• A device and identity management bundle combining Entra ID P1 (SSO, MFA, Conditional Access), Microsoft Intune (mobile device and app management), and Azure Information Protection P1 (document encryption and rights management). The foundational security layer included in Microsoft 365 E3, giving organisations control over how corporate data is accessed and shared across devices.

  • Builds on EMS E3 with advanced identity and threat protection: Entra ID P2 (risk-based Conditional Access, Identity Protection, Privileged Identity Management), Azure Information Protection P2, and Microsoft Defender for Cloud Apps. The more comprehensive security tier included in Microsoft 365 E5, adding proactive, automated threat detection and governance on top of E3's baseline controls.

  • Upgrades an existing Microsoft Entra ID P2 subscription to the full Entra Suite. Adds Entra ID Governance, Private Access (ZTNA/VPN replacement), Internet Access (secure web gateway), premium Verified ID features (including Face Check), and advanced Identity Protection — a complete cloud-based solution for securing workforce access across cloud and on-premises resources.

  • An Intune Suite add-on that lets you create, configure, and manage your own certification authorities (CAs) and certificates entirely in the cloud — no on-premises servers, connectors, or hardware required. Automates certificate issuance, delivery, and revocation for Intune-managed Windows, iOS, macOS, and Android devices, enabling certificate-based authentication in minutes rather than weeks.

  • A frontline worker–priced edition of Microsoft Cloud PKI, letting IT create, configure, and manage certification authorities and certificates entirely in the cloud for Intune-managed devices — no on-premises infrastructure required — extended to shift-based and deskless staff at a reduced cost compared to the standard Intune Suite offering.

  • The frontline worker edition of Microsoft Entra ID, providing core identity and access management — single sign-on, Conditional Access, and multi-factor authentication — sized and priced for shift-based, deskless staff rather than standard knowledge workers.

  • Microsoft's foundational identity and access management tier, providing Conditional Access, multi-factor authentication, self-service password reset, and hybrid identity integration with on-premises Active Directory. The baseline security layer for controlling how users and devices access company resources — included in Microsoft 365 Business Premium and E3.

  • Adds adaptive, risk-based security on top of Entra ID P1. Includes Identity Protection with machine-learning-driven sign-in and user risk detection, Privileged Identity Management (PIM) for just-in-time privileged access, and access reviews — suited to organisations needing more proactive, automated identity threat response. Included in Microsoft 365 E5.

  • An identity-centric Secure Web Gateway that protects users from phishing, malware, and unsafe internet content, and enforces access policies for SaaS and web apps. Extends Conditional Access to any internet destination — not just Microsoft 365 apps — using web content filtering, threat protection, and identity-aware policies, without relying on legacy VPNs or on-prem proxies.

  • A frontline worker–priced edition of Microsoft Entra Internet Access, the identity-centric Secure Web Gateway that protects against phishing, malware, and unsafe web content, and enforces Conditional Access policies for any internet or SaaS destination — extended to shift-based and deskless staff at a reduced cost compared to the standard offering.

  • A Zero Trust Network Access (ZTNA) solution that gives secure, identity-based access to private applications and internal resources — on-prem or in the cloud — without a traditional VPN. Applies Conditional Access controls (user, device, risk) to every connection, replacing legacy network-perimeter security with per-app, identity-driven access.

  • A frontline worker–priced edition of Microsoft Entra Private Access, a Zero Trust Network Access (ZTNA) solution that gives secure, identity-based access to private apps and internal resources without a traditional VPN — extended to shift-based and deskless staff at a reduced cost versus the standard offering.