or block automatically. This is what makes CA truly risk-adaptive.
Together, the five products cover identity governance, identity risk, secure remote access (via replacement of VPN), secure web access, and portable verifiable credentials — a substantial fraction of the modern identity-and-access toolbox.
What it costs
The Suite is priced per user per month. It is licensed on top of Entra ID P1 or P2 — the Suite is an add-on, not a standalone identity platform. Approximate 2026 published price is $12/user/month, but check the current pricing page — it moves.
Buying the five products individually adds up to substantially more, so the break-even on the Suite is low: use two or three of them and you have already saved money over standalone.
Microsoft 365 E5 does not include the Suite. E5 includes P2 (with Identity Protection) but not the Suite's Global Secure Access components, ID Governance, or premium Verified ID. Assuming "we have E5 so we have the Suite" is a common and expensive mistake — check the licensing detail.
When it's the right SKU
The Suite is the right pick when the organisation wants two or more of:
- To replace a legacy VPN with ZTNA (Private Access).
- To replace or supplement a third-party SWG (Internet Access).
- To run access reviews, entitlement management, and JML automation on Entra rather than a separate IGA product (ID Governance).
- To adopt verifiable credentials for onboarding or credential proof (Verified ID).
- To turn on real-time risk-adaptive Conditional Access (Identity Protection — already often licensed via P2, but included here).
Two typical decision profiles fit:
Consolidation-driven. The organisation runs a mix of point products (Zscaler + a small IGA + a homegrown JML workflow) and wants to consolidate onto Microsoft. Suite plus Entra ID P2 replaces the stack.
Zero-Trust adoption. The organisation is doing a Zero Trust push — replacing VPN, tightening CA, adopting risk-adaptive access, formalising access certification. The Suite is the natural bundle for that programme.
When it isn't
Two situations where the Suite is not the right pick.
Only one product needed. If ID Governance is genuinely the only piece needed and there is no ZTNA / SWG / Verified ID roadmap, buying ID Governance standalone is cheaper than the Suite. Same logic for any single component.
Existing third-party stack that's staying. If Zscaler and SailPoint are contractually locked in for another two years and rip-and-replace isn't happening, the Suite's coverage overlaps with the incumbent stack for that period. Wait until contract renewal.
Rollout order
If you have the Suite and want to deploy it, the sensible order is:
- Identity Protection. Fastest value — enable the risk-based CA policies, watch for a couple of weeks in report-only, enforce. Immediate lift on identity security posture.
- ID Governance access reviews. Turn on quarterly reviews on the highest-risk groups (admin roles, sensitive-file access) first. Grows into full entitlement management and lifecycle workflows over quarters.
- Global Secure Access Internet Access. Start with a pilot user group, tune the URL filtering, expand.
- Global Secure Access Private Access. Requires a mapping of internal apps and their access needs — this is the biggest project of the five and worth budgeting accordingly.
- Verified ID. Adopts naturally as the other pieces mature — issuing employment credentials, verifying at rehire, embedding in help-desk password reset.
Trying to deploy all five in parallel almost always ends badly — the change management overloads the identity team and the users. Sequenced deployment gets there faster in wall-clock terms.
Licensing prerequisites
The Suite is layered on top of the base Entra ID licences:
- Entra ID Free is not sufficient — the Suite needs P1 or P2 underneath.
- Entra ID P1 covers Conditional Access, group-based licensing, and self-service password reset.
- Entra ID P2 adds Identity Protection standalone and PIM (Privileged Identity Management).
For most enterprises the working combination is Entra ID P2 + Entra Suite, which delivers CA + PIM + Identity Protection + the four other Suite products. Microsoft 365 E5 + Entra Suite gets you E5's full compliance and Defender stack alongside; that's the pattern for enterprises going all-in on Microsoft security and identity.
The short version
Five Entra products under one licence: Internet Access, Private Access, Verified ID (premium), ID Governance, Identity Protection.
If you plan to use two or more of them, the Suite is cheaper than buying separately. If you're on a Zero Trust journey or consolidating from a mixed identity/access stack, it's the natural bundle. If you only need one component, buy that component alone.
E5 does not include the Suite — check before you assume.
Frequently asked questions
- What is included in the Entra Suite?
- Five products under one per-user licence: Entra Internet Access (secure web gateway), Entra Private Access (ZTNA VPN replacement), Verified ID premium features, Entra ID Governance (access reviews, entitlement management, lifecycle workflows), and Entra ID Protection (real-time risk detection feeding Conditional Access).
- Does Microsoft 365 E5 include the Entra Suite?
- No. E5 includes Entra ID P2 — which carries Identity Protection and PIM — but not the Global Secure Access components, ID Governance, or premium Verified ID. Assuming E5 includes the Suite is a common and expensive mistake; check the licensing detail.
- What are the prerequisites for the Entra Suite?
- An Entra ID P1 or P2 licence underneath — the Suite is an add-on, not a standalone identity platform, and Entra ID Free is not sufficient. The typical enterprise combination is Entra ID P2 plus the Suite.
- In what order should we deploy the Entra Suite products?
- Identity Protection first (fast value — report-only, then enforce), then ID Governance access reviews on the highest-risk groups, then Internet Access with a pilot group, then Private Access (the biggest project — it needs an internal-app inventory), and Verified ID as the rest matures. Deploying all five in parallel overloads the identity team.
Further reading
Spot something wrong or want a topic covered? Send it through the contact form.