How Entra Suite Closes the Zero Trust Gap AI Agents Left Open
Sep 24, 2026
Nicole Walker
Cloud Security
|
Microsoft Solutions
|
Microsoft 365
|
Cybersecurity
|
Sourcepass MCOE
9 min read
In some Microsoft 365 tenants, non-human identities now outnumber human ones, and almost no one can say how many non-human identities they have or what those identities can reach.
Copilot agents, custom agents, and third-party tools are authenticating inside the environment every day, often with standing access and no owner attached. Most Zero Trust frameworks were designed around human users, and they have not caught up to identities that authenticate on their own. The same organizations trying to close that gap are also being asked to tighten identity, replace aging VPNs, and get shadow AI under control, usually with fewer tools and less budget.
Microsoft Entra Suite closes that gap by applying one Conditional Access policy model across users, devices, private applications, internet and SaaS traffic, and AI agents.
Microsoft Entra Suite is one of the tools Microsoft is building (Agent 365 is the other) to pull those problems into one identity-centered model. It bundles identity governance, risk-based protection, VPN replacement, secure web and AI gateway controls, and identity verification, and it extends the same policy model to AI agents through Entra Agent ID.
What is the Microsoft Entra Suite?
Microsoft Entra Suite is a $12 per user per month add-on that sits on top of an Entra ID P1 or P2 base. It bundles five products:
- Entra ID Governance for entitlement management, access reviews, lifecycle workflows, and just-in-time admin elevation.
- Entra ID Protection for AI-driven user and sign-in risk detection.
- Entra Private Access for identity centric Zero Trust Network Access (ZTNA) that replaces legacy VPNs.
- Entra Internet Access for secure web gateway and AI gateway controls.
- Entra Verified ID for high-assurance identity verification with biometric liveness checks.
The Suite is also included in the new Microsoft 365 E7 bundle, which launched on May 1, 2026. E7 combines Microsoft 365 E5, Copilot, Agent 365, and Entra Suite.
Entra ID P1 is required because it includes Conditional Access. Business Premium, M365 E3, and M365 E5 already have it. Business Basic and Business Standard do not, and adding the Suite without P1 will not deliver value.
What is the Difference Between Entra Suite and Entra ID P2?
Microsoft sells identity in tiers, and the naming has been a source of confusion since Azure Active Directory was renamed Entra ID a couple of years ago.
|
Tier |
Per User / Month |
What It Adds |
|---|---|---|
|
Entra ID Free |
$0 |
Basic SSO, basic MFA |
|
Entra ID P1 |
$6 |
Conditional Access, dynamic groups, hybrid join |
|
Entra ID P2 |
$9 |
Identity Protection, PIM, access reviews. Often sold as part of Defender Suite at $10 to $12 |
|
Entra Suite |
$12 |
Adds Private Access, Internet Access, ID Governance, Verified ID |
Pricing reflects Microsoft list pricing in USD as of September 2026.
The difference between Entra Suite and Entra ID P2 comes down to scope. P2 covers the risk engine and privileged access controls. The Suite adds the network layer through Private Access and Internet Access, along with full ID Governance and Verified ID Premium.
How does Conditional Access Work Across Entra Suite?
Because every component feeds into or extends it, Conditional Access comes first. It is the policy engine the rest of the Suite runs through.
Conditional Access evaluates every access request in real time against signals such as user identity, group membership, device compliance from Intune, IP or named location, sign-in risk, application sensitivity, and platform. Based on those signals, it can require phishing-resistant MFA such as a FIDO2 passkey, require a compliant device, block legacy authentication, restrict access by app or location, or block the session entirely.
Two capabilities do most of the work here:
- Report-only mode lets you phase in policies and watch impact before enforcing them.
- Continuous Access Evaluation (CAE) reevaluates access mid-session, not only at sign-in. If Microsoft detects new risk during the session, it can revoke the token in real time and force reauthentication.
Mid-session revocation matters. Attackers stopped guessing passwords a long time ago. They steal tokens, replay sessions, and walk in with valid credentials. If your policies only evaluate at sign-in, you are protecting the door and ignoring what happens inside.
What does Entra ID Protection Detect?
ID Protection is the AI-driven detection layer that feeds risk signals into Conditional Access. It scores two dimensions:
- User risk covers leaked credentials, anomalous behavior, or compromise indicators tied to the identity.
- Sign-in risk covers impossible travel, unfamiliar location, atypical token behavior, or malicious IP.
Those scores trigger outcomes automatically. High user risk can force a password reset and MFA. Medium sign-in risk can require a fresh MFA prompt, which shuts down stolen-token replay because the attacker cannot complete the challenge. High sign-in risk can block access entirely.
Announced at Ignite 2025, expanded AI-powered threat detections and Security Copilot integration is now live inside the Entra admin portal, bringing risk analysis, automated investigations, and guided remediation into one place.
ID Protection is often paid for and never fully turned on or left in audit mode. A smoke detector with dead batteries adds no value. If you own the Suite, this is a feature that has to be deployed and enforced.
How does Entra Private Access Replaces a VPN?
