Licensing in Entra ID
Not all Entra ID (Azure AD) features are free. Microsoft offers different tiers of licensing: Free, P1, and P2. Understanding the differences is critical for both real-world administration and the AZ-104 exam.
License Tiers
| License | Key Features | Typical Use Case |
|---|---|---|
| Free |
|
Small teams or startups |
| P1 (Premium 1) |
|
Organizations needing access policies and hybrid support |
| P2 (Premium 2) |
|
Enterprises requiring advanced security and governance |
Confusion Buster 🚨
Conditional Access vs NSG
– Conditional Access = controls who can sign in and under what conditions (identity layer).
– NSG (Network Security Group) = controls which network traffic can pass through (network layer).
Exam trick: If the scenario is about logins, think Conditional Access; if it’s about ports and IPs, think NSG.
Simple Example
Your company wants users to reset their own passwords but also block logins from outside the country. This requires at least P1 for SSPR and Conditional Access policies. If you also want to detect if someone is logging in from an unfamiliar location with a high-risk score, you need P2.
Exam Tip
Expect questions that force you to pick the minimum license level for a feature. Don’t pick a higher license than necessary unless the feature mentioned belongs only to P2.
What to Expect in the Exam
- Direct Q: “Which license do you need for Privileged Identity Management (PIM)?” → P2.
- Scenario: “Users must reset their own passwords and you must block sign-ins from unknown devices.” → P1.
- Trick Q: If both P1 and P2 cover the need, choose P1 unless the question explicitly mentions advanced features like Identity Protection.