---
title: "Office 365 Group-Based Licensing & License Assignment"
description: "Set up Office 365 group-based licensing and assign Office 365 licenses based on group membership in this tutorial."
canonical: "https://adamtheautomator.com/office-365-group-based-licensing/"
---

# Office 365 Group-Based Licensing & License Assignment

> Set up Office 365 group-based licensing and assign Office 365 licenses based on group membership in this tutorial.

Source: https://adamtheautomator.com/office-365-group-based-licensing/

---

ATA Learning

Tap to hide

[

ATA Learning

](/)

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Search for:  

*   [](https://twitter.com/adbertram)
*   [](https://github.com/Adam-the-Automator)
*   [](https://www.linkedin.com/company/adam-the-automator-llc)
*   [](/feed/)

![Office 365 Group-Based Licensing & License Assignment](https://adamtheautomator.com/wp-content/uploads/2019/10/iot-3337536_1920.png)

# Office 365 Group-Based Licensing & License Assignment

[![](https://secure.gravatar.com/avatar/0c02be182aa73668b51cadb670ce033fe73fd676d708959837e61db4d3eafb4d?s=192&d=mm&r=g)Dustin Dortch](https://adamtheautomator.com/author/dustin/)31 October 20199 min. read

Categories: [Cloud](/category/cloud/)

Tags:[Azure Active Directory](/tag/azure-active-directory/)[Office 365](/tag/office-365/)

Table of Contents

*   [Licensing Office 365 (The Hard Way)](#licensing-office-365-the-hard-way-)
*   [Individual Licenses](#individual-licenses)
*   [Suite Licenses](#suite-licenses)
*   [Using PowerShell May Work But Comes with Drawbacks](#using-powershell-may-work-but-comes-with-drawbacks)
*   [Licensing with Office 365 Group Based Licensing](#licensing-with-azure-ad-group-based-licensing)
*   [Prerequisites](#prerequisites)
*   [Licensing Requirements](#licensing-requirements)
*   [Azure AD Group-Based Licensing How-To Walkthrough](#azure-ad-group-based-licensing-how-to-walkthrough)
*   [Creating an Azure AD Group](#creating-an-azure-ad-group)
*   [Assigning Office 365 License to the Azure AD Group](#assigning-office-365-license-to-the-azure-ad-group)
*   [Direct vs. Inherited Licensing](#direct-vs-inherited-licensing)
*   [Removing Office 365 Licenses](#removing-office-365-licenses)
*   [Removing Groups with Group-Based Licensing](#removing-groups-with-group-based-licensing)
*   [Remediating Licensing Issues](#remediating-licensing-issues)
*   [Conflicting Licenses](#conflicting-licenses)
*   [No Unassigned Licenses are Available](#no-unassigned-licenses-are-available)
*   [Unmet Dependencies](#unmet-dependencies)
*   [Unassigned Usage Location](#unassigned-usage-location)
*   [Reprocessing Users](#reprocessing-users)
*   [Summary](#summary)

If you’re struggling with figuring out how to manage Office 365 user licensing at scale, look no further! You can now manage Office 365 user licensing by a group with [Azure Active Directory (AD) group based licensing](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-licensing-whatis-azure-portal) with Office 365!

Office 365 group based licensing allows you to standardize licensing applications by managing them in groups rather than by individual users. This can soon turn into a huge time-saver for admins! With a seemingly never-ending rollout of Office 365 services, you owe it to yourself to manage licenses in bulk.

