Skip to content
Browse all topics

Do I need Microsoft 365 E5 for Conditional Access?

No. Conditional Access needs Microsoft Entra ID P1, which is included in Microsoft 365 E3, Business Premium, and the F3 frontline plan. E5 adds Entra ID P2, which unlocks sign-in-risk and user-risk conditions via Identity Protection, plus Privileged Identity Management and access reviews.

What P1 gives you

  • The full Conditional Access policy engine — device, location, application, sign-in frequency, session controls.
  • Named locations and trusted networks.
  • MFA enforcement per app and per user.
  • Report-only mode for staging policies before enforcement.

What P2 adds on top

  • Sign-in risk and user-risk as CA conditions (Identity Protection).
  • Privileged Identity Management for just-in-time role activation.
  • Access reviews and Entitlement Management access packages.
  • Workload Identities premium for Conditional Access on service principals.

If the goal is a solid Conditional Access baseline (block legacy auth, require MFA, require compliant device), P1 is enough. Reach for P2 when the security team wants risk-based policies or when PIM becomes the operating model for admin roles.

Read next

Other questions