Do I need Microsoft 365 E5 for Conditional Access?
No. Conditional Access needs Microsoft Entra ID P1, which is included in Microsoft 365 E3, Business Premium, and the F3 frontline plan. E5 adds Entra ID P2, which unlocks sign-in-risk and user-risk conditions via Identity Protection, plus Privileged Identity Management and access reviews.
What P1 gives you
- The full Conditional Access policy engine — device, location, application, sign-in frequency, session controls.
- Named locations and trusted networks.
- MFA enforcement per app and per user.
- Report-only mode for staging policies before enforcement.
What P2 adds on top
- Sign-in risk and user-risk as CA conditions (Identity Protection).
- Privileged Identity Management for just-in-time role activation.
- Access reviews and Entitlement Management access packages.
- Workload Identities premium for Conditional Access on service principals.
If the goal is a solid Conditional Access baseline (block legacy auth, require MFA, require compliant device), P1 is enough. Reach for P2 when the security team wants risk-based policies or when PIM becomes the operating model for admin roles.
Read next
- Entra ID Conditional Access design— Designing a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
- Microsoft 365 E3 vs E5 — what's worth the upgrade— A practical comparison of Microsoft 365 E3 and E5 plans — what E5 adds, where the value sits, and step-up patterns.
- The Entra Suite explained— Entra Suite explained: Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection in one licence — what each does and when it pays.