Azure AD Group-based licensing is a system of implementing a licensing template that is assigned to users through group membership. Unlike manual license assignments that can be performed in the Microsoft 365 Admin Center, all portal-based tasks must be performed in the [Azure AD portal](https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?redirect_uri=https%3A%2F%2Faad.portal.azure.com%2Fsignin%2Findex%2F&response_type=code%20id_token&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2Fuser_impersonation%20openid%20email%20profile&state=OpenIdConnect.AuthenticationProperties%3Dc1MAjDuh0_4h6ikbiTG5-Poi_04cZysu5XqpBKhsqOWlN22zfhCN5aZGclhF4hBOtPFQiTvGZ9UjmUhOrTGGBX3M-LljYARhPgVmhgIwl6Kyz07ZSqqvr6zsDAB6L9qwKQq1B6zpBrQktckKS_mdJTHIxImAMOsyJFXYqTv5BBZURqnZ7qGWNIhm-5ijMhWGjYPcZLrhJEZMLILPJ0J31IVrqwpqEq0gTDGJ5RnyY_yC6Q63Eq6iuaDcaOAVUI_sRAPJh7UGRaXNQXmJPTmgnO90Jky5zLKdxDTeU5VQDGUb4QsPgQ9deOdXaKNqzv5T3aS5_U6xjazo1I8pvkUlT1FAVHgGJ50ZzMRJWChSBrE&response_mode=form_post&nonce=637597660229983042.MjI2ZjIwOTQtMjcyMi00ZjM5LWI5MGMtZjQ5NjUwMTE2Y2EwMzJjZTNlYmUtOWVkNy00NjI4LTg3ZGQtMWUwNWI3YjAyMzgx&client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&site_id=501430&client-request-id=77a4f372-e07f-4521-9f93-9b27bd99da84&x-client-SKU=ID_NET461&x-client-ver=5.3.0.0&sso_reload=true).

In this article, you’re going to learn how Office 365 licensing works today and then how you can save a lot of time and management headaches with Azure group-based licensing.

Let’s get started!

## Licensing Office 365 (The Hard Way)

Office 365 consists of a suite of services like Exchange Online, SharePoint Online, and Skype for Business Online, among others. Each service can be licensed individually by the user.

Related: [Azure AD Premium P1 vs P2: Which One to Choose?](https://adamtheautomator.com/azure-ad-premium-p1-vs-p2/)

### Individual Licenses

For example, let’s say you have purchased an _Exchange Online Plan 1_ license product. You’d like to allocate a user license to that product using a single Exchange Online mailbox.

In the [Microsoft 365 Admin Portal](https://admin.microsoft.com/), you’d click on _Assign_ as shown below to apply the _Exchange Online Plan 1_ license product to the mailbox.

![Assigning a user-based license](/wp-content/uploads/2019/10/image4-1.png)

Assigning a user-based license

The above example is for one product – _Exchange Online_. But licensed products also come in suites with the _Microsoft or Office 365 E3_ license product, for instance.

### Suite Licenses

When assigning a suite license, the individual services can be controlled as you can see below. Here you can apply license products to the mailbox at once.

![Assigning suite licenses](/wp-content/uploads/2019/10/image8-1.png)

Assigning suite licenses

### Using PowerShell May Work But Comes with Drawbacks

At some point, an organization may then need to update user licenses. They then may turn to PowerShell. Although a PowerShell script is certainly a solution, it’s not as simple as one might expect.

Even if you know how to write PowerShell code, you’ll still be faced with a confusing list of various PowerShell modules to use like MSOnline, AzureAD, AzureADPreview, and Az. Which one do you use in which circumstance? It’s not entirely clear. All work similarly.

The hardest part is figuring out which PowerShell cmdlets in these modules map to options in the Microsoft 365 Admin Portal. Inside PowerShell, you’ll see cryptic names like _Deskless for Office Online_. These names are not in the Microsoft 365 Portal.

To assign and remove user licenses with PowerShell, you’d have to find license SKUs, build a list of license options by navigating those cryptic names, and more. There is no simple cmdlet (within these modules) to easily enable and disable user licenses.

Although this approach works, it will mean writing a lot of PowerShell code which comes with its own set of management challenges.

Azure AD group-based licensing removes the requirement to get into the weeds with PowerShell and simplifies the license management process.

## Licensing with Office 365 Group Based Licensing

To forego the challenges of managing user licenses individually or using PowerShell, let’s dive into how to manage licenses via groups via Office 365 group based licensing.

