Which license is needed to provide Entra Application Proxy for external identities? Microsoft Azure

Benedict Lohse 20 Reputation points
2026-07-13T12:18:23.75+00:00

We are currently providing an internal web application (hosted on Azure) to customers via Entra Application Proxy. Usually we create a new tenant for each customer, create users and assign an Entra P1 license so they can use the Application Proxy.

Our new way of deployment should be to host all of our customers in a single, centralized tenant. Many customers already have their own tenants with users, thus we find it redundant to create a new set for users each time we deploy a tenant.

In order for them to access our internal Azure ressources, we are planning to invite their users into our centralized tenant. Question is: Do we need to provide new licenses for each external user again or are they allowed to use this feature via the MAU model (s. https://learn.microsoft.com/en-gb/entra/external-id/external-identities-pricing)?

We know that it is possible for external identities to use MFA and Conditional Access features without needing an Entra P1 license. Thus it would be kind of confusing if it would be different to Entra Application Proxy. But it would be still nice to get some sort of confirmation from Microsoft since we werent able to find a clear answer, nor could our license distributor.

Thank you in advance!

Azure Application Gateway
Azure Application Gateway

An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.

0 comments No comments

Answer accepted by question author

Marcin Policht 99,785 Reputation points MVP Volunteer Moderator
2026-07-13T14:26:50.1533333+00:00

Yep - you do not need to purchase or assign new Entra P1 licenses for your external users in this scenario. They are covered under the Monthly Active Users billing model for external identities. Entra Application Proxy is an Entra ID P1 feature, so you need at least one valid Entra ID P1 (or higher) license assigned within your centralized tenant to activate and manage the Application Proxy infrastructure. Once active, your invited external guest users can authenticate through it, and their usage counts towards your MAU tier rather than consuming a traditional individual per-user license seat.

For more, refer to https://learn.microsoft.com/en-us/entra/external-id/external-identities-pricing


If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

hth

Marcin

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Christos Panagiotidis 3,301 Reputation points
    2026-07-14T09:17:30.9466667+00:00

    Hi, Application Proxy licensing and External ID licensing are separate parts of the design. Application Proxy requires the appropriate Microsoft Entra ID P1/P2 entitlement for the tenant/users using the capability, while external guest/External ID usage follows its own monthly-active-user billing model and feature requirements. The exact license depends on whether these are B2B guests in a workforce tenant or customers in an External ID external tenant, and whether Conditional Access or Identity Protection is used. Map that identity type first, then verify the current Product Terms/licensing page or ask your Microsoft licensing partner for a written confirmation. Technically working access is not proof that the tenant is correctly licensed.

    Was this answer helpful?

    0 comments No comments

  2. Paul Promise Dzahini 210 Reputation points
    2026-07-13T12:30:24.4633333+00:00

    Yes — your external users can access your internal application through Entra Application Proxy under the MAU (Monthly Active Users) model.

    You do not need to assign Entra ID P1 licenses to each external user.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.