Skip to content
Browse all topics
Microsoft Entra (Identity)

The Entra Suite explained

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

Entra Suite explained: Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection in one licence — what each does and when it pays.

9 min read

Share as imagePNG

The Microsoft Entra Suite is a single per-user licence that bundles five Entra products: Internet Access, Private Access, Verified ID (premium features), ID Governance, and Identity Protection. It replaces the "buy each one separately" pattern with one line item — the same shape Microsoft 365 E5 uses to bundle productivity plus security plus compliance.

If you have looked at deploying more than two of these products, the Suite is almost certainly cheaper than buying them separately. If you have only ever heard the phrase "Entra Suite" and don't know what's in it, this guide is the tour.

What each product does

Microsoft Entra Internet Access. A Secure Web Gateway (SWG) delivered as part of Global Secure Access. It routes user internet traffic through Microsoft's global edge, applies URL filtering, TLS inspection, and DLP, and enforces conditional access at the network layer. Competes with Zscaler Internet Access and Netskope.

Microsoft Entra Private Access. A Zero Trust Network Access (ZTNA) product, also part of Global Secure Access. It replaces the corporate VPN: users get per-application access to private resources (on-prem or Azure) with identity-based policy, not a network-level tunnel. Competes with Zscaler Private Access and Cloudflare Access.

Microsoft Entra Verified ID (premium). A verifiable-credentials service that lets an organisation issue and verify digital credentials — employment verification, education records, professional certifications. The free tier covers basic issuing; the premium features (in the Suite) add higher-volume verification, more issuer types, and integration into onboarding and IT-help-desk flows.

Microsoft Entra ID Governance. Access reviews, entitlement management (packaged access with approval workflows), lifecycle workflows (joiner/mover/leaver automation), and separation-of-duties enforcement. Competes with SailPoint, Saviynt, and (partially) Okta Identity Governance. This is one of the two heaviest components of the Suite by capability.

Microsoft Entra ID Protection. Real-time risk detection: leaked credentials, anonymous IP, unfamiliar sign-in, atypical travel, malware-linked IP, plus cumulative user-risk scoring. Feeds Conditional Access to enforce step-up or block automatically. This is what makes CA truly risk-adaptive.

Together, the five products cover identity governance, identity risk, secure remote access (via replacement of VPN), secure web access, and portable verifiable credentials — a substantial fraction of the modern identity-and-access toolbox.

What it costs

The Suite is priced per user per month. It is licensed on top of Entra ID P1 or P2 — the Suite is an add-on, not a standalone identity platform. Approximate 2026 published price is $12/user/month, but check the current pricing page — it moves.

Buying the five products individually adds up to substantially more, so the break-even on the Suite is low: use two or three of them and you have already saved money over standalone.

Microsoft 365 E5 does not include the Suite. E5 includes P2 (with Identity Protection) but not the Suite's Global Secure Access components, ID Governance, or premium Verified ID. Assuming "we have E5 so we have the Suite" is a common and expensive mistake — check the licensing detail.

When it's the right SKU

The Suite is the right pick when the organisation wants two or more of:

  • To replace a legacy VPN with ZTNA (Private Access).
  • To replace or supplement a third-party SWG (Internet Access).
  • To run access reviews, entitlement management, and JML automation on Entra rather than a separate IGA product (ID Governance).
  • To adopt verifiable credentials for onboarding or credential proof (Verified ID).
  • To turn on real-time risk-adaptive Conditional Access (Identity Protection — already often licensed via P2, but included here).

Two typical decision profiles fit:

Consolidation-driven. The organisation runs a mix of point products (Zscaler + a small IGA + a homegrown JML workflow) and wants to consolidate onto Microsoft. Suite plus Entra ID P2 replaces the stack.

Zero-Trust adoption. The organisation is doing a Zero Trust push — replacing VPN, tightening CA, adopting risk-adaptive access, formalising access certification. The Suite is the natural bundle for that programme.

When it isn't

Two situations where the Suite is not the right pick.

