Most writing about Global Secure Access licensing is a list of SKUs, which is why most people come away from it unable to answer the only question that matters: what do I get for what I already own, and what does the next step cost. The model underneath is simpler than the SKU list makes it look, and once you see its shape the pricing stops being fog.
Licensing follows the traffic forwarding profile
There are three administrator-managed traffic forwarding profiles, and each one is entitled separately. The Microsoft traffic profile is included with Entra ID P1 or P2. The Private Access profile requires a Private Access licence or the Entra Suite. The Internet Access profile requires an Internet Access licence or the Suite. Every user of any of them needs P1 or P2 underneath as a base, and the licensing is per user rather than per device.
That is the entire model, and it is worth stating as a rule rather than as a table, because it answers questions the table does not. Can I license Private Access for forty people and leave everyone else alone? Yes, because the profile is assigned to users and the licence follows the assignment. Do I need to buy Internet Access to use the compliant network check? No, because that control lives on the Microsoft profile. Does buying the Suite for the sales team let the finance team use Private Access? No, for the same reason.
Work out which profiles a population needs, and you have worked out what that population costs.
The consequence people miss is that the Microsoft traffic profile is genuinely free with a licence most estates already hold, and it is not a crippled tier. It carries all four clients, the compliant network check, source IP restoration, universal tenant restrictions, universal continuous access evaluation, the enriched Microsoft 365 logs, and branch connectivity for Microsoft traffic. If your reason for looking at this product is token theft rather than VPN retirement, you may find you have already bought everything you need.
I do not think that is generosity. The free tier is good because the compliant network check is the thing that makes an identity-anchored network attractive in the first place, and giving it away with P1 puts a Microsoft-shaped control in estates that would otherwise never have evaluated the product. It is a well-designed on-ramp, and recognising it as one is not a reason to refuse it.
The numbers, in one place
Everything perishable in this article is in the table below, deliberately, so that a price change is a small correction rather than a re-read. All figures are United States list, per user per month, on annual commitment, read on 30 July 2026.
| Product | List price | What it buys here |
|---|---|---|
| Microsoft Entra ID P1 | $7.00 | The base licence, and the Microsoft traffic profile with it |
| Microsoft Entra ID P2 | $10.00 | The same, plus Identity Protection |
| Microsoft Entra Internet Access | $5.00 | The Internet Access profile, on top of a base licence |
| Microsoft Entra Private Access | $5.00 | The Private Access profile, on top of a base licence |
| Microsoft Entra Suite | $12.00 | Both profiles, plus Governance, Identity Protection and premium Verified ID |
| Microsoft Entra ID Governance | $7.00 | Standalone, for the arithmetic below |
P1 and P2 moved on 1 July 2026, from six dollars and nine dollars respectively, which Microsoft published as increases of sixteen and eleven percent. The two add-on profiles and the Suite were not part of that update. That is a statement about what the update covered rather than a commitment that they were reviewed and held, and I would not tell a client those prices are protected.
The Suite arithmetic, and how it is usually mis-sold
Private Access and Internet Access bought separately come to ten dollars. The Suite is twelve. So the marginal two dollars adds Identity Governance, Identity Protection and the premium Verified ID capabilities, and since Governance alone is seven dollars standalone, the comparison looks extraordinary. It gets quoted that way often, and it is worth being careful about what it actually establishes.
It establishes that if you were already buying both network profiles, adding the rest costs two dollars. It does not establish that the Suite is worth twelve dollars to an estate that wanted one profile, and it does not establish that Governance is being sold to you at two dollars. A suite is not priced as the sum of its parts, and the delta only reads as value if you genuinely wanted the parts. I have watched the arithmetic used to justify a Suite purchase for a shop that needed Private Access for forty engineers and had no governance programme to speak of, which turned a two hundred and forty dollar annual line into a five hundred and seventy six dollar one in exchange for entitlements nobody was resourced to operate.
The honest version is that the Suite is good value where you want three or more of its five components and can staff them, and that two of one thing plus a discount on three others is a comparison, not a business case.
