Enterprise Mobility + Security E5
EMS E3 plus Entra ID P2 (identity protection, privileged identity management) and Defender for Cloud Apps.
What's included
Curated capability groupings first, then every remaining service plan Microsoft provisions with this SKU — together they're the complete list, nothing is hidden.
| Identity |
|---|
| Conditional Access Advanced identity and access management: Conditional Access, group-based access management, and self-service password reset with on-premises write-back. Enforce sign-in rules (require MFA, block legacy auth, require a compliant device, restrict by location) based on user, app, and risk signals. |
| Risk-Based Conditional Access / Identity Protection Adds Identity Protection risk-based Conditional Access and Privileged Identity Management on top of Entra ID P1. Automatically detect and respond to compromised credentials and risky sign-ins, and build Conditional Access policies that key off Microsoft’s calculated user/sign-in risk score. |
| Multi-Factor Authentication Requires a second sign-in verification step (phone call, SMS, or app notification) in addition to a password. |
| Self-Service Password Reset With on-premises writeback (Entra ID P1) Advanced identity and access management: Conditional Access, group-based access management, and self-service password reset with on-premises write-back. Let users reset or unlock their own account without a help desk call. Basic cloud-only SSPR is available broadly; on-premises writeback (syncing the reset back to Active Directory) requires Entra ID P1. |
| Privileged Identity Management Adds Identity Protection risk-based Conditional Access and Privileged Identity Management on top of Entra ID P1. Grant admin roles just-in-time (time-bound, approval-gated activation) instead of standing access, with full activation audit history. A core Entra ID P2 entitlement, also obtainable via the standalone Entra ID Governance add-on. |
| Access Reviews Adds Identity Protection risk-based Conditional Access and Privileged Identity Management on top of Entra ID P1. Periodically require an owner or the user themselves to re-certify continued need for group membership, app access, or a role assignment — access that’s no longer needed gets removed automatically. |
| Entitlement Management Adds Identity Protection risk-based Conditional Access and Privileged Identity Management on top of Entra ID P1. Bundle groups, apps, and SharePoint sites into a requestable "access package" with approval workflow and automatic expiration — including for external/guest users. |
| Device Management |
| Intune Device Management Cloud-based mobile device and application management — enroll, configure, and enforce compliance policies on company and personal devices. Enroll, configure, and manage Windows, iOS, Android, and macOS devices: compliance policies, app deployment, and remote wipe. |
| Windows Autopilot Cloud-based mobile device and application management — enroll, configure, and enforce compliance policies on company and personal devices. Provision and configure new Windows devices out of the box, straight from the cloud, with no imaging. Autopilot itself has no separate license line item — it’s an Intune-dependent deployment workflow, mapped here to Intune Plan 1 as the plan that actually enables managing the enrolled device afterward. |
| BitLocker Management Cloud-based mobile device and application management — enroll, configure, and enforce compliance policies on company and personal devices. Centrally enforce BitLocker drive encryption policy and escrow recovery keys. BitLocker itself ships with Windows Pro/Enterprise; cloud-based policy and key escrow specifically need Intune, mapped here as the enabling plan since there’s no dedicated BitLocker-management license line item. |
| Security |
| Defender for Identity Monitors on-premises Active Directory signals to detect compromised identities and malicious insider actions. Monitors on-premises Active Directory signals (via a lightweight sensor on domain controllers) to detect compromised identities and lateral-movement/privilege-escalation attacks. |
| Defender for Cloud Apps Full Defender for Cloud Apps (all sanctioned SaaS) A cloud access security broker (CASB) that discovers shadow IT and applies access and session controls to third-party cloud apps. A cloud access security broker (CASB): discovers shadow IT, and applies session/access policies across sanctioned SaaS apps. The Office 365-scoped tier only covers Microsoft 365 activity; the full product extends that policy control to third-party cloud apps. |
| Other service plans |
| Exchange Foundation The baseline Exchange Online mailbox service included in most Microsoft 365 plans — hosted email, calendar, and contacts. |
| Azure Information Protection Premium P1 Classify and protect documents and email with sensitivity labels, including on-premises scanner support for protecting files at rest. |
| Azure Information Protection Premium P2 Adds automatic sensitivity-labeling recommendations and unified labeling management on top of Azure Information Protection Premium P1. |
| Azure Rights Management · RMS_S_ENTERPRISE Encrypts and applies usage restrictions (view-only, no-forward, expiration) to documents and email so protection travels with the file. |