Knowledge for better technology decisions
Knowledge BaseMicrosoft licensing

Microsoft licensing · Module 3

Tenant-wide Microsoft 365 capabilities:
How should they be licensed?

Some Microsoft 365 capabilities are switched on centrally for the whole organisation. That does not mean one licence always covers everyone—or that every user automatically needs the most expensive licence.

A central setting does not tell you which people must be licensed.

What matters is which capability is used, who benefits from it, and which base or additional licence is required.

  1. 01Every capability has its own licensing rules
  2. 02Tenant-wide does not automatically mean E5 for every account
  3. 03Assess every benefiting user and affected resource
  4. 04Additional licences need an eligible base licence

Who benefits from which capability?

A tenant is an organisation's shared Microsoft 365 environment. Even when a capability is switched on centrally, you still need to check which users, devices, or data it actually covers.

Per user or device

Conditional Access, Purview policies, and Intune depend on the users or devices that actually benefit.

Per protected service or system

Customer Key applies different counting rules to protected services; protected servers can require separate server licences.

Documented exception

One eligible Copilot licence can unlock particular SharePoint management capabilities tenant-wide, but not every capability.

Consumption or special rule

Microsoft 365 Backup is billed through Azure; selected Teams Premium capabilities follow the meeting organiser.

An add-on is an additional licence. A prerequisite is the required base licence or another condition. Both must match the capability actually being used.

01

What does tenant-wide actually mean?

A tenant-wide capability is enabled or configured centrally for a Microsoft 365 organisation. Its technical reach and the people requiring appropriate licences are separate questions.

TENANT

Centrally enabled

Customer Lockbox is enabled through organisation settings. Conditional Access and Purview policies are also managed centrally.

SCOPE

Different areas of impact

A capability can affect the entire tenant, be limited to user groups, protect specific mailboxes, or apply to selected SharePoint sites.

LICENCE

Usage rights remain user-specific

Microsoft generally requires an appropriate licence for each user benefiting from the service. Some capabilities additionally apply explicit workload-specific counting rules.

RISK

Technically available does not mean compliant

A service can operate tenant-wide even though not every benefiting user is correctly licensed. For Customer Key, insufficient licensing can cause encryption to revert to Microsoft-managed default encryption.

02

Licensing is not limited to the administrator

Microsoft provides concrete examples for Purview. The relevant population includes not only the person creating a policy, but also people whose content, activities, or shared resources receive protection or analysis.

  1. 01Administrators and other users assigned an appropriate Microsoft Purview role.
  2. 02Users whose Exchange mailbox, OneDrive account, Teams chat, or device is covered by a policy or capability.
  3. 03Owners and members of a SharePoint site, Microsoft 365 group, or Team where a licensed Purview capability is used.
  4. 04For Teams DLP, senders whose chat or channel messages are inspected.
  5. 05For Insider Risk Management, users whose activities are monitored by a relevant policy.
Important distinction

For shared locations, Microsoft explicitly excludes visitors and users with view-only permissions from this particular licensing benefit. The Purview service description says inactive mailboxes do not require a usage licence. Guests, technical identities, and other exceptions must be assessed against the relevant product terms.

03

Which tenant-wide and centrally managed capabilities exist?

Microsoft organises tenant-related security, compliance, identity, and management capabilities into multiple product families. Distinguish genuine tenant-wide effects from scoped policies and user-, device-, or consumption-based licensing.

Microsoft Purview: compliance and information protection

31 capabilities

A centrally configured policy does not automatically mean one tenant licence. Evaluate protected users, content, mailboxes, and the exact premium capability.