### Prerequisites

If you plan to follow along with the following demonstration, know that you will need to meet a few prerequisites. You’ll first need to ensure you’re in an organization with the following licenses (paid subscriptions or active trials):

*   Azure AD Premium P1, or higher
*   Office 365 E3  license (or equivalent), or higher
*   Enterprise Mobility + Security E3, or higher (includes Azure AD Premium P1)
*   Microsoft 365 E3, or higher (includes both Office 365 E3, or higher and Enterprise Mobility + Security, or higher)

In addition, each user that has licenses applied via Office 365 group based licensing must have licenses for the product to be assigned.

### Licensing Requirements

Office 365 group based licensing is only available for organizations with the following licenses (paid subscriptions or active trials):

*   Azure AD Premium P1, or higher
*   Office 365 E3 license (or equivalent), or higher
*   Enterprise Mobility + Security E3, or higher (includes Azure AD Premium P1)
*   Microsoft 365 E3, or higher (includes both Office 365 E3, or higher and Enterprise Mobility + Security, or higher)

In addition, each user that has licenses applied via Office 365 group based licensing must have licenses for the product to be assigned and the previously mentioned licensing to support group-based licensing.

License requirements for Office 365 group based licensing present a “chicken and egg” problem. The prerequisite licenses must be available, but without having assigned the licenses, the users do not have the required license assigned. To account for this problem, Azure AD Group-based licensing is enabled tenant-wide as soon as subscriptions that meet the licensing requirements exist.

To remain in the spirit of the license, only the number of users that will be assigned one of the required licenses should have group-based licensing applied.

If, for example, 300 Office 365 E3 licenses exist (and no Azure AD Premium licenses exist), then only 300 users should be licensed via group-based licensing. There is no control that prevents exceeding the limits, so self-auditing is recommended to ensure tenants remain in compliance.

More information on licensing requirements can be found on Microsoft’s [licensing requirements](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-licensing-whatis-azure-portal#licensing-requirements) page.

## Azure AD Group-Based Licensing How-To Walkthrough

To implement Office 365 group based licensing, you must perform the following four rough steps:

1.  Create a group in Azure AD (synchronized, on-premises group, or a group only in Azure AD)
2.  Choose a license to apply
3.  Choose the license options to apply
4.  Select the applicable group(s) to apply the license settings

Related:[How to Force Azure AD Connect to Sync \[Walkthrough\]](https://adamtheautomator.com/azure-ad-connect/)

Once these steps have been done, licenses can be applied in a consistent manner to users by assigning them to the appropriate groups.

Let’s now get our hands dirty and walk through a simple example of how to implement Office 365 group based licensing!

### Creating an Azure AD Group

The first task you’ll need to do is create a group. This is the group you’ll eventually use to assign licenses to members inside of the group.

The following steps are displayed in the next screenshot.

1.  To get started, ensure you’re logged into the [Azure AD Portal](https://aad.portal.azure.com/).
2.  In the portal, navigate to _Azure Active Directory_ —> _Groups._
3.  Click _New group_.
4.  Assign the _Group name_ as _E3 Standard_. You can choose any group name you wish.
5.  Click _Members_ to add the desired members, select the desired users and click on _Select_.
6.  Click _Create_ to confirm the creation of the group.

![Creating an Azure AD group](/wp-content/uploads/2019/10/image11-1.png)

Creating an Azure AD group

### Assigning Office 365 License to the Azure AD Group

Once the group is created, it’s time to assign product licenses to the group. The following steps are displayed in the next screenshot.

1.  While still in the Azure AD portal, navigate to _Azure Active Directory_ —> _Licenses_ —> _All products_.
2.  Check the product to license as _Microsoft 365 E3_ or another product.
3.  Click _Assign_.
4.  To choose the assignment group, click _Users and groups_.
5.  Select _E3 Standard_ or the name of the group created earlier.
6.  Click _Select_.
7.  Click _Assignment options_.
8.  Toggle the desired options.
9.  Click _OK._
10.  Click _Assign_ as seen below.

![Assigning license to Azure AD group](/wp-content/uploads/2019/10/image10-1.png)

Assigning license to Azure AD group

More information can be found on the [Assign licenses to users by group membership in Azure Active Director](https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/licensing-groups-assign)y page.

