Comparing generally available features of the Free, Basic, and Premium editions

Azure Active Directory Free Azure Active Directory BasicAzure Active Directory Premium P1Azure Active Directory Premium P2Office 365 apps only
Common features Directory objects1500,000 object limitNo object limit No object limit No object limit No object limit for Office 365 user accounts
User/group management (add/update/delete), user-based provisioning, device registration, password change, synchronization tools for “on-premises to cloud” directory integration (Azure AD Connect)Yes Yes Yes Yes Yes
Single Sign-On (SSO) 10 apps per user2 (pre-integrated SaaS and developer-integrated apps)10 apps per user2 (free tier + Application proxy apps) No limit (free, Basic tiers + Self-Service App Integration templates4)No limit (free, Basic tiers + Self-Service App Integration templates4)10 apps per user2 (pre-integrated SaaS and developer-integrated apps)
Self-service password change for cloud usersYes Yes Yes Yes Yes
Connect (sync engine that extends on-premises directories to Azure Active Directory)Yes Yes Yes Yes Yes
Security/usage reportsBasic reportsBasic reportsAdvanced reportsAdvanced reportsBasic reports
Premium + Basic featuresGroup-based access management/provisioningYesYesYes
Self-service password reset for cloud users YesYesYesYes
Company branding (logon pages/access panel customization)YesYesYesYes
Application proxyYesYesYes
SLA 99.9%YesYesYesYes
Premium featuresSelf-Service Group and app Management/Self-Service application additions/ Dynamic GroupsYes Yes
Self-service password reset/change/unlock with write-back to on-premises directoriesYes Yes
Multi-Factor Authentication (cloud and on-premises (MFA server))Yes Yes Limited cloud-only for Office 365 Apps
MIM CAL + MIM Server3YesYes
Cloud app discoveryYesYes
Connect HealthYes Yes
Conditional Access based on group and locationYes Yes
Conditional Access based on device state (allow access from managed devices)YesYes
Identity ProtectionYes
Privileged Identity ManagementYes
Windows 10 + Azure AD Join related featuresJoin a Windows 10 device to Azure AD, Desktop SSO, Microsoft Passport for Azure AD, Administrator Bitlocker recoveryYes Yes Yes Yes Yes
Windows 10 + Azure AD Join related featuresMDM auto-enrollment, Self-service Bitlocker recovery, additional local administrators to Windows 10 devices via Azure AD Join, Enterprise State RoamingYes Yes
Common features
Directory objects1
Azure Active Directory Free
500,000 object limit
Azure Active Directory Basic
No object limit
Azure Active Directory Premium P1
No object limit
Azure Active Directory Premium P2
No object limit
Office 365 apps only
No object limit for Office 365 user accounts
User/group management (add/update/delete), user-based provisioning, device registration, password change, synchronization tools for “on-premises to cloud” directory integration (Azure AD Connect)
Azure Active Directory Free
Yes
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Yes
Single Sign-On (SSO)
Azure Active Directory Free
10 apps per user2 (pre-integrated SaaS and developer-integrated apps)
Azure Active Directory Basic
10 apps per user2 (free tier + Application proxy apps)
Azure Active Directory Premium P1
No limit (free, Basic tiers + Self-Service App Integration templates4)
Azure Active Directory Premium P2
No limit (free, Basic tiers + Self-Service App Integration templates4)
Office 365 apps only
10 apps per user2 (pre-integrated SaaS and developer-integrated apps)
Self-service password change for cloud users
Azure Active Directory Free
Yes
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Yes
Connect (sync engine that extends on-premises directories to Azure Active Directory)
Azure Active Directory Free
Yes
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Yes
Security/usage reports
Azure Active Directory Free
Basic reports
Azure Active Directory Basic
Basic reports
Azure Active Directory Premium P1
Advanced reports
Azure Active Directory Premium P2
Advanced reports
Office 365 apps only
Basic reports
Premium + Basic features
Group-based access management/provisioning
Azure Active Directory Free
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Self-service password reset for cloud users
Azure Active Directory Free
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Yes
Company branding (logon pages/access panel customization)
Azure Active Directory Free
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Yes
Application proxy
Azure Active Directory Free
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
SLA 99.9%
Azure Active Directory Free
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Yes
Premium features
Self-Service Group and app Management/Self-Service application additions/ Dynamic Groups
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Self-service password reset/change/unlock with write-back to on-premises directories
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Multi-Factor Authentication (cloud and on-premises (MFA server))
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Limited cloud-only for Office 365 Apps
MIM CAL + MIM Server3
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Cloud app discovery
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Connect Health
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Conditional Access based on group and location
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Conditional Access based on device state (allow access from managed devices)
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Identity Protection
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Yes
Office 365 apps only
Privileged Identity Management
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Yes
Office 365 apps only
Windows 10 + Azure AD Join related features
Join a Windows 10 device to Azure AD, Desktop SSO, Microsoft Passport for Azure AD, Administrator Bitlocker recovery
Azure Active Directory Free
Yes
Azure Active Directory Basic
Yes
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Yes
Windows 10 + Azure AD Join related features
MDM auto-enrollment, Self-service Bitlocker recovery, additional local administrators to Windows 10 devices via Azure AD Join, Enterprise State Roaming
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Yes
Azure Active Directory Premium P2
Yes
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only
Azure Active Directory Free
Azure Active Directory Basic
Azure Active Directory Premium P1
Azure Active Directory Premium P2
Office 365 apps only

1Default usage quota is 150,000 objects. An object is an entry in the directory service, represented by its unique distinguished name. An example of an object is a user entry used for authentication purposes. If you need to exceed this default quota, please contact support. The 500K object limit does not apply for Office 365, Microsoft Intune, or any other Microsoft paid online service that relies on Azure Active Directory for directory services.

2With Azure AD Free and Azure AD Basic, end-users are entitled to get single sign-on access for up to 10 applications.

3Microsoft Identity Manager Server software rights are granted with Windows Server licenses (any edition). Since Microsoft Identity Manager runs on Windows Server OS, as long as the server is running a valid, licensed copy of Windows Server, then Microsoft Identity Manager can be installed and used on that server. No other separate license is required for Microsoft Identity Manager Server.

4Self-service integration of any application supporting SAML, SCIM, or forms-based authentication by using templates provided in the application gallery menu. For more details, please read this article.

Back To Top
close-button