CapabilityImpact / scopeLicensing and prerequisite
Audit (Standard)Scoped usersVerify an eligible baseline licence and the users or data sources actually covered.
Audit (Premium)Scoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Audit: 10-Year RetentionScoped usersRequires the separate 10-Year Audit Log Retention add-on for covered users.
Collection PoliciesEntire tenantThe collection policy itself does not require a separate licence; assess underlying capabilities and any pay-as-you-go charges.
Communication ComplianceScoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Compliance ManagerAdministration / scopeFollow the documented product-specific exception, applicable SKU, and exact service description.
Customer KeySpecific workloadExplicit counting rules apply to Exchange, Teams, or SharePoint licences; the calculation differs by workload.
Customer LockboxEntire tenantCheck eligible E5, Purview, or explicitly qualified add-ons; Microsoft does not publish a Customer Key-style counting formula.
Data ConnectorsScoped usersEach user actually benefiting from this protection requires the appropriate product entitlement.
Data Lifecycle ManagementContent / policiesAssess the licensing rule separately for the protected users, content, and affected workload.
Records ManagementContent / policiesAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Adaptive ScopesScoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Endpoint DLPUsers / endpointsAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
DLP: Cloud Apps im BrowserScoped usersFollow the documented product-specific exception, applicable SKU, and exact service description.
DLP: Cloud Apps auf NetzwerkebeneScoped usersDocumented consumption-based network scenarios additionally require an Azure subscription linked for pay-as-you-go billing.
DLP: Microsoft TeamsScoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
DLP: Exchange, SharePoint und OneDriveContent / policiesAssess the licensing rule separately for the protected users, content, and affected workload.
DLP: Microsoft Graph APIsSpecific workloadFollow the documented product-specific exception, applicable SKU, and exact service description.
DLP: Copilot und Copilot ChatScoped usersAssess Copilot, Purview, user, agent, and feature-specific prerequisites separately.
eDiscovery (Standard)Content / policiesVerify an eligible baseline licence and the users or data sources actually covered.
eDiscovery (Premium)Content / policiesAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Information BarriersScoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Sensitivity Labels / Information ProtectionContent / policiesAssess the licensing rule separately for the protected users, content, and affected workload.
Automatic LabelingContent / policiesAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Content Explorer / Activity ExplorerAdministration / scopeAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Microsoft Purview Message EncryptionScoped usersAssess the licensing rule separately for the protected users, content, and affected workload.
Advanced Message EncryptionScoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Double Key EncryptionContent / policiesAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Insider Risk ManagementScoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Forensic EvidenceScoped usersRequires eligible Insider Risk rights plus additional Forensic Evidence capacity.
Data Security Posture Management für AIScoped usersAssess Copilot, Purview, user, agent, and feature-specific prerequisites separately.

Microsoft Defender: email, identities, devices, and cloud applications

16 capabilities

Several Defender services are technically enabled tenant-wide. Microsoft states that Defender for Identity currently cannot limit benefits to specific users.

CapabilityImpact / scopeLicensing and prerequisite
Defender for BusinessEntire tenantEach user actually benefiting from this protection requires the appropriate product entitlement.
Defender for Business ServersServers / VMsSeparate server licence; requires at least one Business Premium or Defender for Business licence; maximum 60 server licences per customer.
Defender for Cloud AppsScoped usersEach user actually benefiting from this protection requires the appropriate product entitlement.
App GovernanceScoped usersVerify the precise suite, included feature, and users or resources actually benefiting.
Defender for Endpoint P1Users / endpointsEach user actually benefiting from this protection requires the appropriate product entitlement.
Defender for Endpoint P2Users / endpointsAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Defender for Endpoint for ServersServers / VMsA separate licence is required for each protected operating system environment; user licences do not automatically cover servers.
Defender for IdentityEntire tenantUser-based licensing; Microsoft explicitly states that benefits currently cannot be limited to specific users.
Defender for Office 365 P1Scoped usersEach user actually benefiting from this protection requires the appropriate product entitlement.
Defender for Office 365 P2Scoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Safe LinksScoped usersEach user actually benefiting from this protection requires the appropriate product entitlement.
Safe AttachmentsScoped usersEach user actually benefiting from this protection requires the appropriate product entitlement.
Attack Simulation TrainingScoped usersAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Defender for IoT: Enterprise IoTUsers / endpointsOne add-on per IoT device; Defender for Endpoint P2 or a product containing P2 is required.
Defender Vulnerability ManagementUsers / endpointsAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Defender XDR / Defender ExpertsEntire tenantVerify the precise suite, included feature, and users or resources actually benefiting.

Microsoft Entra: access, identities, and governance

16 capabilities

Entra is managed centrally but distinguishes users, external identities, workload identities, administrator roles, and individual resources.

