Azure Active Directory plans and pricing
Choose the best version for your business
Azure Active Directory is available in four editions. Check the table below to see the features included in each edition.
Azure Active Directory Free
The free edition of Azure AD is included with a subscription of a commercial online service such as Azure, Dynamics 365, Intune, Power Platform, and others.1
Office 365
Additional Azure AD features are included with Office 365 E1, E3, E5, F1, and F3 subscriptions.2
Azure Active Directory Premium P1
Azure AD Premium P1, included with Microsoft 365 E3, offers a free 30-day trial. Azure and Office 365 subscribers can buy Azure AD Premium P1 online.
Azure Active Directory Premium P2
Azure AD Premium P2, included with Microsoft 365 E5, offers a free 30-day trial. Azure and Office 365 subscribers can buy Azure Active Directory Premium P2 online.
Feature name | Azure Active Directory Free | Office 365 | Azure Active Directory Premium P1 | Azure Active Directory Premium P2 |
---|---|---|---|---|
Authentication, single sign-on and multifactor authentication (MFA) |
This feature is partially included
|
This feature is partially included
|
included
|
included
|
Cloud authentication |
included
|
included
|
included
|
included
|
Federated authentication (Active Directory Federation Services or federation with other identity providers) |
included
|
included
|
included
|
included
|
Single sign-on (SSO) unlimited3 |
included
|
included
|
included
|
included
|
Multifactor authentication (MFA)4 |
included
|
included
|
included
|
included
|
Passwordless (Windows Hello for Business, Microsoft Authenticator, FIDO2 security key integrations5) |
included
|
included
|
included
|
included
|
Service-level agreement6 |
not included
|
not included
|
included
|
included
|
Applications Access |
This feature is partially included
|
This feature is partially included
|
included
|
included
|
SaaS apps with modern authentication (Azure AD application gallery apps, SAML, and OAUTH 2.0) |
included
|
included
|
included
|
included
|
Group assignment to applications |
Partially included |
Partially included |
included
|
included
|
Cloud app discovery (Microsoft Defender for Cloud Apps)7 |
Partially included |
Partially included |
included
|
included
|
Application Proxy for on-premises, header-based, and Integrated Windows Authentication |
not included |
not included |
included
|
included
|
Secure hybrid access partnerships8 (Kerberos, NTLM, LDAP, RDP, and SSH authentication) |
included
|
included
|
included
|
included
|
Authorization and Conditional Access |
This feature is partially included
|
This feature is partially included
|
This feature is partially included
|
included
|
Role-based access control (RBAC) |
included
|
included
|
included
|
included
|
Conditional Access |
not included |
not included |
included
|
included
|
SharePoint limited access |
not included |
not included |
included
|
included
|
Session lifetime management Learn more |
not included |
not included |
included
|
included
|
Identity Protection (Risky sign-ins, risky users, risk-based conditional access) |
not included |
not included |
not included |
included
|
Custom security attributes |
not included |
not included |
included
|
included
|
Administration and hybrid identity |
This feature is partially included
|
This feature is partially included
|
included
|
included
|
User and group management |
included
|
included
|
included
|
included
|
Advanced group management (Dynamic groups, naming policies, expiration, default classification) |
not included |
not included |
included
|
included
|
Directory synchronization—Azure AD Connect (sync and cloud sync) |
included
|
included
|
included
|
included
|
Azure AD Connect Health reporting9 |
not included |
not included |
included
|
included
|
Delegated administration—built-in roles |
included
|
included
|
included
|
included
|
Global password protection and management – cloud-only users |
included
|
included
|
included
|
included
|
Global password protection and management – custom banned passwords, users synchronized from on-premises Active Directory |
not included |
not included |
included
|
included
|
Microsoft Identity Manager user client access license (CAL)10 |
not included |
not included |
included
|
included
|
End-user self-service |
This feature is partially included
|
This feature is partially included
|
This feature is partially included
|
included
|
Application launch portal (My Apps) |
included
|
included
|
included
|
included
|
User application collections in My Apps |
included
|
included
|
included
|
included
|
Self-service account management portal (My Account) |
included
|
included
|
included
|
included
|
Self-service password change for cloud users |
included
|
included
|
included
|
included
|
Self-service password reset/change/unlock with on-premises write-back |
not included |
not included |
included
|
included
|
Self-service sign-in activity search and reporting |