Only one product needed. If ID Governance is genuinely the only piece needed and there is no ZTNA / SWG / Verified ID roadmap, buying ID Governance standalone is cheaper than the Suite. Same logic for any single component.

Existing third-party stack that's staying. If Zscaler and SailPoint are contractually locked in for another two years and rip-and-replace isn't happening, the Suite's coverage overlaps with the incumbent stack for that period. Wait until contract renewal.

Rollout order

If you have the Suite and want to deploy it, the sensible order is:

  1. Identity Protection. Fastest value — enable the risk-based CA policies, watch for a couple of weeks in report-only, enforce. Immediate lift on identity security posture.
  2. ID Governance access reviews. Turn on quarterly reviews on the highest-risk groups (admin roles, sensitive-file access) first. Grows into full entitlement management and lifecycle workflows over quarters.
  3. Global Secure Access Internet Access. Start with a pilot user group, tune the URL filtering, expand.
  4. Global Secure Access Private Access. Requires a mapping of internal apps and their access needs — this is the biggest project of the five and worth budgeting accordingly.
  5. Verified ID. Adopts naturally as the other pieces mature — issuing employment credentials, verifying at rehire, embedding in help-desk password reset.

Trying to deploy all five in parallel almost always ends badly — the change management overloads the identity team and the users. Sequenced deployment gets there faster in wall-clock terms.

Licensing prerequisites

The Suite is layered on top of the base Entra ID licences:

  • Entra ID Free is not sufficient — the Suite needs P1 or P2 underneath.
  • Entra ID P1 covers Conditional Access, group-based licensing, and self-service password reset.
  • Entra ID P2 adds Identity Protection standalone and PIM (Privileged Identity Management).

For most enterprises the working combination is Entra ID P2 + Entra Suite, which delivers CA + PIM + Identity Protection + the four other Suite products. Microsoft 365 E5 + Entra Suite gets you E5's full compliance and Defender stack alongside; that's the pattern for enterprises going all-in on Microsoft security and identity.

Decision matrix — Suite, à la carte, or skip

The Suite's break-even is low but not automatic. This table is the shortcut most identity teams walk through when the CIO asks "why should we buy it":

| Situation | What to do | Why | | --- | --- | --- | | Zero-Trust programme is funded and the identity team owns it | Buy the Suite | Two or more of the five components are on the roadmap by month six; the Suite is cheaper than any two à la carte. | | Replacing a legacy VPN with ZTNA is the only Zero-Trust priority in flight | Buy Private Access + P1 (or P2) standalone | ZTNA alone doesn't clear the Suite's break-even; revisit at renewal when Internet Access or Governance surface. | | Third-party IGA (SailPoint / Saviynt) has 18+ months left on contract | Skip the Suite for now | Suite ID Governance overlaps with the incumbent; the CFO won't sign a duplicate spend. Revisit six months before renewal. | | Zscaler / Netskope contract runs to 2028, but ID Governance is a live gap | Buy ID Governance standalone | Suite value is diluted while the SWG stack is intact; a single-component licence is cheaper than paying for four you can't use. | | Small org (< 100 users), Business Premium tenant, no P2 | Skip both | Suite requires Entra ID P1 or P2 underneath; that step-up alone costs more than the CA + PIM baseline this size of org typically needs. | | On E5 already, and rolling out advanced identity governance | Add the Suite | E5 gives you P2 (Identity Protection, PIM). The Suite adds ID Governance, GSA and Verified ID — the four things E5 doesn't include. |

The single rule underneath the table: need any two of the five, and the Suite wins on price. Everything else is nuance about incumbents and pace.

A worked example — 800 users, mixed stack

An 800-user professional-services firm on Microsoft 365 E3 today, running Cisco AnyConnect for VPN, a small SailPoint deployment for access reviews on the finance apps, and no SWG. The CIO wants a Zero-Trust roadmap over two years.