CapabilityImpact / scopeLicensing and prerequisite
Conditional AccessScoped usersAffected users need Entra ID P1 or a qualifying product that contains P1.
Risk-based Conditional AccessScoped usersAffected users need Entra ID P2 or another expressly eligible suite.
Entra ID ProtectionIdentitiesAffected users need Entra ID P2 or another expressly eligible suite.
Privileged Identity ManagementAdministration / scopeAffected users need Entra ID P2 or another expressly eligible suite.
Access ReviewsScoped usersCheck the Entra ID Governance entitlement and the users covered by the governance scenario.
Entitlement ManagementScoped usersCheck the Entra ID Governance entitlement and the users covered by the governance scenario.
Lifecycle WorkflowsScoped usersCheck the Entra ID Governance entitlement and the users covered by the governance scenario.
Dynamic Groups / Administrative UnitsScoped usersAffected users need Entra ID P1 or a qualifying product that contains P1.
Cross-Tenant SynchronizationExternal identitiesAffected users need Entra ID P1 or a qualifying product that contains P1.
Entra External IDExternal identitiesFollow the documented product-specific exception, applicable SKU, and exact service description.
Entra Workload IDIdentitiesFollow the documented product-specific exception, applicable SKU, and exact service description.
Entra Internet AccessScoped usersVerify the precise suite, included feature, and users or resources actually benefiting.
Entra Private AccessScoped usersVerify the precise suite, included feature, and users or resources actually benefiting.
Entra Verified IDIdentitiesFollow the documented product-specific exception, applicable SKU, and exact service description.
Entra Domain ServicesResource / consumptionReview Azure-based pay-as-you-go billing, the connected subscription, and the protected resources.
Agent Identities / Agent Conditional AccessAgents / identitiesCheck Agent 365, Entra, user, and underlying product prerequisites for the precise scenario.

Microsoft Intune: device management and advanced capabilities

12 capabilities

Microsoft requires an appropriate licence for every user or device directly or indirectly benefiting from Intune.

CapabilityImpact / scopeLicensing and prerequisite
Intune Plan 1: MDM / MAMUsers / endpointsEvery user or device directly or indirectly benefiting from Intune needs the appropriate entitlement.
Intune Device LicenseUsers / endpointsCheck the eligible device licence or the appropriate entitlement for the users and endpoints covered.
Device Compliance / Conditional AccessScoped usersAffected users need Entra ID P1 or a qualifying product that contains P1.
Intune Plan 2Scoped usersAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Remote HelpScoped usersAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Advanced AnalyticsUsers / endpointsAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Endpoint Privilege ManagementScoped usersAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Microsoft Cloud PKIUsers / endpointsAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Enterprise Application ManagementUsers / endpointsAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Specialty Device ManagementUsers / endpointsCheck the eligible device licence or the appropriate entitlement for the users and endpoints covered.
Microsoft Tunnel for MAMUsers / endpointsAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Firmware-over-the-Air UpdatesUsers / endpointsAn eligible base licence and the appropriate feature-specific add-on or suite are required.

Microsoft Priva: tenant-wide privacy risk management

2 capabilities

Microsoft Priva identifies risks when handling personal data. Privacy Risk Management is a tenant-wide add-on; check the eligible base licence and every protected or benefiting person.

CapabilityImpact / scopeLicensing and prerequisite
Priva Privacy Risk ManagementEntire tenantTenant-wide privacy add-on: verify the eligible base licence and every benefiting user. Microsoft does not list F1/F3 frontline plans as eligible base licences.
Oversharing / Data Transfer / Data HoardingScoped usersLicense every user intended to benefit from or receive protection through the tenant-wide privacy service.

SharePoint, Teams, agents, and consumption-based services

10 capabilities

These services use particularly different models: Copilot-based enablement, meeting-organiser rights, agent prerequisites, and Azure consumption.

CapabilityImpact / scopeLicensing and prerequisite
SharePoint Advanced Management via CopilotEntire tenantA documented exception: at least one assigned eligible Copilot licence can unlock included SAM capabilities for SharePoint administrators across the tenant.
SharePoint Advanced Management Plan 1Entire tenantCapabilities such as Restricted Site Creation by Apps still require SAM Plan 1; Copilot does not unlock every SAM feature.
SAM: Sensitivity LabelsContent / policiesAn eligible premium licence is required for the users, content, or resources benefiting from the capability.
Teams Premium: organizer-based featuresMeeting organiserA licensed organiser can share particular meeting capabilities with attendees during that meeting; not every attendee automatically needs Premium.
Teams Premium: personal user featuresScoped usersAn eligible base licence and the appropriate feature-specific add-on or suite are required.
Microsoft 365 BackupResource / consumptionReview Azure-based pay-as-you-go billing, the connected subscription, and the protected resources.
Microsoft 365 ArchiveResource / consumptionReview Azure-based pay-as-you-go billing, the connected subscription, and the protected resources.
Microsoft Purview Pay-as-you-goResource / consumptionReview Azure-based pay-as-you-go billing, the connected subscription, and the protected resources.
Microsoft Agent 365Agents / identitiesMicrosoft lists prerequisites including Microsoft 365 E5/A5/Business Premium or qualifying Defender-and-Purview combinations; verify the exact SKU and agreement.
Copilot Studio Agents / Copilot CreditsAgents / identitiesAssess Copilot, Purview, user, agent, and feature-specific prerequisites separately.
How should this inventory be interpreted?