What your Microsoft 365 suite does and does not contain
Microsoft 365 E5 does not include Private Access or Internet Access. It carries Entra ID P2, which means an E5 estate already owns the Microsoft traffic profile and everything on it, and owns neither of the paid profiles. This surprises people regularly, because E5 is the suite that usually contains the answer, and here it does not.
Microsoft 365 E7 reached general availability on 1 May 2026 at ninety-nine dollars per user per month, and it contains E5, Microsoft 365 Copilot, Agent 365 and the Entra Suite. It is the first Microsoft 365 suite to carry the Entra Suite, and that claim rests on nobody else carrying it rather than on Microsoft describing it as a first. For an estate already committed to Copilot at scale, E7 is where the network profiles arrive as a by-product of a decision made for other reasons, and that is worth knowing before you price the add-ons separately.
Between those two sits the SKU nobody prints, and it is the most useful thing in this article for a P2 or E5 estate. There is a step-up licence called Microsoft Entra Suite Add-on for Microsoft Entra ID P2, and its published service-plan list contains four entitlements rather than five: Internet Access, Private Access, Identity Governance, and the Verified ID service request. Identity Protection is absent because a P2 estate already has it. That is the clearest available description of what a step-up actually is, and it is more informative than any price would be, because Microsoft publishes no public list price for it at all. Reseller figures circulate. Do not put one in a client document, and do not let one be quoted at you as list.
Frontline worker and education variants of the Suite exist and are named in the same reference, and none of them publishes a price or a per-variant entitlement table. I would not assume they carry identical Global Secure Access entitlements to the base Suite until somebody shows you the service plans.
A third axis appeared, and it breaks the model
Until recently this was a two-axis model: a base licence, and a profile. There is now a third. Network controls for agents sit under Internet Access in the entitlement table with a footnote requiring a separate Microsoft Agent 365 licence, so Internet Access alone does not buy them. Agent 365 in turn acquired its own prerequisite floor on 1 June 2026, requiring Microsoft 365 E5, A5 or Business Premium, or the Defender and Purview suites, before it can be purchased at all.
I raise it not because many readers are governing agent traffic yet, but because it is the first time this product has needed a licence outside the base-plus-profile pattern, and a model that has acquired one exception usually acquires more. If you are building a cost model that has to survive a renewal cycle, leave room in it for capabilities that are entitled somewhere other than where they appear.
What a hundred-user shop actually pays
List-price arithmetic, one year, one hundred users, so the shapes are comparable rather than precise. An estate that already holds P1 and wants Private Access only spends six thousand dollars. The same estate adding both profiles spends twelve thousand. Taking the Suite instead spends fourteen thousand four hundred. A greenfield estate buying P1 and the Suite together spends twenty-two thousand eight hundred.
The useful comparison is not between those four numbers. It is between the second one and what the VPN it replaces actually costs, and that is a number almost nobody has to hand. It is the appliance refresh amortised, the concentrator support renewal, the client licensing where it is licensed separately, the circuit and public address, and the labour of patching a device that terminates untrusted traffic and therefore cannot wait for a maintenance window. I am not going to invent figures for those, because they vary by an order of magnitude between estates. I will say that the second and third of them are usually the ones nobody has counted, and that a client who cannot produce them is not yet in a position to say this product is expensive.
The meters that are not on the price page
Two things in this product are metered rather than licensed per seat, and both catch people out because they do not appear in a per-user model.
The first is guests. External users are billed by monthly active user rather than by assigned licence, and the trigger is narrower than the phrase suggests: a guest becomes billable when they sign in at least once in the month to a Private Access tunnel through the client. The fifty thousand free monthly active users that External ID gives you does not extend to this, the tenant has to have an Azure subscription linked for the billing to land anywhere, and the unit price is not published, so this is a conversation with your account team rather than a line you can model from public information. The detail I would underline is that the test is the account’s type rather than where it came from, so internal accounts carrying a guest type are counted too, which is not obvious and is exactly the sort of thing that produces a surprising first invoice.
