Enterprise IT · 19 August 2026 · 5 min
License leakage
Group-based licensing: the failure modes, the limits, and the cost nobody sees
Group-based licensing is one of the better things Microsoft has built: put the user in the right group, and the license follows. In practice it is also one of the most leak-prone mechanisms in an M365 estate, because the errors it produces are silent. A user without a license complains. A license without a user does not.
The six error types
Microsoft documents six error states in group-based license assignment. They are worth knowing, because they explain almost every "why isn't this working" case:
1. Not enough licenses — there are fewer available licenses than there are users in the group.
2. Conflicting service plans — a product in the group contains a service plan that conflicts with a plan the user already has from another product.
3. Missing dependent service plans — a service plan requires that another plan, in another product, is enabled.
4. Usage location not specified — the user is missing usageLocation, which must be set before a license can be assigned.
5. Duplicate proxy addresses — two users have the same proxy address.
6. Other — typically a knock-on error from another license assigned by the same group.
The errors are shown in the Microsoft 365 admin center under Billing → Licenses → [product] → Errors & issues, and all activity is logged in the Entra audit log — which, worth recalling, only has 30 days of retention on P1 and P2.
The limits that surprise people
- Nested groups are not supported. Only users who are direct members of the group get a license. This is the single most common blunder: you build a neat hierarchy of department groups under an umbrella group, assign the license on the umbrella, and wonder why nobody gets anything.
- A maximum of 20 groups can be assigned licenses at a time.
- Reprocess handles a maximum of 20 users at a time.
- Large groups mean long processing time. Microsoft states that changes for groups of 60,000 users or fewer should be complete within 24 hours, otherwise a support case should be opened.
- A group with an active license assignment cannot be deleted.
The role requirement is documented: Groups Administrator, License Administrator or User Administrator.
A caveat we have to be honest about: the historical rule that group-based licensing requires Entra ID P1 for every user covered does not appear in Microsoft's current documentation as of August 2026 — only the role requirements are stated there. We therefore do not claim a license requirement we cannot document. If this is going into a proposal or a tender response, it must be verified against Microsoft Product Terms.
Where the money actually leaks
The six error types are visible. The leakage is not:
Licenses on disabled accounts. As covered in the article on offboarding, disabling an account does not remove license assignments — Microsoft's own Lifecycle Workflows have "Remove all license assignments from user" as a separate task, precisely because disabling does not do it. An E5 license on an account that was disabled in February is still an E5 license you are paying for in August.
Direct assignments that outlive the group. Directly assigned licenses are not removed when the user is taken out of the group. In estates that have moved from direct to group-based assignment without a cleanup job, both layers sit there at the same time.
The wrong SKU for the wrong role. E5 for a warehouse worker who uses Outlook Web. Visio Plan 2 for someone who opened Visio once in 2024. This is not a technical error, it is an absence of data — nobody sees the connection between actual usage and assigned SKU until the agreement comes up for renewal.
The group split. In a group of companies with several tenants, the licensing picture lives in one console per tenant. Answering "what do we pay Microsoft in total, broken down per company" requires export, manual consolidation, and an assumption that nobody has changed anything since the last export.
The negotiation argument
This is where license leakage stops being a hygiene question and becomes a CFO question. When renewing an Enterprise Agreement or a CSP program, you negotiate against a vendor who has perfect visibility into what you have bought. If you do not have correspondingly precise visibility into what you actually use, broken down per company and per role, you are negotiating from memory.
Consolidated, accurate usage data across subsidiaries is not a negotiating tool in itself — it is the precondition for having one. The point is worth stating precisely: the product provides the data foundation. It does not negotiate.
An important limitation
The cost picture covers Microsoft licenses, Azure consumption and applications connected via SSO through Entra ID. It does not cover shadow IT paid for outside SSO — SaaS somebody bought on the company card and never connected to the directory. That category requires a different tool, and claiming otherwise does not survive the first technical meeting.
Note also that static seat licenses (Microsoft 365, Visio) and consumption-based AI credits are two fundamentally different economies. The first is mature and well covered by established tools; the second is new and immature. They should not be mixed into the same argument.
What this means for Entra Logic
Cost and identity are the same data set seen from two sides. Entra Logic's synchronization service keeps users, groups, licenses and cost data in one up-to-date, searchable copy — per tenant, with allocation to company or customer. That turns "who are we paying for, in which company, with which SKU, and did they sign in last quarter" into a lookup instead of a project.
And because license changes go through the same order flow as every other change — a single order, a request that carries its own approval and execution — cleanup becomes an approved, traceable action with a justification, not a manual adjustment in a console that nobody can find again three months later.
For a group like Amesto — 58 companies, more than 1,000 employees, NOK 1.4 billion in revenue, three people in IT — this is not an efficiency gain. It is the difference between the task being possible at all and not.
—
Sources
- Microsoft Learn — Group-based licensing: additional scenarios
- Microsoft Learn — Identify and resolve license assignment problems for a group
- Microsoft Learn — Lifecycle Workflow tasks
- Microsoft Learn — Data retention for Microsoft Entra monitoring and health
RELEVANT SOLUTION
See how this is handled in practice:
Norwegian version: Les artikkelen på norsk
Related reading
- No, NIS2 does not yet apply in Norway
Enterprise IT · 7 min
- After the acquisition: multi-tenant is not a transitional phase
Enterprise IT · 4 min
- One console, many tenants: what MSPs actually need from Entra ID tooling
Practice · 6 min