The inventory covers Microsoft's documented product families and their main centrally managed capabilities. Not every administrative setting is a separate licensable product. The actual SKU, Product Terms, agreement and acquisition date, technical scope, and benefiting users or resources remain authoritative.

04

Same tenant, different licensing rules

A shared activation surface does not imply identical requirements. The protected user population and the specific product prerequisites are what matter.

CapabilityTechnical effectLicensing approach
Customer Key: multiple workloadsTenant-level encryption policy across several Microsoft 365 servicesAt least as many eligible Customer Key licences as users assigned Exchange or Teams licences, whichever number is greater.
Customer Key: ExchangeEncryption policy assigned to individual Exchange mailboxesEach protected user mailbox needs a persistent eligible licence; Microsoft documents an exception for certain non-user-specific mailboxes.
Customer Key: SharePoint / OneDriveTenant-level encryption covering SharePoint and OneDriveAt least as many eligible Customer Key licences as users assigned SharePoint licences.
Customer LockboxCentral approval process for Microsoft support access to tenant contentAssess appropriate Lockbox rights for benefiting scenarios. Microsoft does not publish the same numerical counting formula used for Customer Key.
Conditional AccessCentral access policies with definable user scopesUsers benefiting from Conditional Access require Microsoft Entra ID P1; risk-based policies require P2. Business Premium includes P1.
Purview DLP / Insider RiskPolicies covering messages, files, devices, Copilot, or user activityUsers within the protection or monitoring scope require the entitlement for the specific capability; DLP variants differ.
Audit (Premium)Advanced auditing available at tenant levelOne-year retention and premium audit events apply to appropriately licensed users; ten-year retention requires an additional specialised add-on.
Defender Safe Links / Safe AttachmentsPreset protection policies can apply very broadlyThe technical effect triggered by an existing Defender licence does not replace a licensing review of users and mailboxes receiving the protection.
05

Customer Key has explicit Microsoft counting rules

Customer Key adds customer-controlled keys to the encryption already present in Microsoft 365. The required calculation depends on the type of data encryption policy.

MULTI-WORKLOAD

Exchange or Teams: use the larger number

Example: 400 users have an Exchange licence and 360 have a Teams licence. A multi-workload policy requires at least 400 eligible Customer Key entitlements.

SHAREPOINT

Assess SharePoint separately

If 450 users are licensed for SharePoint, Customer Key for SharePoint requires at least 450 eligible assigned entitlements. A multi-workload policy does not automatically protect SharePoint and OneDrive.

EXCHANGE

Review individual mailboxes separately

For an Exchange mailbox encryption policy, the protected user mailbox must maintain an eligible licence persistently.

400 plus 450 does not automatically mean 850 licences

The workload checks are separate, but user populations may overlap. Where the same appropriately licensed users access both workloads and their SKU covers both scenarios, existing entitlements should not be counted twice automatically. Validate actual user assignment, workload access, and policy scope.

Which licences can include Customer Key?

Microsoft identifies, among others, Office 365 E5, Microsoft 365 E5, eligible Microsoft Purview Suite and Frontline variants, and relevant E5 or F5 Information Protection and Governance add-ons. For Business Premium add-ons and standalone SKUs, verify the precise included entitlement against current documentation.

06

A tenant-wide switch is not a universal one-licence rule

Customer Lockbox requires explicit approval before Microsoft support can access customer content in particular cases. The control is enabled tenant-wide and covers services including Exchange Online, SharePoint, OneDrive, Teams, and Windows 365.

INCLUDED

Available only in eligible products

Microsoft identifies options including Office 365 E5, Microsoft 365 E5, eligible Purview Suites, appropriate Frontline suites, and certain Insider Risk add-ons.

DISTINCTION

No published Customer Key-style formula

The official Customer Lockbox description does not provide a counting formula comparable to the Exchange, Teams, or SharePoint rules for Customer Key. Such a rule must not be invented or copied across.

COMPLIANCE

Assess the benefiting population

Even without a published numerical formula, Product Terms and Microsoft's principle that benefiting users require suitable licences still apply. Neither ‘one E5 covers everyone’ nor ‘every Entra account must have E5’ is a defensible blanket statement.

07

Not every add-on suite fits every starting licence

An organisation-wide strategy may require advanced security or compliance for every protected user. Before purchasing, assess whether each group's existing base licence supports the intended add-on.

