Most companies with 200 to 5,000 employees run Microsoft 365 Business Premium or E3, and both include Microsoft Entra ID P1, not P2. That one letter decides whether you have Privileged Identity Management, risk-based Conditional Access, and the wider Defender attack disruption set. This page separates what your license already includes from what only P2, E5, or an add-on provides, then explains what Orbitra does at any license level. Every Microsoft statement comes from Microsoft Learn and is listed under Sources; for the terms, see the glossary and the guides.
What Entra ID P1 gives you on Business Premium and E3
Microsoft's licensing fundamentals page states that Entra ID P1 is standalone or included with Microsoft 365 E3 and Microsoft 365 Business Premium, while Entra ID P2 is standalone or included with Microsoft 365 E5. On P1 you have:
- Sign-in and audit logs, kept 30 days. The logs exist on every tier, but Microsoft's retention reference keeps them 7 days on Free and 30 days on P1 and P2. E5 does not extend this; only risky sign-ins go from 30 days on P1 to 90 days on P2.
- Export paths for longer history. Streaming logs to Azure Monitor and Log Analytics requires P1 or P2, and anything beyond 30 days needs diagnostic settings that send logs to a Log Analytics workspace, a storage account, or an event hub. Retention is not retroactive, so decide where evidence will live before you need it.
- Limited ID Protection views. On Free and P1 the risky users report shows only medium and high risk users with no details or history, the risky sign-ins report shows no risk detail or level, and detections arrive titled "Additional risk detected" because premium detections are visible only to P2 customers.
What only P2, E5, or an add-on adds
Privileged Identity Management
PIM provides eligible role assignments that must be activated before use, time-bound assignments, approval and MFA on activation, access reviews of role holders, audit history, and protection against removing the last active Global Administrator or Privileged Role Administrator. Using it requires Entra ID P2 or Microsoft Entra ID Governance, and licenses are needed for everyone with an eligible or time-bound assignment, everyone in PIM for Groups, and every approver. Two limits hold even after you buy it: PIM manages Entra roles, Azure resource roles, and groups, not application API permissions, OAuth consent grants, or service principal credentials, and it does not detect compromise or evaluate sign-in risk. If you stay on P1, our guide to privileged access in Entra without P2 covers role hygiene, emergency access accounts, and a small Global Administrator count.
Risk-based Conditional Access
Microsoft states that Entra ID P2 is required to use risk-based access policies; the license table marks sign-in and user risk policies as No for Free and P1 and Yes for P2 and Entra Suite. Premium detections such as Anomalous Token, Password spray, and Attacker in the Middle are visible only to P2 customers. On P1 you can see that something was flagged, but not what, and no policy can react to it.
Automatic attack disruption
Defender XDR's automatic attack disruption correlates signals to identify ransomware campaigns and other sophisticated attacks with high confidence, then contains the assets the attacker is using; Microsoft says it holds a confidence level of 99 percent or higher for containment actions. Its licensing list includes Microsoft 365 E5, E3 with the Defender Suite or EMS E5 add-on, individual Defender products, and Defender for Business. Plain E3 is not on the list. Business Premium qualifies through the Defender for Business it includes, which Microsoft designs for businesses up to 300 users, and whose page documents two disruption actions: containing a device by blocking its communication, and containing a user account by disconnecting the user's connections at the device level, when a human-operated attack is detected on an onboarded device. The Defender XDR page lists more, including Disable user, Revoke user session, and Suspend user in Entra. Either way, attack disruption is Microsoft's response to Microsoft's high-confidence incidents, not a policy your team writes about which identities to contain, when, and with what evidence.
Side by side: Business Premium or E3, E5, and Orbitra
| Capability | Business Premium or E3 (Entra ID P1) | E5 or add-on (Entra ID P2) | Orbitra, at either level |
|---|---|---|---|
| Just-in-time privileged roles (PIM) | Not included | Included with P2, ID Governance, or Entra Suite | Not a PIM. Shows who holds privileged roles and what they can reach; role removal is a governed response action that requires a named approver in Approve mode. |
| Risk-based Conditional Access | Not included | Sign-in and user risk policies | Not a policy engine. Deterministic detection rules on Entra sign-in and audit logs, detections in minutes. |
| Attack disruption | Defender for Business: contain device and contain user at the device level | Defender XDR action set, on high-confidence incidents | Human-initiated, approval-gated response from an allowlisted catalog, working alongside Defender. |
| Audit and sign-in log retention | 30 days | 30 days (risky sign-ins 90 days) | Evidence receipts with a SHA-256 content fingerprint that you export and keep; not a SIEM or a log archive. |
| Proof that a containment held | Read the tenant back yourself | Same; disrupted incidents carry an Attack Disruption tag | Independently re-reads Microsoft after supported response actions to verify the final state. |
Where Orbitra fits
Orbitra works at any Microsoft license level and alongside Microsoft native controls; it owns the governed response and evidence layer between detection and directory recovery. It connects through Microsoft Graph and Azure APIs with nothing installed on endpoints, starts read-only, and response permissions are consented separately. Response comes from an allowlisted catalog of more than two dozen governed response actions: review, approve, execute, verify. In Recommend mode, Orbitra proposes the response and your team executes it. In Approve mode, a named person signs off before Orbitra executes. Orbitra independently re-reads Microsoft after supported response actions to verify the final state, and every response produces an attributable evidence receipt with a SHA-256 content fingerprint. Every customer tenant uses Recommend or Approve today, and Autonomous mode has never executed in a customer tenant. See how it works.
