Microsoft licensing · Module 3
Tenant-wide Microsoft 365 capabilities:
How should they be licensed?
Some Microsoft 365 capabilities are switched on centrally for the whole organisation. That does not mean one licence always covers everyone—or that every user automatically needs the most expensive licence.
The essential distinction
A central setting does not tell you which people must be licensed.
What matters is which capability is used, who benefits from it, and which base or additional licence is required.
- 01Every capability has its own licensing rules
- 02Tenant-wide does not automatically mean E5 for every account
- 03Assess every benefiting user and affected resource
- 04Additional licences need an eligible base licence
Quick explanation · In 30 seconds
Who benefits from which capability?
A tenant is an organisation's shared Microsoft 365 environment. Even when a capability is switched on centrally, you still need to check which users, devices, or data it actually covers.
Per user or device
Conditional Access, Purview policies, and Intune depend on the users or devices that actually benefit.
Per protected service or system
Customer Key applies different counting rules to protected services; protected servers can require separate server licences.
Documented exception
One eligible Copilot licence can unlock particular SharePoint management capabilities tenant-wide, but not every capability.
Consumption or special rule
Microsoft 365 Backup is billed through Azure; selected Teams Premium capabilities follow the meeting organiser.
An add-on is an additional licence. A prerequisite is the required base licence or another condition. Both must match the capability actually being used.
01 · Foundations
What does tenant-wide actually mean?
A tenant-wide capability is enabled or configured centrally for a Microsoft 365 organisation. Its technical reach and the people requiring appropriate licences are separate questions.
Centrally enabled
Customer Lockbox is enabled through organisation settings. Conditional Access and Purview policies are also managed centrally.
Different areas of impact
A capability can affect the entire tenant, be limited to user groups, protect specific mailboxes, or apply to selected SharePoint sites.
Usage rights remain user-specific
Microsoft generally requires an appropriate licence for each user benefiting from the service. Some capabilities additionally apply explicit workload-specific counting rules.
Technically available does not mean compliant
A service can operate tenant-wide even though not every benefiting user is correctly licensed. For Customer Key, insufficient licensing can cause encryption to revert to Microsoft-managed default encryption.
02 · Who benefits?
Licensing is not limited to the administrator
Microsoft provides concrete examples for Purview. The relevant population includes not only the person creating a policy, but also people whose content, activities, or shared resources receive protection or analysis.
- 01Administrators and other users assigned an appropriate Microsoft Purview role.
- 02Users whose Exchange mailbox, OneDrive account, Teams chat, or device is covered by a policy or capability.
- 03Owners and members of a SharePoint site, Microsoft 365 group, or Team where a licensed Purview capability is used.
- 04For Teams DLP, senders whose chat or channel messages are inspected.
- 05For Insider Risk Management, users whose activities are monitored by a relevant policy.
For shared locations, Microsoft explicitly excludes visitors and users with view-only permissions from this particular licensing benefit. The Purview service description says inactive mailboxes do not require a usage licence. Guests, technical identities, and other exceptions must be assessed against the relevant product terms.
03 · Comprehensive capability inventory
Which tenant-wide and centrally managed capabilities exist?
Microsoft organises tenant-related security, compliance, identity, and management capabilities into multiple product families. Distinguish genuine tenant-wide effects from scoped policies and user-, device-, or consumption-based licensing.
Microsoft Purview: compliance and information protection
31 capabilitiesA centrally configured policy does not automatically mean one tenant licence. Evaluate protected users, content, mailboxes, and the exact premium capability.
| Capability | Impact / scope | Licensing and prerequisite |
|---|---|---|
| Audit (Standard) | Scoped users | Verify an eligible baseline licence and the users or data sources actually covered. |
| Audit (Premium) | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Audit: 10-Year Retention | Scoped users | Requires the separate 10-Year Audit Log Retention add-on for covered users. |
| Collection Policies | Entire tenant | The collection policy itself does not require a separate licence; assess underlying capabilities and any pay-as-you-go charges. |
| Communication Compliance | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Compliance Manager | Administration / scope | Follow the documented product-specific exception, applicable SKU, and exact service description. |
| Customer Key | Specific workload | Explicit counting rules apply to Exchange, Teams, or SharePoint licences; the calculation differs by workload. |
| Customer Lockbox | Entire tenant | Check eligible E5, Purview, or explicitly qualified add-ons; Microsoft does not publish a Customer Key-style counting formula. |
| Data Connectors | Scoped users | Each user actually benefiting from this protection requires the appropriate product entitlement. |
| Data Lifecycle Management | Content / policies | Assess the licensing rule separately for the protected users, content, and affected workload. |
| Records Management | Content / policies | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Adaptive Scopes | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Endpoint DLP | Users / endpoints | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| DLP: Cloud Apps im Browser | Scoped users | Follow the documented product-specific exception, applicable SKU, and exact service description. |
| DLP: Cloud Apps auf Netzwerkebene | Scoped users | Documented consumption-based network scenarios additionally require an Azure subscription linked for pay-as-you-go billing. |
| DLP: Microsoft Teams | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| DLP: Exchange, SharePoint und OneDrive | Content / policies | Assess the licensing rule separately for the protected users, content, and affected workload. |
| DLP: Microsoft Graph APIs | Specific workload | Follow the documented product-specific exception, applicable SKU, and exact service description. |
| DLP: Copilot und Copilot Chat | Scoped users | Assess Copilot, Purview, user, agent, and feature-specific prerequisites separately. |
| eDiscovery (Standard) | Content / policies | Verify an eligible baseline licence and the users or data sources actually covered. |
| eDiscovery (Premium) | Content / policies | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Information Barriers | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Sensitivity Labels / Information Protection | Content / policies | Assess the licensing rule separately for the protected users, content, and affected workload. |
| Automatic Labeling | Content / policies | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Content Explorer / Activity Explorer | Administration / scope | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Microsoft Purview Message Encryption | Scoped users | Assess the licensing rule separately for the protected users, content, and affected workload. |
| Advanced Message Encryption | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Double Key Encryption | Content / policies | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Insider Risk Management | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Forensic Evidence | Scoped users | Requires eligible Insider Risk rights plus additional Forensic Evidence capacity. |
| Data Security Posture Management für AI | Scoped users | Assess Copilot, Purview, user, agent, and feature-specific prerequisites separately. |
Microsoft Defender: email, identities, devices, and cloud applications
16 capabilitiesSeveral Defender services are technically enabled tenant-wide. Microsoft states that Defender for Identity currently cannot limit benefits to specific users.
