What subscription is Azure AD in M365B?

%3CLINGO-SUB%20id%3D%22lingo-sub-268035%22%20slang%3D%22en-US%22%3EWhat%20subscription%20is%20Azure%20AD%20in%20M365B%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268035%22%20slang%3D%22en-US%22%3E%3CP%3EIt's%20not%20clear%20if%20it%20is%20Azure%20AD%20P1%20or%20not%3F%26nbsp%3B%20If%20it%20isn't%2C%20what%20can't%20you%20do%20with%20it%3F%26nbsp%3B%20It%20sounds%20like%20conditional%20access%20is%20not%20possible.%26nbsp%3B%20Are%20there%20any%20side%20by%20side%20docs%20comparing%20what%20it%20is%20and%20isn't%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-274740%22%20slang%3D%22en-US%22%3ERe%3A%20What%20subscription%20is%20Azure%20AD%20in%20M365B%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-274740%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20replying%20Ashanka.%26nbsp%3B%20The%20link%20you%20supplied%20gives%20a%20broad%20overview%20of%20the%20plans%20but%20it%20doesn't%20focus%20on%20Azure%20AD%20specifically.%26nbsp%3B%20It's%20hard%20to%20tell%20what%20parts%20of%20P1%20or%20P2%20are%20included.%26nbsp%3B%20This%20particular%20comparison%20gives%20more%20granular%20comparisons%3A%20%26nbsp%3B%3CFONT%3E%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Factive-directory%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Factive-directory%2F%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20that%20link%2C%20it's%20not%20clear%20what%20%22advanced%20reporting%22%20means%20and%20reporting%20is%20something%20I've%20found%20to%20be%20really%20useful.%26nbsp%3B%20One%20example%20has%20to%20do%20with%20a%2070%20user%20tenant%20that%20has%20SSO%20and%20provisioning%20enabled%20with%20Dropbox%20(sorry%2C%20couldn't%20get%20them%20off%20it).%26nbsp%3B%20Whenever%20we%20create%20a%20user%20in%20O365%2FE3%2C%20it%20creates%20a%20user%20in%20Dropbox%20which%20is%20great.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20we%20ran%20into%20an%20issue%20where%20a%20user%20locked%20themselves%20out%20of%20O365.%26nbsp%3B%20It%20put%20their%20account%20in%20a%20blocked%20status%20(due%20to%20O365%20Cloud%20App%20Security%20policy%20in%20place).%26nbsp%3B%20As%20such%2C%20it%20removed%20them%20from%20Dropbox%20which%20shouldn't%20have%20happened.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20worked%20with%20support%20which%20took%20a%20while%20to%20find%20the%20right%20person%20to%20help%20troubleshoot.%26nbsp%3B%20By%20the%20time%20they%20finally%20figured%20out%20who%20that%20person%20was%2C%20my%20audit%20logs%20had%20expired%20and%20we%20couldn't%20see%20the%20sequence%20of%20events.%26nbsp%3B%20I%20%22think%22%20basic%20Azure%20AD%20gives%207%20days%20but%20can't%20be%20certain.%26nbsp%3B%20We%20ended%20up%20not%20being%20able%20to%20figure%20out%20why%20the%20user%20was%20removed%20from%20Dropbox.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20to%20me%2C%20it%20seems%20like%20M365B%20having%20a%20subset%20of%20P1%20is%20confusing%20which%20is%20why%20I%20was%20hoping%20to%20get%20a%20more%20granular%20breakdown%20of%20what%20it%20includes%20and%20doesn't%20include.%26nbsp%3B%20Conditional%20Access%20and%20reporting%20are%26nbsp%3Bfeatures%20that%20are%20on%20our%20radar.%26nbsp%3B%20If%20you%20can't%20come%20out%20and%20say%20Azure%20AD%20P1%20is%20included%20in%20M365B%20then%20it%20would%20be%20nice%20to%20have%20some%20clarity%20of%20what%20features%20of%20Azure%20AD%20P1%20are%20included.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnything%20to%20simplify%20the%20confusing%20subscription%2Ffeature%20matrix%20that%20keeps%20growing%20would%20be%20fantastic.%26nbsp%3B%20I%20personally%20would%20support%20a%20M365B%2B%20model%20that%20includes%20Azure%20AD%20P1%20but%20would%20be%20price%20dependent%20obviously.%26nbsp%3B%20It%20gets%20too%20cumbersome%20to%20have%20corner%20cases%20in%20regards%20to%20users%2Fsubscriptions%20so%20an%20%22all%20you%20can%20eat%22%20plan%20makes%20administration%20easier.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHopefully%20that%20made%20sense.