> _If a user is assigned to multiple groups the various SKUs and options will be added together to form to total license assignment for the user._

## Direct vs. Inherited Licensing

A key concept for Office 365 group based licensing is _Direct_ versus _Inherited_ licensing. If a user has had licenses assigned manually, these are known as direct assignments, and Azure AD Group-based Licensing will not override these. Reviewing a member of a group that has had directly assigned and licenses inherited, you can see below.

![Direct vs. inherited license](/wp-content/uploads/2019/10/image1-1.png)

Direct vs. inherited license

### Removing Office 365 Licenses

For Office 365 group based licensing to be effective, direct-assigned licenses should be removed such that any changes to assignment options are handled with consistency via a group assignment. Any inherited assignments will remain, so the previous redundancy works to transition the user to group-based licensing seamlessly.

When users are assigned a license both directly and via inheritance, the redundant direct license assignment must be removed. To do so, in the Azure AD Portal:

1.  Navigate to _Users_.
2.  Select the user to modify.
3.  Click _Licenses_.
4.  Click on the license to remove.
5.  Click _Remove license_.
6.  Click _Yes._

You can see in the below screenshot what this will look like from steps five and six.

![Removing a direct license](/wp-content/uploads/2019/10/image9-1.png)

Removing a direct license

After a few moments, only the inherited license remains, as seen below.

![Direct license has been removed](https://adamtheautomator.com/wp-content/uploads/2020/06/icense-remains-as-seen-below.-1024x285.png)

Direct license has been removed

For more information, refer to the Microsoft page on [How to migrate users with individual licenses to groups for licensing](https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/licensing-groups-migrate-users).

After the direct licenses have been removed, users will be managed entirely through groups-based licensing.

## Removing Groups with Group-Based Licensing

As a fail-safe mechanism, a group involved in Office 365 group based licensing cannot be removed until all licenses assigned handled by the group are removed. This is to prevent inadvertent license removal that would result in users being unable to perform work.

In order to remove a group, follow the below steps:

1.  In the Azure AD Portal navigate to _Azure Active Directory_ —> _Licenses_ —> _All products_.
2.  Check the product to license _Microsoft 365 E3_.
3.  Check the group to remove.
4.  Click _Remove license_.
5.  Click _Yes_.

You can see what steps four through six looks like below.

![E3 Standard licensed groups in Azure Active Directory](https://adamtheautomator.com/wp-content/uploads/2020/06/through-six-look-like-below.-1024x243.png)

E3 Standard licensed groups in Azure Active Directory

Now the group may be removed. Be mindful of any other potential conflicts that removing licensing from a group could create, like with dependent products.

## Remediating Licensing Issues

As with direct licensing, where the admin portal displays errors in applying licenses, groups-based licensing can encounter the same circumstances which must be reconciled.

When licensing issues occur with groups-based licensing, administrators are not interactively working with the portal or PowerShell and will need to become informed of such issues. Licensing issues can be identified in the Azure AD portal under the licensing section, as seen below.

![Inspecting license problems](https://adamtheautomator.com/wp-content/uploads/2020/06/Azure-AD-portal-under-the-licensing-section-as-seen-below.-1024x446.png)

Inspecting license problems

### Conflicting Licenses

Some subscriptions have conflicting versions of licenses that cause a failure to occur when applying licenses. This failure happens when manually assigning licenses and using Office 365 group based licensing at the same time.

When you assign the _Exchange Online Plan 1_ license and there is an attempt to assign a license that includes _Exchange Online Plan 2_, or _SharePoint Online Plan 1_ and _SharePoint Online Plan 2_ is a great example. The licenses will conflict with each other.

To resolve this issue, refer to the above steps on removing the direct assignment that causes the conflict or, if necessary, removing the group-based membership.

This situation can be tricky to navigate if the combination of assignments is necessary to get a complete licensing profile assigned to a user.

### No Unassigned Licenses are Available

Even though you do everything right you might still end up in a situation where you simply run out of licenses to assign. As mentioned in the Prerequisites section, each license applied via groups-based licensing must be available within the tenant’s subscriptions.

