{"id":46305,"date":"2023-01-27T06:13:53","date_gmt":"2023-01-27T11:13:53","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=46305"},"modified":"2024-08-15T18:01:14","modified_gmt":"2024-08-15T22:01:14","slug":"understanding-aad-premium-p1","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/understanding-aad-premium-p1","title":{"rendered":"Understanding Entra ID’s Premium P1 Tier"},"content":{"rendered":"\n
To better understand the structure of Entra ID\u00ae<\/sup>, we explore each tier of their service offerings in a four-part series. This is part two of the series.<\/em><\/em><\/p>\n\n\n\n Each article covers the benefits of a particular service, as well as the drawbacks that come with each tier. <\/em>Click here<\/em><\/a> to read our previous blog on Entra ID Free, or this one which covers <\/em>Entra ID’s Premium P2 Tier<\/em><\/a>.<\/em><\/p>\n\n\n\n Entra ID is a cloud-based user management platform often introduced to organizations via the purchase of a Microsoft 365\u2122 license or Azure subscription. IT teams start their organizations with Entra ID Free or Microsoft 365 apps (since those are included with a subscription to either service), but that SKU has limited functionality. It\u2019s not uncommon for organizations to upgrade their Entra ID instances to Premium P1 or P2 licenses just to get \u201cthat one thing\u201d or consume other Microsoft services that require the Premium SKUs.<\/p>\n\n\n\n Entra ID Premium P1 can be used entirely on its own to manage Microsoft 365\/Azure identities, as well as enact single sign-on (SSO) for pre-integrated web applications. It also integrates with Active Directory (AD) and has some federated authentication to interoperate with other identity provider (IdPs). It doesn\u2019t manage devices or external identities without additional subscriptions from Microsoft or additional identity management solutions from other vendors. <\/p>\n\n\n\n This article evaluates Entra ID Premium P1\u2019s capabilities as a standalone service, and explores how organizations can best utilize Entra ID Premium P1\u2019s services.<\/p>\n\n\n\n Entra ID Premium P1 offers the following features:<\/p>\n\n\n\n The premium features offered by Entra ID Premium P1 are attractive for Microsoft shops. However, there are drawbacks to consider with Entra ID Premium P1 as a holistic identity management solution.<\/p>\n\n\n\n Entra P1 integrates with on-premise Active Directory, but doesn\u2019t include services that are required to prevent lateral movement by attackers throughout the Microsoft stack. Workarounds are required to utilize core network protocols to secure and manage access to network devices. Devices serve as the gateway to access resources to work and leaving devices unmanaged fails to achieve a Zero Trust<\/a> security posture like Microsoft recommends<\/a>. Entra P1 will not manage devices without additional subscriptions from Microsoft or a different M365 SKU that has Intune<\/a>\u00ae<\/sup><\/em>.<\/p>\n\n\n\n Many admins just want to use MS Office, tighten up their security posture, and be business enablers by providing users with the solutions that they need. Organizations that adopt Microsoft become focused on rolling out its products instead of assisting business performance.<\/p>\n\n\n\n Microsoft licensing can be complex, and implementing best practices for Entra<\/a> takes a lot of work. License management and pricing can be complex\/unpredictable without understanding how everything interconnects and what features are included in each plan. Some features are gated off and require more services to run, including reporting for conditional access policies. Entra P1 is designed to work in conjunction with a directory service and lacks features most organizations find necessary to achieve SSO to everything. For example, no matter the subscription tier, Entra ID lacks the ability to manage user access to networks via RADIUS or LDAP unless you pay Microsoft more money and use more of its services.<\/p>\n\n\n\nWhat Is Entra ID Premium P1?<\/h2>\n\n\n\n
Benefits of Entra ID Premium P1<\/h2>\n\n\n\n
\n
Drawbacks of Entra ID Premium P1<\/h2>\n\n\n\n
Implementation<\/h3>\n\n\n\n
Many organizations may have to hire consultants to guide them through the migration. These challenges have given rise to a cottage industry<\/a> of consultants. Otherwise deploying all of these features leads to reskilling and new hires at market rates. This is due to the breadth of configurations and resulting complexity that Microsoft\u2019s enterprise features involve.<\/p>\n\n\n\nMissing Identity and Access Control Functionality <\/h3>\n\n\n\n
SSO to Everything<\/h4>\n\n\n\n