Company Branding (Logon Pages/Access Panel customization)
Application Proxy
Advanced group features
Self-Service Password Reset/Change/Unlock with on-premises writeback
Device objects two-way synchronization between on-premises directories and Azure AD (Device write-back)
Multi-Factor Authentication (Cloud and On-premises (MFA Server))
Microsoft Identity Manager user CAL
Cloud App Discovery
Connect Health
Automatic password rollover for group accounts
Conditional Access based on group and location
Conditional Access based on device state (Allow access from managed devices)
3rd party identity governance partners integration
Terms of Use
SharePoint Limited Access
OneDrive for Business Limited Access
Identity Protection
Privileged Identity Management
3rd party MFA partner integration (preview)
Access Reviews
Microsoft Cloud App Security integration
Join a device to Azure AD, Desktop SSO, Windows Hello for Azure AD, Administrator BitLocker recovery
MDM auto-enrollment, Self-Service BitLocker recovery, Additional local administrators to Windows 10 devices via Azure AD Join, Enterprise State Roaming
Security/Usage ReportsAdvanced reports
Cloud app security
Discovered cloud apps16,000+
Deployment for discovery analysisManual and automatic log upload
Log anonymization for user privacy
Access to full Cloud App Catalog
Cloud app risk assessment
Cloud usage analytics per app, user, IP address
Ongoing analytics & reporting
Anomaly detection for discovered apps
Data loss prevention (DLP) supportCross-SaaS DLP and data sharing control
App permissions and ability to revoke access
Policy setting and enforcement
Integration with Azure Information Protection
Integration with third party DLP solutions
Anomaly detection and behavioral analyticsCross-SaaS apps including Office 365
Manual and automatic alert remediation
SIEM connector
Integration to Microsoft Intelligent Security Graph
Activity policies
Azure Information ProtectionPlan 2
Document classification
Automated and recommended data classification
Hold your own key (HYOK)
Bring your own key (BYOK)
Protection for content in Microsoft services
On-premises Windows Server file shares content protection
On-premises Exchange and SharePoint content protection
On-premises automated classification
Custom templates
Azure Information Protection developer kit
Document tracking and revocation
Protection for non-Microsoft Office file formats
Protected content consumption for policy-aware apps