The Suite maths, at list price, per user per month:

  • Entra ID P2 step-up (from P1 in E3): $3
  • Entra Suite add-on: $12
  • Total Suite cost / user / month: $15
  • Annual per-user: $180
  • Annual total for 800 users: $144,000

Compared to the à la carte alternative for the same coverage (rough public list prices):

  • Private Access + Internet Access (as separate SKUs): roughly $10-12 combined
  • ID Governance standalone: ~$7
  • Verified ID premium: ~$3
  • Identity Protection (already in P2)
  • À la carte total: $20-22 / user / month before the P2 step-up

The Suite is roughly 30% cheaper than buying the four remaining products separately, and it collapses four contracts into one add-on line. Displacing Cisco AnyConnect saves another ~$40k/year in VPN licences and gateway maintenance; retiring the SailPoint deployment at contract end saves ~$60k/year. Payback on the Suite investment is well under a year in this shape of tenant.

The rollout order matches the section above: Identity Protection first (already licensed via P2, immediate risk-based CA lift), ID Governance access reviews second (displacing the SailPoint scope one team at a time), Internet Access in month six (pilot then expand), Private Access in month nine as the internal-app inventory matures, Verified ID as a slow burn through 2027 onboarding.

MSP / first-time-admin checklist

For a partner or consultant scoping an Entra Suite engagement, this is the checklist that keeps the deal honest:

  • Confirm base licensing. Every Suite user needs Entra ID P1 (minimum) or P2. Mixed tenants (some P1, some Free) fail activation for the Free users.
  • Inventory internal apps for Private Access. Without this list, Private Access sits idle and the Suite economics collapse. Ask for it before signing.
  • Confirm no active SWG contract with 18+ months left. If Zscaler / Netskope / Palo Alto is contractually locked in, the SWG half of Suite (Internet Access) is duplicate spend for that window.
  • Confirm identity-team ownership for ID Governance. If HR or a third-party IGA team owns joiner-mover-leaver today, the migration is a change-management project, not just a licence flip.
  • Plan Identity Protection in report-only for at least two weeks. Sign-in risk policies enforced day-one will lock people out; report-only catches the false-positive shape before enforcement.
  • Set expectations on Verified ID. It is genuinely useful, and it is genuinely slow. Nobody adopts verifiable credentials in a quarter — plan a year-plus horizon.
  • Budget the Global Secure Access agent rollout. Every device needs it for Internet Access and Private Access. Intune deployment is straightforward; the pilot and MDM policy tuning takes weeks, not days.

The short version

Five Entra products under one licence: Internet Access, Private Access, Verified ID (premium), ID Governance, Identity Protection.

If you plan to use two or more of them, the Suite is cheaper than buying separately. If you're on a Zero Trust journey or consolidating from a mixed identity/access stack, it's the natural bundle. If you only need one component, buy that component alone.

E5 does not include the Suite — check before you assume.

Frequently asked questions

What is included in the Entra Suite?
Five products under one per-user licence: Entra Internet Access (secure web gateway), Entra Private Access (ZTNA VPN replacement), Verified ID premium features, Entra ID Governance (access reviews, entitlement management, lifecycle workflows), and Entra ID Protection (real-time risk detection feeding Conditional Access).
Does Microsoft 365 E5 include the Entra Suite?
No. E5 includes Entra ID P2 — which carries Identity Protection and PIM — but not the Global Secure Access components, ID Governance, or premium Verified ID. Assuming E5 includes the Suite is a common and expensive mistake; check the licensing detail.
What are the prerequisites for the Entra Suite?
An Entra ID P1 or P2 licence underneath — the Suite is an add-on, not a standalone identity platform, and Entra ID Free is not sufficient. The typical enterprise combination is Entra ID P2 plus the Suite.
In what order should we deploy the Entra Suite products?
Identity Protection first (fast value — report-only, then enforce), then ID Governance access reviews on the highest-risk groups, then Internet Access with a pilot group, then Private Access (the biggest project — it needs an internal-app inventory), and Verified ID as the rest matures. Deploying all five in parallel overloads the identity team.

Further reading

Was this useful?

Spot something wrong or want a topic covered? Send it through the contact form.