%26nbsp%3B%20I%20rambled%20a%20bit.%26nbsp%3B%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20listening.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-274711%22%20slang%3D%22en-US%22%3ERe%3A%20What%20subscription%20is%20Azure%20AD%20in%20M365B%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-274711%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20David%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOur%20vision%20for%20M365B%20is%20to%20build%20a%20product%20that%20meets%20the%20most%20IT%20needs%20of%20an%20SMB%2C%20so%20we%20are%20curating%20it%20carefully%20to%20match%20SMB%20needs.%20The%20Service%20description%20is%20your%20best%20guide%20to%20understand%20what%20features%20it%20has%20and%20it%20does%20have%20side%20by%20side%20comparisons%3A%20%3CA%20href%3D%22http%3A%2F%2Faka.ms%2Fm365bsd%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttp%3A%2F%2Faka.ms%2Fm365bsd%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECould%20you%20tell%20us%20what%20customer%20scenarios%20you%20need%20AAD%20P1%20or%20P2%20for%3F%20is%20Conditional%20Access%20the%20only%20feature%20from%20AADP1%20that%20you%20think%20you%20need%20in%20M365B%3F%20are%20there%20other%20features.%20Would%20love%20to%20understand%20this%20more%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%3C%2FP%3E%0A%3CP%3EAshanka%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268056%22%20slang%3D%22en-US%22%3ERe%3A%20What%20subscription%20is%20Azure%20AD%20in%20M365B%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268056%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20David%20(and%20Sonia!!!)%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI've%20got%20an%20even%20better%20one%20for%20you%20in%20here...%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fausoemteam%2F2018%2F05%2F05%2Fnew-microsoft-365-business-capabilities-identity-enhancements%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fausoemteam%2F2018%2F05%2F05%2Fnew-microsoft-365-business-capabilities-identity-enhancements%2F%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%3EI%20created%20the%20table%20in%20this%20one%20to%26nbsp%3Btry%20to%20make%20it%20clearer%20than%20the%20service%20description%20for%20what%20AAD%20Premium%20P1%20features%20are%20included.%26nbsp%3B%3C%2FFONT%3E%3CFONT%3EThe%20one%20thing%20I%20just%20realised%20I%20hadn't%20followed%20up%20is%20the%20%22Application%20policy%22%20reference%20which%20I'm%20pretty%20certain%20is%20supposed%20to%20be%20the%20AAD%20Application%20Proxy%2C%26nbsp%3Bwhich%20I%20wouldn't%20rank%20as%20one%20of%20the%20more%20requested%20capabilities%20like%20CA%20or%20PW%20writeback.%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268044%22%20slang%3D%22en-US%22%3ERe%3A%20What%20subscription%20is%20Azure%20AD%20in%20M365B%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268044%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20Azure%20Active%20Directory%20product%20page%20has%20a%20nice%20side-by-side%20feature%20comparison%20across%20the%20various%20license%20types%2C%20for%20the%20full%20Azure%20AD%20licenses%3A%20%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fpricing%2Fdetails%2Factive-directory%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fpricing%2Fdetails%2Factive-directory%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F48091%22%20target%3D%22_blank%22%3E%40Mark%20O'Shea%3C%2FA%3E%26nbsp%3Bhas%20a%20great%20blog%20that%20explains%20that%20Microsoft%20365%20Business%20includes%20a%20subset%20of%20an%20Azure%20AD%20P1%20license%20features%3A%20%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fausoemteam%2F2017%2F09%2F28%2Fmicrosoft-365-business-part-2-azure-active-directory%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fausoemteam%2F2017%2F09%2F28%2Fmicrosoft-365-business-part-2-azure-active-directory%2F%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20that%20helps!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