not included |
included
|
included
|
included
|
Self-service group management (My Groups) |
not included |
not included |
included
|
included
|
Self-service entitlement management (My Access) |
not included |
not included |
not included |
included
|
Identity Governance |
This feature is partially included
|
This feature is partially included
|
This feature is partially included
|
included
|
Automated user provisioning to apps |
included
|
included
|
included
|
included
|
Automated group provisioning to apps |
not included |
not included |
included
|
included
|
HR-driven provisioning |
not included |
not included |
included
|
included
|
Terms of use attestation |
not included |
not included |
included
|
included
|
Access certifications and reviews |
not included |
not included |
not included |
included
|
Entitlements management |
not included |
not included |
not included |
included
|
Privileged Identity Management (PIM), just-in-time access |
not included |
not included |
not included |
included
|
Event logging and reporting |
This feature is partially included
|
This feature is partially included
|
This feature is partially included
|
included
|
Basic security and usage reports |
included
|
included
|
included
|
included
|
Advanced security and usage reports |
not included |
not included |
included
|
included
|
Identity Protection: vulnerabilities and risky accounts |
not included |
not included |
not included |
included
|
Identity Protection: risk events investigation, SIEM connectivity |
not included |
not included |
not included |
included
|
Frontline workers |
not included |
not included |
included
|
included
|
SMS sign-in |
not included |
not included |
included
|
included
|
Shared device sign-out |
not included |
not included |
included
|
included
|
Delegated user management portal (My Staff) |
not included |
not included |
included
|
included
|
External Identities |
not included |
not included |
not included |
not included |
|
not included |
not included |
not included |
not included |
You’ll need an Azure or Office 365 subscription. You can use an existing subscription or set up a new one and then sign into the Microsoft 365 portal with your credentials to buy Azure AD licenses. Learn more.
To manage your Azure Active Directory Premium P1 or Premium P2, or Enterprise Mobility + Security licenses, sign in with your credentials or learn more.
Enterprise Mobility + Security E3 licenses include Azure Active Directory Premium P1. Enterprise Mobility + Security E5 licenses include Azure Active Directory Premium P2.
Support and service-level agreement
Technical support for Azure Active Directory is available through Azure Support, starting at $29 per month. Billing and account management support is provided at no additional cost. Learn more.
Service-level agreement (SLA): Azure Active Directory Premium editions guarantee a 99.99% effective April 1, 2021, monthly availability. Free services, such as Azure Active Directory Free, don’t have an SLA. For more details, visit the Azure SLA page.
1. The free edition of Azure AD is included with a subscription of a commercial online service such as Azure, Dynamics 365, Intune, Power Platform, and others in countries where they are available for sale.
2. Additional Azure AD features are included with Office 365 E1, E3, E5, F1, and F3 subscriptions in countries where they are available for sale.
3. With the free edition of Azure AD end users who have been assigned access to software as a service (SaaS) apps can get single sign-on access to unlimited number of cloud apps. On-premises apps require Azure AD Application Proxy or secure hybrid partnerships integrations available with Azure AD Premium P1 and Premium P2.
4. Authentication methods and configuration capabilities may vary by subscription. Learn more.
5. FIDO2 security key partners.
6. Terms and conditions for service-level agreements.
7. To access the cloud app discovery features go to the cloud app security portal and log in with your Azure AD Premium P1 credentials. Azure AD Premium P2 customers won’t need to enter credentials and will be automatically redirected.
8. Secure hybrid access partnerships; Conditional access API requires Premium P1; Risky User API requires Premium P2 for Secure Hybrid Access.
9. First monitoring agent requires at least one license. Each additional agent requires 25 additional incremental licenses. Agents monitoring Azure AD Federation Services, Azure AD Connect, and Azure AD Domain Services are considered separate agents.
10. Microsoft Identity Manager Server software rights are granted with Windows Server licenses (any edition). Since Microsoft Identity Manager runs on Windows Server OS, as long as the server is running a valid, licensed copy of Windows Server, Microsoft Identity Manager can be installed and used on that server. No separate license is required for Microsoft Identity Manager Server.
11. Azure Active Directory Domain Services pricing.