If you manage Microsoft 365 tenants for clients, you have almost certainly been asked what Microsoft Entra ID Protection costs, and whether P1 is good enough. The short answer is that P1 is $7.00 per user per month, P2 is $10.00, and for ID Protection specifically, P1 buys you very little.
This piece works through Microsoft's published pricing and its own licensing table, prices it at the scale an MSP actually operates, and then covers the part that neither tier addresses: Entra ID Protection is a detection product, not a recovery product.
Every figure and quotation below is taken from Microsoft's own pages, retrieved 14 August 2026, and linked at the end. Microsoft changes pricing and packaging, so re-check before you quote a client.
The list prices
From the Microsoft Entra plans and pricing page, as of 14 August 2026, all tiers billed annually:
**Microsoft Entra ID Free** — included with Microsoft cloud subscriptions.
**Microsoft Entra ID P1** — $7.00 user/month, paid yearly, annual commitment.
**Microsoft Entra ID P2** — $10.00 user/month, paid yearly, annual commitment.
**Microsoft Entra Suite** — $12.00 user/month, paid yearly, annual commitment.
The step from P1 to P2 is $3.00 per user per month. That $3 is where essentially all of ID Protection lives.
What P1 actually includes for ID Protection
Microsoft's ID Protection documentation opens its licensing section with a single sentence: "Using this feature requires Microsoft Entra ID P2 licenses." The table beneath it is more specific, and worth reading closely before you position P1 to a client as an identity-security tier.
**Risk policies** — sign-in and user risk policies, the automation that actually blocks or challenges a risky sign-in. Free: No. P1: **No**. P2: Yes.
**Security reports, Overview** — Free: No. P1: **No**. P2: Yes.
**Risky users** — Free and P1 both get, in Microsoft's words, "Limited Information. Only users with medium and high risk are shown. No details drawer or risk history." P2 gets full access.
**Risky sign-ins** — Free and P1 again get "Limited Information. No risk detail or risk level is shown." P2 gets full access.
**Risk detections** — Free: No. P1: "Limited Information. No details drawer." P2: Full access.
**Users-at-risk alerts and the weekly digest** — P1: No, on both. P2: Yes.
**Microsoft Graph, all risk reports** — P1: **No**. P2: Yes. This is the one that catches MSPs building automation: you cannot pull risk data via Graph on P1.
Read as a whole: on P1 you can see that some users are risky, without being told why, without history, without alerting, without API access, and without the ability to act on it automatically.
Workload identity risk is a separate SKU again — Microsoft requires Workload Identities Premium for the risky workload identities report. And several detections (impossible travel, suspicious inbox rules, anonymous IP activity) are fed by Microsoft Defender products, so they need the relevant Defender licence on top. Microsoft 365 E5 covers those signals.
What this costs at MSP scale
Take one 500-seat client on P2 at list: 500 x $10.00 = $5,000 per month, $60,000 per year, for identity risk detection on a single tenant.
Now take ten such clients. That is $600,000 a year of pass-through licensing flowing through your P&L. Most of it is not margin — it is Microsoft's revenue that you invoice, collect, and carry the credit risk on.
None of that is an argument against P2. Risk-based Conditional Access is genuinely good, and for many clients it is the correct purchase. It is an argument for being precise about what the money buys, because the next question a client asks is usually the one nobody has a good answer to.
The question P2 does not answer
"Someone deleted a Conditional Access policy last Tuesday. Can we put it back?"
ID Protection does not answer that. It is a detection and response product: it tells you a sign-in looked compromised, and it can challenge or block that sign-in. It does not keep a copy of your tenant configuration. It has no version history for Conditional Access policies, no record of what your role assignments looked like last month, and no undo of its own. Microsoft Entra Backup and Recovery, which shipped separately, now covers part of this — seven days of retention, supported object types only. We work through exactly what it does and does not reach in a companion article.
For deleted objects, Microsoft is explicit about the boundary. From its documentation on restoring deleted users: "After you delete a user, the account remains in a suspended state for 30 days… After that 30-day window passes, the permanent deletion process automatically starts and can't be stopped."
And then the sentence that matters most: "After a user is permanently deleted, neither you nor Microsoft Support can restore them."
Thirty days is a generous window for a deletion someone notices. It is a short one for a misconfiguration nobody notices — a Conditional Access policy quietly narrowed, a role assignment added, a group's membership rewritten. Those changes do not go to a recycle bin at all.
Detection tells you something happened. Recovery puts it back. They are different products, and a licence tier that is excellent at the first does not become the second at a higher price point.
What an independent copy changes
This is the gap VentraID is built for. It takes its own copy of the tenant configuration, on your schedule, and keeps it somewhere the tenant cannot reach.
**33 object types**, including Conditional Access policies, named locations, role assignments, PIM policies, app registrations, service principals, groups, users and administrative units.
**Snapshots up to every 5 minutes** with continuous protection enabled, or on a fixed 6x, 4x, 2x or once-daily cadence.
**Point-in-time restore per object.** Choose a snapshot, choose what to bring back. Restores are approval-gated: a request is raised, an administrator approves it, and every step is written to a tamper-evident audit trail.
**Drift detection with field-level detail.** When a service principal is disabled or a policy is narrowed, you get the object, the field, the previous value and the new one.
**Retention configurable to seven years**, with disposition enforced and audited, and every snapshot SHA-256 hash-chained to the one before it so the history can be proven intact.
Priced per tenant, not per seat
One structural note, because it changes the arithmetic for anyone managing more than a handful of tenants.
Identity protection is almost always sold per user. That means the cost of protecting a directory scales with headcount, even though the thing being protected — the configuration — does not get meaningfully larger when a client hires twenty people.
VentraID is priced per tenant: $49, $99, $199 or $349 per month depending on tier. A 500-seat client and a 50-seat client cost the same to protect at the same tier. Growth stops being a tax on protection.
That is not a replacement for P2. If you need risk-based Conditional Access, buy P2. It is a complement, and it answers the question P2 cannot.
Sources
Pricing: Microsoft Entra plans and pricing, microsoft.com/en-us/security/business/microsoft-entra-pricing, retrieved 14 August 2026.
Licensing table and the "requires Microsoft Entra ID P2 licenses" quotation: What is Microsoft Entra ID Protection, learn.microsoft.com/en-us/entra/id-protection/overview-identity-protection, documentation updated 10 February 2026, retrieved 14 August 2026.
Deletion and restore quotations: Restore or permanently remove a recently deleted user, learn.microsoft.com/en-us/entra/fundamentals/users-restore, documentation updated 18 June 2026, retrieved 14 August 2026.
Microsoft revises pricing and packaging without notice. Verify current figures before quoting them to a client.