Plain-English guide

Microsoft licensing, explained simply

Your Microsoft license decides how much ITDR is allowed to watch. This page explains, in everyday words, what you get with each license — Entra Free, Business Premium, E3, E5, Entra P1, and Entra P2 — for logs, detections, alerts, and risk.

Last reviewed

June 10, 2026

Want the precise, technical version with API names and warning signals? See the license coverage matrix.

Read this first

Think of it like a wristband at a theme park

Microsoft licenses are like the wristband you get at the gate. The wristband decides which rides you are allowed on. ITDR is the security team watching the cameras — but Microsoft only lets us watch the camera feeds your wristband includes. A bigger wristband (a higher license) means more cameras, sharper footage, and Microsoft's own guards handing us tip-offs. ITDR is the same product for everyone; the wristband just decides how much we are allowed to see.

The four building blocks

Logs, detections, alerts, and risk

1

Logs

The diary of what happened. Who signed in, from where, and who changed a setting. ITDR reads this diary to know what is going on.

2

Detections

The rules that read the diary and shout "that looks wrong." Example: the same person "signs in" from two countries ten minutes apart.

3

Alerts

The sticky note a detection leaves for your team: "Check this — it might be an attacker." Some alerts come from Microsoft itself (Defender).

4

Risk

Microsoft's own opinion about how dangerous a sign-in or user looks. It is a bonus signal we mix in — but Microsoft only shares it on higher licenses.

The chain runs left to right: logs feed detections, detections raise alerts, and Microsoft's risk score makes those alerts smarter. Your license decides how much of each Microsoft will share.

At a glance

What you get by license tier

What ITDR can doEntra FreeEntra P1 (Business Premium / E3)Entra P2 (E5)

Identity inventory

A list of your users, devices, and apps.

YesYesYes

Directory change logs

Who changed a role, a group, or a password setting.

LimitedYesYes

Sign-in logs

Who logged in, from where, on what device. The backbone of ITDR.

NoYesYes

Mailbox & file activity

Sneaky inbox rules, forwarding, odd file access (needs Microsoft 365 apps).

DependsDependsYes

Microsoft's risk score

Microsoft flags a sign-in as "risky" and tells us why.

NoLimitedYes

Risky users list

Microsoft's ranked list of accounts it thinks are compromised.

NoNoYes

Defender alerts & incidents

Ready-made alerts from Microsoft Defender, pulled into one place.

NoDependsYes

Containment actions

Disable an account, kick out active sessions, remove from a group.

YesYesYes

Depends means it is not about the Entra tier — it needs your Microsoft 365 apps (Exchange, SharePoint) with audit turned on. Limited means it works, but Microsoft hides some detail until a higher license.

Real customer scenarios

"Here's what I have" — here's what you get

"I only have Entra ID Free."

Entra ID Free — the default that comes with any Microsoft 365 subscription.

What ITDR can watch

We can see your users, devices, and apps, and read directory change logs (kept ~7 days). But Microsoft does not let Free tenants stream sign-in logs to us, and there is no risk data.

What you get

  • A full inventory of identities, devices, and applications.
  • Detections built on directory changes (new admin, risky app consent, group changes).
  • Full containment — we can still disable a user or revoke their sessions in an emergency.

What you don't get

  • No sign-in detections (impossible travel, password spray, token replay) — those need sign-in logs.
  • No Microsoft risk scores or risky-users list.
  • No mailbox/forwarding detections unless you turn on Microsoft 365 audit.

Bottom line: Works, but thin. Sign-in telemetry is the heart of identity threat detection, so Free leaves most detections dark. The single best upgrade is anything that includes Entra P1.

"I have Microsoft 365 Business Premium."

Business Premium quietly includes Entra ID P1 and the Microsoft 365 apps (Exchange, SharePoint).

What ITDR can watch

This is the sweet spot for small/mid customers. We get sign-in logs and directory logs (kept ~30 days), plus mailbox and file activity once Microsoft 365 audit is on.

