An identity-centric Secure Web Gateway that protects users from phishing, malware, and unsafe internet content, and enforces access policies for SaaS and web apps. Extends Conditional Access to any internet destination — not just Microsoft 365 apps — using web content filtering, threat protection, and identity-aware policies, without relying on legacy VPNs or on-prem proxies.
A frontline worker–priced edition of Microsoft Entra Internet Access, the identity-centric Secure Web Gateway that protects against phishing, malware, and unsafe web content, and enforces Conditional Access policies for any internet or SaaS destination — extended to shift-based and deskless staff at a reduced cost compared to the standard offering.
A Zero Trust Network Access (ZTNA) solution that gives secure, identity-based access to private applications and internal resources — on-prem or in the cloud — without a traditional VPN. Applies Conditional Access controls (user, device, risk) to every connection, replacing legacy network-perimeter security with per-app, identity-driven access.
A frontline worker–priced edition of Microsoft Entra Private Access, a Zero Trust Network Access (ZTNA) solution that gives secure, identity-based access to private apps and internal resources without a traditional VPN — extended to shift-based and deskless staff at a reduced cost versus the standard offering.
Microsoft's complete cloud-based identity security solution for workforce access. Combines Entra ID Governance, Private Access (ZTNA/VPN replacement), Internet Access (secure web gateway), premium Verified ID features (including Face Check), and advanced Identity Protection — giving administrators secure, least-privilege access to any app or resource, cloud or on-premises.
Upgrades an existing Microsoft Entra ID F2 subscription to the full Entra Suite, at frontline-worker pricing. Adds Entra ID Governance, Private Access, Internet Access, premium Verified ID features, and advanced Identity Protection — bringing enterprise-grade identity security to shift-based and deskless staff at a reduced cost versus the standard Entra Suite.
Upgrades an existing Microsoft Entra ID P2 subscription to the full Entra Suite. Adds Entra ID Governance, Private Access (ZTNA/VPN replacement), Internet Access (secure web gateway), premium Verified ID features (including Face Check), and advanced Identity Protection — a complete cloud-based solution for securing workforce access across cloud and on-premises resources.
A frontline worker–priced edition of the Entra Suite, bundling Microsoft's full identity security stack — Conditional Access, Identity Protection, Privileged Identity Management, advanced governance (including Lifecycle Workflows), Internet Access, and Private Access — for shift-based and deskless staff at a reduced cost compared to the standard Entra Suite.
A standalone license that secures non-human identities — applications, service principals, and managed identities used for service-to-service access. Adds Conditional Access and Identity Protection for workload identities, plus risk detection for compromised or inactive credentials — a separate SKU not bundled into any Microsoft 365 or Entra suite.
An add-on to Microsoft Intune that extends endpoint analytics with anomaly detection, device query (using KQL), battery health reporting, and an enriched device timeline. Gives IT teams deeper insight into device health and performance for faster, more proactive troubleshooting — now included in Microsoft 365 E3 and E5 as part of Intune Plan 2.
A frontline worker–priced edition of Intune Advanced Analytics, extending endpoint analytics with anomaly detection, device query, battery health reporting, and an enriched device timeline — giving IT deeper visibility into shared or shift-based frontline devices at a reduced cost compared to the standard add-on.
An Intune Suite add-on that lets standard users run specific, IT-approved tasks — like installing applications, updating drivers, or running diagnostics — without being granted full administrator rights. Supports a Zero Trust, least-privilege approach by allowing just-in-time elevation for selected tasks, with full audit logging of every elevation request.