| Capability | Impact / scope | Licensing and prerequisite |
|---|---|---|
| Defender for Business | Entire tenant | Each user actually benefiting from this protection requires the appropriate product entitlement. |
| Defender for Business Servers | Servers / VMs | Separate server licence; requires at least one Business Premium or Defender for Business licence; maximum 60 server licences per customer. |
| Defender for Cloud Apps | Scoped users | Each user actually benefiting from this protection requires the appropriate product entitlement. |
| App Governance | Scoped users | Verify the precise suite, included feature, and users or resources actually benefiting. |
| Defender for Endpoint P1 | Users / endpoints | Each user actually benefiting from this protection requires the appropriate product entitlement. |
| Defender for Endpoint P2 | Users / endpoints | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Defender for Endpoint for Servers | Servers / VMs | A separate licence is required for each protected operating system environment; user licences do not automatically cover servers. |
| Defender for Identity | Entire tenant | User-based licensing; Microsoft explicitly states that benefits currently cannot be limited to specific users. |
| Defender for Office 365 P1 | Scoped users | Each user actually benefiting from this protection requires the appropriate product entitlement. |
| Defender for Office 365 P2 | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Safe Links | Scoped users | Each user actually benefiting from this protection requires the appropriate product entitlement. |
| Safe Attachments | Scoped users | Each user actually benefiting from this protection requires the appropriate product entitlement. |
| Attack Simulation Training | Scoped users | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Defender for IoT: Enterprise IoT | Users / endpoints | One add-on per IoT device; Defender for Endpoint P2 or a product containing P2 is required. |
| Defender Vulnerability Management | Users / endpoints | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Defender XDR / Defender Experts | Entire tenant | Verify the precise suite, included feature, and users or resources actually benefiting. |
Microsoft Entra: access, identities, and governance
16 capabilitiesEntra is managed centrally but distinguishes users, external identities, workload identities, administrator roles, and individual resources.
| Capability | Impact / scope | Licensing and prerequisite |
|---|---|---|
| Conditional Access | Scoped users | Affected users need Entra ID P1 or a qualifying product that contains P1. |
| Risk-based Conditional Access | Scoped users | Affected users need Entra ID P2 or another expressly eligible suite. |
| Entra ID Protection | Identities | Affected users need Entra ID P2 or another expressly eligible suite. |
| Privileged Identity Management | Administration / scope | Affected users need Entra ID P2 or another expressly eligible suite. |
| Access Reviews | Scoped users | Check the Entra ID Governance entitlement and the users covered by the governance scenario. |
| Entitlement Management | Scoped users | Check the Entra ID Governance entitlement and the users covered by the governance scenario. |
| Lifecycle Workflows | Scoped users | Check the Entra ID Governance entitlement and the users covered by the governance scenario. |
| Dynamic Groups / Administrative Units | Scoped users | Affected users need Entra ID P1 or a qualifying product that contains P1. |
| Cross-Tenant Synchronization | External identities | Affected users need Entra ID P1 or a qualifying product that contains P1. |
| Entra External ID | External identities | Follow the documented product-specific exception, applicable SKU, and exact service description. |
| Entra Workload ID | Identities | Follow the documented product-specific exception, applicable SKU, and exact service description. |
| Entra Internet Access | Scoped users | Verify the precise suite, included feature, and users or resources actually benefiting. |
| Entra Private Access | Scoped users | Verify the precise suite, included feature, and users or resources actually benefiting. |
| Entra Verified ID | Identities | Follow the documented product-specific exception, applicable SKU, and exact service description. |
| Entra Domain Services | Resource / consumption | Review Azure-based pay-as-you-go billing, the connected subscription, and the protected resources. |
| Agent Identities / Agent Conditional Access | Agents / identities | Check Agent 365, Entra, user, and underlying product prerequisites for the precise scenario. |
Microsoft Intune: device management and advanced capabilities
12 capabilitiesMicrosoft requires an appropriate licence for every user or device directly or indirectly benefiting from Intune.