The second is branch bandwidth. Site tunnels need at least fifty combined base and Internet Access licences before the feature is available at all, each tunnel is provisioned at a fixed rate rather than sold by consumption, and the tenant’s aggregate allowance scales in bands with licence count, with two discontinuities where the allowance jumps rather than steps. Beyond the top band it grows at a fixed rate per additional block of licences, and if you need more than the band gives you there is a bandwidth add-on sold in increments, whose price is also unpublished. The practical consequence is that branch connectivity has a minimum size below which it is not a supported design, and that is worth knowing before you promise it to a client with thirty seats.
What is not metered is traffic. There is no per-gigabyte or per-transaction charge documented anywhere for client-based use of this service, and I went looking for one specifically in order to be able to say so. The honest form of that statement is that the published pricing surfaces show no consumption meter today, not that Microsoft has undertaken never to introduce one.
The costs that are real and are not licences
Private Access needs connectors, and connectors are yours. There is no per-connector fee, and there is no managed option, so the cost is compute and Windows Server licensing for machines you build and patch. Microsoft’s sizing guidance is eight gigabytes of memory and four cores or more per connector, with peak utilisation kept under seventy percent, and a minimum of two healthy connectors per group for resilience. Two is a floor rather than a target, and it is a floor per group, so an estate with connectors in three sites is running six machines before it has published anything.
Treat that as the same class of cost as the VPN concentrator you are retiring, because it is: a small number of servers that sit in the path of everything and therefore have to be built properly, monitored, and patched on somebody’s schedule. What you are buying is not the removal of that responsibility. It is a better shape for it, with the resilience handled by numbers rather than by a clustering licence.
What happens if the licensing lapses, and why I cannot tell you
This is the question every renewal conversation eventually reaches, and the answer is that Microsoft does not document it. The licensing reference has explicit paragraphs describing what happens when Conditional Access licences expire and what happens when Privileged Identity Management licences expire. The Internet Access and Private Access sections have no such paragraph. There is no documented per-user enforcement behaviour and no documented tenant behaviour.
What is documented is a state the client can enter where every traffic forwarding profile is disabled and it reports being disabled by your organisation, and it is worth knowing that this state is an administrator action or the result of a user being assigned no profile. Its documented causes do not include a lapsed licence. So the accurate statement is that the failure mode the client can surface is the same one an administrator can trigger deliberately, and that anybody telling you what a lapse specifically does is telling you something Microsoft has not published.
I would treat that as a reason to keep the renewal boring rather than as a reason to worry. But if you are the person who has to write the risk paragraph, write the absence rather than filling it in.
Two places where the documentation contradicts itself
Both are small, both are current, and both sit on pages a buyer would reasonably rely on, so I would rather name them than let you find them mid-quote.
The entitlement table marks branch connectivity as included under Internet Access, while prose on the same page describes internet traffic over branch tunnels as coming soon. Those cannot both be current, and the functional documentation elsewhere describes the capability as supported with no preview label and no general availability announcement anywhere. If you are buying for that specific use case, get it in writing.
The other is the fifty-licence floor for branch connectivity. The sentence stating the floor counts base licences plus Internet Access. The bandwidth table’s own note counts base plus Internet Access or the Suite. So whether Suite licences count toward the threshold is not stated consistently, and an estate sitting near the boundary with Suite seats has a question the documentation does not answer.
Neither is a reason to avoid the product. They are a reason to price it from a quote rather than from a page, which is true of most enterprise licensing and is only worth saying because this particular model is otherwise clean enough to tempt you into modelling it yourself.
What I would do with this
Work out which of your populations needs which profile, and price those populations rather than the estate. Then take the free one first, because the Microsoft traffic profile costs nothing on a licence you already hold and carries the control that addresses the attack most likely to happen to you. Everything after that is a project with a business case, and both of the paid profiles will still be there when the case is made.
The next article is the one that explains why the free profile is worth deploying on its own merits, and what the compliant network check actually asserts. If you have arrived here without the architecture, [GSA 1] Global Secure Access: Identity at the Network Edge sets it out.
Global Secure Access
‹ Previous: [GSA 1] Global Secure Access: Identity at the Network Edge
Next: [GSA 3] The Microsoft Profile and Conditional Access: The Cheapest Security Win You Own ›