Legacy VPNs are showing their age. They grant broad network access, add little identity-based control, cost real money to operate as hardware and licenses move with devices, and have been a consistent target for zero-day exploits against VPN and firewall solutions.
Private Access is Microsoft's Zero Trust Network Access (ZTNA) service, delivered as one half of Global Secure Access, Microsoft's Secure Service Edge (SSE) platform. It replaces the VPN with per-application access enforced through Conditional Access and MFA, including for legacy apps that could never natively support modern authentication.
What it delivers:
- Per-app tunneling instead of full-network exposure.
- MFA and device compliance on every connection, including legacy apps.
- Support for TCP and UDP, including RDP, SSH, and legacy app connections.
- No public IP required for private resources.
- Split tunneling for hybrid networks.
- Traffic routed through Microsoft's global network, which can outperform the public backbone for international or low-bandwidth users.
For endpoint-based access, Microsoft uses the Global Secure Access client rather than a traditional VPN agent. Browser-based access may also be available for some private application scenarios, which can be useful for contractors or BYOD users when installing a client is not practical.
Before deployment, confirm the endpoint identity and device compliance requirements for your access model. Conditional Access can enforce device posture, but the exact requirements depend on whether you are using the client, browser-based access, Intune compliance, and the join or registration state of the device.
How does Entra Private Access Connect to On-Premises Applications?
Private Access still needs a path into the legacy environment. Microsoft supports that in two common ways: remote network connectivity, which can use a site-to-site VPN from the customer network into Global Secure Access, or private network connectors installed on Windows Server inside the legacy datacenter or private network.
The connector model is often the cleaner starting point for traditional datacenter applications. The connector is a lightweight agent that sits close to the application servers and makes outbound connections to Microsoft's service, so organizations do not have to publish inbound firewall rules or expose private resources directly to the internet.
Site-to-site connectivity can make sense when the organization wants to connect a broader network location, branch, or datacenter into Global Secure Access. Connectors make sense when access should be scoped closer to specific private application, connector groups, or isolated network segments. In either model, users still authenticate through Entra, and access decisions are enforced through Conditional Access rather than broad VPN entitlement.
How Entra Internet Access Controls Shadow AI and Web Traffic
Internet Access is the other half of Global Secure Access. It handles outbound internet and SaaS traffic, and it replaces a traditional secure web gateway (SWG) such as Zscaler or Netskope for many workloads.
The classic SWG capabilities are here, including blocking malicious URLs and categories, FQDN-based filtering, token theft detection tied to network authentication, and tunneling traffic through Microsoft's network for untrusted connections such as hotel or coffee-shop Wi-Fi.
The newer capability is where shadow AI gets solved. Internet Access includes an AI gateway that lets you enforce policy on generative AI traffic:
- Block unauthorized AI apps.
- Prevent data loss via AI prompts.
- Control which Gen AI tools employees can use.
- Log and audit AI interactions for compliance.
That gives admins more control over how AI tools are accessed and what data can leave the environment. You can allow ChatGPT for general use while blocking uploads of company data. You can permit Copilot broadly while restricting other tools by role. And you can produce an audit trail of AI activity that satisfies both compliance and internal governance.
What does Entra ID Governance do?
Entra ID Governance is the component that answers two questions every audit eventually asks, who has access to what, and should they still have it.
Core capabilities:
- Entitlement management builds access packages that bundle apps, groups, and SharePoint sites into a single request-and-approval workflow, with single or multi-stage approvals and time-limited grants.
- Access reviews run user-centric or resource-centric, with auto-revoke when reviewers do not respond.
- Lifecycle workflows automate onboarding, role changes, and offboarding, from provisioning apps and assigning groups to revoking access and disabling accounts.
- Privileged Identity Management (PIM) provides just-in-time elevation for admin roles with MFA at elevation, approval workflows, time-bounded access, and an audit trail of why elevation was requested.
Risk-based approvals trigger a review when Entra detects new risk on an account. For sensitive data and regulated industries, that closes a real gap between detection and access change.
For larger organizations, the automation around joiner, mover, and leaver events is where the hours come back. This is the layer that pulls HR tickets out of the queue.
How Entra Verified ID Verifies Identity with Face Check
Passwords and MFA prove someone knows a credential. Verified ID proves they are who they say they are. It is Microsoft's implementation of decentralized identity using verifiable credentials, and it matters more every quarter as deepfake attacks and fraudulent-hire schemes rise, including cases of threat actors from foreign nations getting hired at American companies to gain inside access.
Where it applies:
- Face Check provides real-life biometric liveness verification tied to a verified credential to stop deepfake spoofing and account takeover on high-risk workflows.
- Employee verification fully verifies the person without collecting or storing all the underlying data yourself.
- External partner verification confirms identity of partners without requiring them to be in your directory.
- Self-service account recovery gates password resets and MFA recovery behind real identity proofing.
In financial services and healthcare, this is becoming a compliance requirement rather than a nice-to-have.
How Entra Agent ID Extends Zero Trust to AI Agents
This is the newest piece, and it is why Entra Suite has become central to the E7 story.