Existing baseIntended add-onLicensing assessment
Office 365 E1 / Exchange OnlineMicrosoft Purview Suite / Microsoft Defender SuiteE1 or an individual mailbox is not an eligible base for these Enterprise suites. Individual standalone products may follow different prerequisites.
Office 365 E3Microsoft Purview Suite / Microsoft Defender SuiteEnterprise Mobility + Security E3 is additionally required.
Microsoft 365 E3Microsoft Purview Suite / Microsoft Defender SuiteThe required Enterprise foundation is already present.
Microsoft 365 F1 / F3Microsoft Purview Suite FLW / Defender Suite FLWEligible Frontline base; the actual user role must also satisfy the Frontline eligibility conditions.
Office 365 F3Appropriate Frontline add-on suiteEnterprise Mobility + Security E3 (K) is additionally required.
Business Basic / Business StandardPurview or Defender Suite for Business PremiumNot eligible: these specific add-on suites require Business Premium.
Microsoft 365 Business PremiumPurview / Defender Suite for Microsoft 365 Business PremiumThe specific Business Premium base is present; verify included capabilities and the shared 300-seat limit.
Practical example: ‘The employee only needs a mailbox’

Office 365 E1 or Exchange Online may be sufficient for email alone. If that person also benefits from an organisation-wide premium compliance capability, the necessary additional entitlement must exist. The Enterprise Purview Suite cannot simply be added compliantly on top of E1.

08

A shared mailbox is not automatically licence-free

Shared mailboxes require particular care. Their baseline Exchange licensing rules are not interchangeable with requirements for advanced Purview or security capabilities.

BASELINE

Up to 50 GB often needs no mailbox licence

A shared mailbox can generally hold up to 50 GB without its own mailbox licence. People accessing it must have their own licensed Exchange Online mailbox.

EXTENSIONS

More storage, archive, or hold requires rights

Microsoft specifies additional licensing for over 50 GB, particular archive scenarios, or litigation hold, such as Exchange Online Plan 2 or an eligible alternative.

PREMIUM PURVIEW

Some premium capabilities require a licence on the mailbox

Microsoft explicitly states that shared or resource mailboxes may need their own assigned eligible licence for certain E5 or Purview premium capabilities.

CUSTOMER KEY

Apply the documented exception separately

For Customer Key encryption policies, Microsoft documents an exception: shared, group, and public-folder mailboxes do not need an additional separate Customer Key licence when the requirements for user mailboxes are met.

Important

The Customer Key exception must not automatically be applied to eDiscovery, retention, Defender, or other premium features. Always verify the rule for the specific capability.

09

Build a licensing architecture that avoids unexpected gaps

A mixed-licence tenant can still be economical. Every protected user group must, however, hold the right entitlement and an eligible licence combination.

STARTING POINT

180 × Microsoft 365 E3

These users may receive an eligible Enterprise Purview Suite add-on when advanced compliance capabilities are required.

FRONTLINE

60 × Microsoft 365 F3

Frontline workers may receive the appropriate Purview Suite FLW when role eligibility and required capabilities are satisfied.

GAP

120 × Office 365 E1

E1 may be sufficient for email. However, the Enterprise Purview Suite requires Microsoft 365 E3 or Office 365 E3 plus EMS E3, so affected E1 users need a different eligible licensing design.

OUTCOME

Not automatically 360 × E5

The right answer depends on which capabilities apply to which users and workloads. It may combine eligible E5 products, E3 plus add-on suites, and qualifying Frontline combinations.

10

Seven questions before enabling a tenant-wide capability

This sequence connects organisational strategy, technical configuration, and defensible licensing compliance.

  1. 01Which exact capability is being enabled, and which Product Terms apply to the purchased SKU?
  2. 02Does it affect the whole tenant, selected user groups, mailboxes, Teams, or SharePoint sites?
  3. 03Which users, owners, members, administrators, or resources actually benefit?
  4. 04Does a specific counting rule apply, as with Customer Key for Exchange, Teams, or SharePoint?
  5. 05Does every affected person have an eligible base licence and, where necessary, the correct add-on?
  6. 06Are there specific rules for shared mailboxes, Frontline users, guests, agents, or consumption-based charges?
  7. 07Are policy scope, licence assignments, contractual basis, and recurring verification documented?

Tenant-wide impact is an architecture question—not permission for arbitrary licensing.

Not every person automatically needs E5. However, every benefiting person and affected resource needs the appropriate entitlement. A sound decision connects capability, scope, user population, base licence, add-on prerequisites, and organisational strategy.

Verified against current original Microsoft documentation.

The information was verified against official Microsoft sources available on 22 August 2026. Licensing availability, functionality, and product names may change. The exact SKU, agreement, acquisition date, and applicable Product Terms remain authoritative.

Note: This article provides professional orientation and does not replace assessment of an organisation's specific agreement, products, and circumstances. Technical availability, user assignment, partner offer, and contractual usage rights should be evaluated separately.