If there are 30 users, for example, in a group being assigned an _Office 365 E3_ license but there are only 25 licenses for that SKU, there will not be enough unassigned licenses to fulfill the settings applied through groups-based licensing. You can see an example of this situation below.

![Not enough licenses available](https://adamtheautomator.com/wp-content/uploads/2020/06/You-can-see-an-example-of-this-situation-below.-1024x177.png)

Not enough licenses available

### Unmet Dependencies

Certain licenses depend on other licenses being applied. For instance, individual licenses for _PSTN service for Skype for Business_ and/or _Microsoft Teams_ require all users to have the underlying products assigned.

In this instance, if a user is not assigned options for Skype for Business or Microsoft Teams, any PSTN licenses applied will result in an unmet dependency which but be remediated prior to any PSTN functionality being available to the assigned users.

### Unassigned Usage Location

Before a user can be assigned any licenses, a usage location must be selected. The usage location is used when legal or regulatory mandates exist that restrict certain products from being used. If no usage location is assigned, the tenant location will be assigned as the usage location with groups-based licensing. While this allows the user to function, it could result in legal or regulatory ramifications.

With a direct license assigned, an error would be presented rather than automatically assigning the tenant location as the usage location.

### Reprocessing Users

After remediating any licensing errors, users may still not be in a proper license assignment. In such an event, it is necessary to force the reprocessing of license assignments.

To reprocess licensing for a user:

1.  Navigate to _Users_.
2.  Select the user to reprocess
3.  Click _Licenses_.
4.  Click _Reprocess_.

![Reprocessing licenses](https://adamtheautomator.com/wp-content/uploads/2020/06/Click-Reprocess.-1024x208.png)

Reprocessing licenses

More information can be found at the [Identify and resolve license assignment problems for a group in Azure Active Director](https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/licensing-groups-resolve-problems)y Microsoft docs page.

## Summary

Azure AD Group-based licensing can contribute to the consistent assignment and updating of product licensing within Office 365. In addition, it can be part of a mature provisioning process; such a process may begin with user creation in Active Directory, synchronization to Azure AD, provisioning an Exchange Online mailbox via the on-premises Exchange Management Shell, and assigning licenses through Office 365 group based licensing.

Share this article

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fadamtheautomator.com%2Foffice-365-group-based-licensing%2F&text=Office%20365%20Group-Based%20Licensing%20%26%20License%20Assignment)[Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fadamtheautomator.com%2Foffice-365-group-based-licensing%2F)[Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fadamtheautomator.com%2Foffice-365-group-based-licensing%2F)

## Related Posts

![](https://adamtheautomator.com/wp-content/uploads/2020/07/microsoft_office_logo_press_image_1200x800-100751542-large.jpg)

### [Connect Azure AD to Office 365: Install Azure AD Connect](/connect-azure-ad-to-office-365/)

Discover how to connect Azure AD to Office 365, install Azure AD Connect, and enable directory synchronization for your tenancy.

![](https://adamtheautomator.com/wp-content/uploads/2026/05/featured_image-3.webp)

### [Survive the Azure AD B2C Sunset with Entra External ID](/azure-ad-b2c-entra-migration/)

Learn how to migrate Azure AD B2C to Microsoft Entra External ID—covering JIT credential migration, custom policy translation, HSC mode decisions, and phased cutover strategies.

![](https://adamtheautomator.com/wp-content/uploads/2026/04/featured_image-20.webp)

### [How to Secure Azure Service Accounts with Managed Identities](/secure-azure-managed-identities/)

Learn how to replace secret-based Azure service accounts with managed identities, grant least-privilege Azure RBAC access, validate token-based authentication,

## Categories

*   [IT Ops](/category/it-ops/)
*   [Cloud](/category/cloud/)
*   [DevOps](/category/devops/)
*   [Home Ops](/category/home-ops/)
*   [Information Security](/category/infosec/)
*   [Software Development](/category/software-development/)

## Site

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Copyright 2026© ATA Learning | [Privacy Policy](/privacy/)