What you get

  • Sign-in detections: impossible travel, password spray, token replay, MFA fatigue.
  • Mailbox-rule and forwarding detections from Microsoft 365 activity.
  • A basic Microsoft risk signal ("additional risk detected") mixed into scoring.
  • Full containment.

What you don't get

  • No detailed risk breakdown or risky-users list — those are P2-only.
  • No Microsoft Defender alerts/incidents feed unless you add Defender.

Bottom line: Strong, practical coverage. Most of what people picture when they say "identity threat detection" works here.

"I have Microsoft 365 E3."

E3 also includes Entra ID P1 plus the Microsoft 365 apps — for ITDR it behaves like Business Premium.

What ITDR can watch

Same as Business Premium: sign-in logs, directory logs (30 days), and mailbox/file activity with audit on.

What you get

  • The full Business-Premium detection set above.
  • Basic risk signal blended into scoring.
  • Full containment.

What you don't get

  • No P2 risk detail or risky-users list.
  • Defender alerts/incidents only if you bought a Defender add-on.

Bottom line: Solid. The only thing standing between E3 and "everything" is the P2 / Defender depth that comes with E5.

"I have Microsoft 365 E5."

E5 includes Entra ID P2 and Microsoft Defender — the top tier.

What ITDR can watch

Everything. Sign-in and directory logs, mailbox/file activity, full Microsoft risk detail, and ready-made Defender alerts and incidents.

What you get

  • Every detection ITDR ships, with the richest signals.
  • Full risk detail per sign-in and Microsoft's ranked risky-users list.
  • Defender alerts and incidents pulled into the same timeline.
  • Full containment.

What you don't get

  • Nothing material is gated — this is the complete picture.

Bottom line: Best case. ITDR runs at full strength.

"I have Entra ID P1 (on its own)."

Standalone Entra P1 — the identity license without the Microsoft 365 apps necessarily attached.

What ITDR can watch

Sign-in logs and directory logs (30 days) plus a basic risk signal. Mailbox/file detections only if you also have Exchange/SharePoint with audit on.

What you get

  • Sign-in and directory detections.
  • Basic Microsoft risk signal.
  • Full containment.

What you don't get

  • No risky-users list or detailed risk (P2-only).
  • No mailbox detections unless Microsoft 365 apps + audit are present.

Bottom line: A genuinely useful minimum. P1 is the line where ITDR goes from "barely watching" to "actually detecting."

"I have Entra ID P2 (on its own)."

Standalone Entra P2 — top identity license, but not automatically the Microsoft 365 apps.

What ITDR can watch

All the identity signals: sign-in logs, directory logs, full risk detail, and the risky-users list. Mailbox/file detections still depend on having Microsoft 365 apps with audit on.

What you get

  • Every sign-in and directory detection.
  • Full risk detail and Microsoft's risky-users list.
  • Full containment.

What you don't get

  • Mailbox/file activity detections need Microsoft 365 apps + audit (P2 alone does not add them).
  • Defender alerts/incidents need Defender licensing.

Bottom line: Top-tier identity coverage. Pair it with Microsoft 365 apps to also unlock the mailbox lane.

So what is the minimum?

Floor, practical floor, and ceiling

The true floor is Entra ID Free: ITDR still inventories identities, reads directory changes, and can contain a compromised account.
The practical floor is Entra ID P1 (which you already own if you have Business Premium, E3, or E5). P1 unlocks sign-in logs — the telemetry most identity detections depend on.
The ceiling is Entra ID P2 / E5: full Microsoft risk detail, the risky-users list, and Defender alerts.
One thing that works on every license: if an account is compromised, ITDR can disable it, sign it out everywhere, and pull it from sensitive groups — even on Entra Free. Responding to a threat is never license-gated; only how much we can see beforehand changes.

Official Microsoft references

Microsoft Entra licensing (what each tier includes)Sign-in & audit log retention by tier (7 vs 30 days)Identity Protection / risk APIs (P1 vs P2)Microsoft 365 activity feed (mailbox/file lane)