As organizations deploy more Copilot agents, custom agents, and third-party tool agents, those agents need identities, permissions, and access controls just like users. Left ungoverned, these agents become one of the largest attack surfaces. Each one can authenticate, hold standing permissions, and reach data on its own, yet most never get an owner or a review.
Agent ID treats an AI agent as a first-class identity in Entra, with the following:
- Agent inventory to register and catalog every agent operating in the tenant.
- Least-privilege scoping so an invoice-review agent gets access to invoices, not the entire accounting suite.
- OAuth and token management for visibility into how agents authenticate and where tokens flow.
- Sign-in and audit logs for agent activity, which closes the long-standing pain of investigating enterprise apps after the fact.
- Access packages for agents that mirror how governance already works for users, including inheritable permission blueprints.
Agent ID is best understood as an Entra identity capability, but the licensing path runs through the Agent 365 model. Microsoft currently positions agent identity governance as requiring either Microsoft 365 E7, which includes both Agent 365 and Entra Suite, or a Microsoft Agent 365 license paired with at least Entra ID P1 or Microsoft 365 E3. Entra provides the identity, governance, Conditional Access, and audit framework for agents, while Agent 365 is the commercial and management layer that lights up the agent-specific capabilities.
How Much does Microsoft Entra Suite Cost?
Extending that same identity model across every layer is also where the cost case comes together. Bought individually, the components of the Suite would run $17 to $23 per user per month, while the bundled price is $12. That figure comes before your account for what you may be able to retire, including the VPN contract, the secure web gateway contract, the PAM tool, and the lifecycle automation add-ons. For Microsoft-first organizations, the consolidation math often works out in the Suite's favor.
How to Deploy Entra Suite in a Zero Trust Rollout
Entra Suite usually makes the most sense after the Entra ID P1 foundation is already in place. Conditional Access, MFA enforcement, device compliance, and identity hygiene should come first. From there, the Suite adds the network, governance, verification, and AI access controls that move Zero Trust beyond sign-in policy.
|
Rollout Layer |
What to Deploy |
Why It Matters |
|---|---|---|
|
Baseline identity |
Entra ID P1, Conditional Access, MFA, device compliance |
Establishes the policy foundation the Suite depends on |
|
Risk-based access |
Entra ID Protection, PIM, access reviews |
Adds automated response to risky users, risky sign-ins, and privileged access |
|
Network access |
Entra Private Access and Entra Internet Access |
Replaces broad VPN access and applies identity-based controls to private apps, SaaS, internet, and AI traffic |
|
Governance |
Entra ID Governance |
Automates access packages, lifecycle workflows, approvals, and recurring reviews |
|
AI access |
Entra Agent ID and AI gateway controls |
Brings agents and generative AI traffic into the same Zero Trust model as users |
Microsoft Entra Suite FAQ
-
Is Entra Suite included in Microsoft 365 E5?
No. E5 includes Entra ID P2, not the full Suite. Entra Suite is a separate add-on at $12 per user per month, or it is included in the new M365 E7 bundle.
-
How much does Microsoft Entra Suite cost?
Microsoft Entra Suite is $12 per user per month as an add-on to Entra ID P1 or P2. Bought separately, the same components would run $17 to $23 per user per month.
-
What is included in Microsoft Entra Suite?
Entra Suite bundles five products: Entra ID Governance, Entra ID Protection, Entra Private Access, Entra Internet Access, and Entra Verified ID. It also extends Zero Trust to AI agents through Entra Agent ID (which also requires Agent 365 licensing).
-
Do I need Entra ID P1 or P2 to use Entra Suite?
Yes. Entra ID P1 is the minimum prerequisite, because Conditional Access is the foundation the Suite builds on.
-
Does Entra Private Access fully replace a VPN?
For most private app access scenarios, yes. It uses ZTNA to provide per-application access instead of broad network access, with MFA and Conditional Access enforced on every connection.
-
How does Entra Suite address shadow AI?
Entra Internet Access includes an AI gateway that helps block unauthorized Gen AI tools, prevent data loss through prompts, and log AI interactions for audit.
-
What is Entra Agent ID?
Agent ID gives AI agents their own identity in Entra so they can be inventoried, scoped to least privilege, governed with access packages, and audited like any other user.
Is Microsoft Entra Suite Worth it for your Organization?
Entra Suite brings several Zero Trust controls into one place, including identity risk, access governance, private app access, internet and AI traffic controls, and high-assurance identity verification. What matters more than the bundle is the model behind it, a single identity-centered policy applied across users, devices, private resources, SaaS traffic, and AI agents.
For organizations already invested in Microsoft 365, Entra Suite is worth evaluating when VPN risk, shadow AI, over-privileged access, or manual provisioning have become hard to manage with separate tools. It comes down to fit, meaning whether the organization is ready to extend Conditional Access beyond sign-in and use it as the enforcement point for identity, network, and AI access.
Want to explore whether this fits your environment? Reach out to our experts to talk through your current setup.
Subscribe To
Sourcepass Insights
Sourcepass Insights
Stay in the loop and never miss out on the latest updates by subscribing to our newsletter today!