It's not clear if it is Azure AD P1 or not?  If it isn't, what can't you do with it?  It sounds like conditional access is not possible.  Are there any side by side docs comparing what it is and isn't?

 

Thank you.

4 Replies

The Azure Active Directory product page has a nice side-by-side feature comparison across the various license types, for the full Azure AD licenses: https://azure.microsoft.com/pricing/details/active-directory/

 

@Mark O'Shea has a great blog that explains that Microsoft 365 Business includes a subset of an Azure AD P1 license features: https://blogs.technet.microsoft.com/ausoemteam/2017/09/28/microsoft-365-business-part-2-azure-active... 

 

Hope that helps!

 

 

 

 

 

Hi David (and Sonia!!!)

 

I've got an even better one for you in here...

 

https://blogs.technet.microsoft.com/ausoemteam/2018/05/05/new-microsoft-365-business-capabilities-id...

 

I created the table in this one to try to make it clearer than the service description for what AAD Premium P1 features are included. The one thing I just realised I hadn't followed up is the "Application policy" reference which I'm pretty certain is supposed to be the AAD Application Proxy, which I wouldn't rank as one of the more requested capabilities like CA or PW writeback.

 

 

 

 

Hi David

 

Our vision for M365B is to build a product that meets the most IT needs of an SMB, so we are curating it carefully to match SMB needs. The Service description is your best guide to understand what features it has and it does have side by side comparisons: http://aka.ms/m365bsd

 

Could you tell us what customer scenarios you need AAD P1 or P2 for? is Conditional Access the only feature from AADP1 that you think you need in M365B? are there other features. Would love to understand this more

 

Thanks

Ashanka

Thanks for replying Ashanka.  The link you supplied gives a broad overview of the plans but it doesn't focus on Azure AD specifically.  It's hard to tell what parts of P1 or P2 are included.  This particular comparison gives more granular comparisons:  https://azure.microsoft.com/en-us/pricing/details/active-directory/

 

In that link, it's not clear what "advanced reporting" means and reporting is something I've found to be really useful.  One example has to do with a 70 user tenant that has SSO and provisioning enabled with Dropbox (sorry, couldn't get them off it).  Whenever we create a user in O365/E3, it creates a user in Dropbox which is great.

 

However, we ran into an issue where a user locked themselves out of O365.  It put their account in a blocked status (due to O365 Cloud App Security policy in place).  As such, it removed them from Dropbox which shouldn't have happened. 

 

I worked with support which took a while to find the right person to help troubleshoot.  By the time they finally figured out who that person was, my audit logs had expired and we couldn't see the sequence of events.  I "think" basic Azure AD gives 7 days but can't be certain.  We ended up not being able to figure out why the user was removed from Dropbox.

 

So to me, it seems like M365B having a subset of P1 is confusing which is why I was hoping to get a more granular breakdown of what it includes and doesn't include.  Conditional Access and reporting are features that are on our radar.  If you can't come out and say Azure AD P1 is included in M365B then it would be nice to have some clarity of what features of Azure AD P1 are included.  

 

Anything to simplify the confusing subscription/feature matrix that keeps growing would be fantastic.  I personally would support a M365B+ model that includes Azure AD P1 but would be price dependent obviously.  It gets too cumbersome to have corner cases in regards to users/subscriptions so an "all you can eat" plan makes administration easier.

 

Hopefully that made sense.  I rambled a bit.  :)

 

Thanks for listening.