Microsoft cloud
EMS
Enterprise Mobility + Security
Enterprise Mobility + Security, universally abbreviated EMS, is Microsoft's licensing bundle for identity and device security services, sold as a standalone add-on (EMS E3 and EMS E5) and included as a component within the Microsoft 365 E3 and E5 suites.
Why EMS matters in a Microsoft estate
EMS matters because Microsoft 365, Azure, Windows 365, Teams, and related services are usually managed as one estate. The term connects to planning, cost, configuration, security, and day-two operational decisions across that estate.
How EMS shows up in practice
It groups together services that are functionally independent but commercially and operationally treated as a set. These include Microsoft Entra ID P1 or P2 for identity and access management, Microsoft Intune for mobile device and application management, Microsoft Defender for Identity for on-premises Active Directory threat detection, Microsoft Purview Information Protection for data classification and rights management, and Microsoft Defender for Cloud Apps at the E5 tier for cloud access security broker functionality. The distinction between EMS E3 and E5 matters considerably for licence planning. E3 covers baseline identity and device management, including Conditional Access, self-service password reset, and standard Intune device management.
E5 adds the higher-value security capabilities, notably Entra ID P2 with risk-based Conditional Access and Privileged Identity Management, and Defender for Identity, which are the features organisations most often discover they actually need only after a security incident or an audit finding forces the question. Because EMS is bundled inside Microsoft 365 E3 and E5, organisations already on those suites frequently do not need to buy EMS separately at all. A genuinely common licence-optimisation finding in mixed estates is duplicate EMS standalone licences sitting alongside an M365 E3/E5 assignment that already grants the same entitlement, wasting spend on a redundant SKU the user does not need.
The other frequent misstep runs the opposite direction: assigning EMS E5 broadly across a user base to get Entra ID P2's risk-based Conditional Access, when only privileged or high-risk accounts actually need that tier. The bulk of standard users would be fully served by E3-level identity and device management. From an operational standpoint, EMS is less a single product a user logs into than a licensing wrapper that unlocks specific service tiers inside the Microsoft admin centres. Correctly reading which EMS SKU is assigned to which user, and which underlying service plans that activates, is therefore a prerequisite for any serious Microsoft 365 licence audit or cost-reclaim exercise, since the entitlement is invisible in the interface a user actually works in day to day.