What Orbitra provides at any license level
Orbitra is privileged identity response for Microsoft Entra ID and Azure, built for lean security teams without a dedicated identity specialist. None of it depends on P2:
- One graph of human and non-human identities. Users, groups, applications, service principals, OAuth grants, managed identities, roles, and Azure RBAC, with blast radius traversal that shows what an identity can reach before you act and what remains reachable after.
- Detection on the logs P1 already provides. More than 70 deterministic detection rules on Entra sign-in and audit logs, roughly 40 percent of them aimed at applications, service principals, consent grants, and app credentials, the surfaces PIM does not manage.
- Governed response with stated limits. Orbitra tells you which steps are permanent before you approve them, and rollback is provided where the provider action is truly reversible; otherwise Orbitra provides a defined recovery path.
- Evidence you keep beyond the 30 day window. Four timestamps per incident (signal observed, plan ready, action submitted, provider verified) and exports designed to support audit and insurer review.
See how Orbitra works with Microsoft for the permissions and data flow, and the lean security teams page for how a one to five person team runs it.
If you add P2 or E5 later
Nothing here argues against E5. PIM reduces standing privilege and risk-based Conditional Access adds a policy response to sign-in risk; Orbitra keeps working alongside both. One caution from Microsoft's licensing page: when a P2, Governance, or trial license lapses, eligible Entra role assignments and PIM configuration settings are removed, while permanent assignments are unaffected. Settle the license before you move administrators to eligible assignments.
Plans and next step
Orbitra is priced per tenant and per response pack on an annual term, quoted rather than published; see plans. To see the identity graph and the response catalog against your own tenant, request a demo.
Sources
- Microsoft Entra ID Governance licensing fundamentals, checked September 2026
- What is Microsoft Entra Privileged Identity Management, checked September 2026
- What is Microsoft Entra ID Protection, checked September 2026
- Risk-based access policies (Microsoft Entra ID Protection), checked September 2026
- What are risk detections (Microsoft Entra ID Protection), checked September 2026
- Automatic attack disruption in Microsoft Defender XDR, checked September 2026
- Configure automatic attack disruption capabilities, checked September 2026
- Automatic attack disruption in Defender for Business, checked September 2026
- What is Microsoft Defender for Business, checked September 2026
- Microsoft Entra data retention, checked September 2026
- Access activity logs in Microsoft Entra ID, checked September 2026
Frequently asked questions
Does Microsoft 365 Business Premium include Privileged Identity Management?
No. Business Premium and Microsoft 365 E3 include Entra ID P1. Microsoft's licensing fundamentals page says using PIM requires Entra ID P2 or Microsoft Entra ID Governance, which are add-ons or come with Microsoft 365 E5. Licenses are needed for every user with an eligible or time-bound assignment, every PIM for Groups member or owner, and every approver.
Can I use risk-based Conditional Access on E3 or Business Premium?
Not without P2. Microsoft states that Entra ID P2 is required to use risk-based access policies, and the license table marks sign-in and user risk policies as not available on Free and P1. On P1, detections arrive titled Additional risk detected without the detail behind them.
Does Defender for Business already respond to identity attacks for me?
Partly. Business Premium includes Defender for Business, and attack disruption is built in once devices are onboarded. The Defender for Business page documents two actions: containing a device by blocking its communication, and containing a user account by disconnecting the user's connections at the device level, triggered when a human-operated attack is detected on a device. It is Microsoft's response to Microsoft's high-confidence incidents, not a policy your team writes about which identities to contain and how to prove it.
Do I need E5 to use Orbitra?
No. Orbitra works at any Microsoft license level. It connects through Microsoft Graph and Azure APIs, starts read-only, and response permissions are consented separately. Detection runs on the Entra sign-in and audit logs your P1 license already provides.
How long does Entra keep sign-in and audit logs on Business Premium?
30 days. Microsoft's retention reference keeps audit and sign-in logs 7 days on Entra ID Free and 30 days on P1 and P2. Only risky sign-ins differ between P1 (30 days) and P2 (90 days). Longer history requires diagnostic settings that send logs to Log Analytics, a storage account, or an event hub, and retention changes are not retroactive.