Hey there! Today, we're diving into something that might seem a bit daunting at first: Microsoft Entra ID Governance Licensing. But fear not! By the end of this post, you'll be navigating these waters like a pro. Let’s get started, shall we?
What’s the Buzz About?
Microsoft recently rolled out some clarifications on Entra ID Governance licensing. This is great news because it means we get a clearer picture of what's included and how we can make the most of it. Think of it as getting a map for your treasure hunt—way less wandering and more finding the gold!
Alright, let's break it down into bite-sized chunks:
Choosing the right license is like picking the perfect ice cream flavor. Here’s a quick rundown of your options:
- Free: Comes with your Microsoft cloud subscriptions like Microsoft 365.
- Entra ID P1: Available standalone or with Microsoft 365 E3/Business Premium.
- Entra ID P2: Available standalone or with Microsoft 365 E5.
- Entra ID Governance: An advanced package for P1 and P2 users, offering top-tier identity governance features.
To get the most out of Entra ID Governance, you’ll need to have the right prerequisites. Depending on your chosen package, you might need an active subscription to Entra ID P1, P2, or other compatible Microsoft products.
| Feature | Free | Microsoft Entra ID P1 | Microsoft Entra ID P2 | Microsoft Entra ID Governance |
| API-driven provisioning | + | + | + | |
| HR-driven provisioning | + | + | + | |
| Automated user provisioning to SaaS apps | + | + | + | + |
| Automated group provisioning to SaaS apps | + | + | + | |
| Automated provisioning to on-premises apps | + | + | + | |
| Conditional Access - Terms of use attestation | + | + | + | |
| Entitlement management - Basic entitlement management | + | + | ||
| Entitlement management - Conditional Access Scoping | + | + | ||
| Entitlement management MyAccess Search | + | + | ||
| Entitlement management with Verified ID | + | |||
| Entitlement management + Custom Extensions (Logic Apps) | + | |||
| Entitlement management + Auto Assignment Policies | + | |||
| Entitlement management - Directly Assign Any User(Preview) | + | |||
| Entitlement management - Guest Conversion API | + | |||
| Entitlement management - Grace Period(Preview) | + | + | ||
| My Access portal | + | + | ||
| Entitlement management - Microsoft Entra Roles (Preview) | + | |||
| Entitlement management - Sponsors Policy | + | |||
| Privileged Identity Management (PIM) | + | + | ||
| PIM For Groups | + | + | ||
| PIM CA Controls | + | + | ||
| Access Reviews - Basic access certifications and reviews | + | + | ||
| Access reviews - PIM For Groups | + | |||
| Access reviews - Inactive Users reviews | + | |||
| Access Reviews - Inactive Users recommendations | + | + | ||
| Access reviews - Machine learning assisted access certifications and reviews | + | |||
| Lifecycle Workflows (LCW) | + | |||
| LCW + Custom Extensions (Logic Apps) | + | |||
| Identity governance dashboard | + | + | + | |
| Insights and reporting - Inactive guest accounts | + |
With the right license, you can:
- Automate user provisioning and access reviews.
- Use entitlement management to streamline access packages.
- Implement lifecycle workflows for smooth onboarding and offboarding.
- Leverage Privileged Identity Management (PIM) to secure privileged roles.
FAQs: Your Burning Questions Answered
Do I need to assign licenses to each user? Nope! But you need enough license seats for all users in scope or those configuring the features.
What about business guests? Business guests also need licenses, but a new model for these licenses is coming soon, offering more flexibility.
What happens if a license expires? Features like PIM will no longer be available, but permanent role assignments remain unaffected.
Wrapping Up
Microsoft Entra ID Governance is your ally in managing identities and ensuring compliance. With the right licenses, you can unlock powerful features that streamline operations and enhance security. Ready to get started? Dive into the Entra ID Governance world and make identity management a breeze!