| Capability | Impact / scope | Licensing and prerequisite |
|---|---|---|
| Intune Plan 1: MDM / MAM | Users / endpoints | Every user or device directly or indirectly benefiting from Intune needs the appropriate entitlement. |
| Intune Device License | Users / endpoints | Check the eligible device licence or the appropriate entitlement for the users and endpoints covered. |
| Device Compliance / Conditional Access | Scoped users | Affected users need Entra ID P1 or a qualifying product that contains P1. |
| Intune Plan 2 | Scoped users | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Remote Help | Scoped users | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Advanced Analytics | Users / endpoints | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Endpoint Privilege Management | Scoped users | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Microsoft Cloud PKI | Users / endpoints | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Enterprise Application Management | Users / endpoints | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Specialty Device Management | Users / endpoints | Check the eligible device licence or the appropriate entitlement for the users and endpoints covered. |
| Microsoft Tunnel for MAM | Users / endpoints | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Firmware-over-the-Air Updates | Users / endpoints | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
Microsoft Priva: tenant-wide privacy risk management
2 capabilitiesMicrosoft Priva identifies risks when handling personal data. Privacy Risk Management is a tenant-wide add-on; check the eligible base licence and every protected or benefiting person.
| Capability | Impact / scope | Licensing and prerequisite |
|---|---|---|
| Priva Privacy Risk Management | Entire tenant | Tenant-wide privacy add-on: verify the eligible base licence and every benefiting user. Microsoft does not list F1/F3 frontline plans as eligible base licences. |
| Oversharing / Data Transfer / Data Hoarding | Scoped users | License every user intended to benefit from or receive protection through the tenant-wide privacy service. |
SharePoint, Teams, agents, and consumption-based services
10 capabilitiesThese services use particularly different models: Copilot-based enablement, meeting-organiser rights, agent prerequisites, and Azure consumption.
| Capability | Impact / scope | Licensing and prerequisite |
|---|---|---|
| SharePoint Advanced Management via Copilot | Entire tenant | A documented exception: at least one assigned eligible Copilot licence can unlock included SAM capabilities for SharePoint administrators across the tenant. |
| SharePoint Advanced Management Plan 1 | Entire tenant | Capabilities such as Restricted Site Creation by Apps still require SAM Plan 1; Copilot does not unlock every SAM feature. |
| SAM: Sensitivity Labels | Content / policies | An eligible premium licence is required for the users, content, or resources benefiting from the capability. |
| Teams Premium: organizer-based features | Meeting organiser | A licensed organiser can share particular meeting capabilities with attendees during that meeting; not every attendee automatically needs Premium. |
| Teams Premium: personal user features | Scoped users | An eligible base licence and the appropriate feature-specific add-on or suite are required. |
| Microsoft 365 Backup | Resource / consumption | Review Azure-based pay-as-you-go billing, the connected subscription, and the protected resources. |
| Microsoft 365 Archive | Resource / consumption | Review Azure-based pay-as-you-go billing, the connected subscription, and the protected resources. |
| Microsoft Purview Pay-as-you-go | Resource / consumption | Review Azure-based pay-as-you-go billing, the connected subscription, and the protected resources. |
| Microsoft Agent 365 | Agents / identities | Microsoft lists prerequisites including Microsoft 365 E5/A5/Business Premium or qualifying Defender-and-Purview combinations; verify the exact SKU and agreement. |
| Copilot Studio Agents / Copilot Credits | Agents / identities | Assess Copilot, Purview, user, agent, and feature-specific prerequisites separately. |
The inventory covers Microsoft's documented product families and their main centrally managed capabilities. Not every administrative setting is a separate licensable product. The actual SKU, Product Terms, agreement and acquisition date, technical scope, and benefiting users or resources remain authoritative.
04 · Capability comparison
Same tenant, different licensing rules
A shared activation surface does not imply identical requirements. The protected user population and the specific product prerequisites are what matter.
| Capability | Technical effect | Licensing approach |
|---|---|---|
| Customer Key: multiple workloads | Tenant-level encryption policy across several Microsoft 365 services | At least as many eligible Customer Key licences as users assigned Exchange or Teams licences, whichever number is greater. |
| Customer Key: Exchange | Encryption policy assigned to individual Exchange mailboxes | Each protected user mailbox needs a persistent eligible licence; Microsoft documents an exception for certain non-user-specific mailboxes. |
| Customer Key: SharePoint / OneDrive | Tenant-level encryption covering SharePoint and OneDrive | At least as many eligible Customer Key licences as users assigned SharePoint licences. |
| Customer Lockbox | Central approval process for Microsoft support access to tenant content | Assess appropriate Lockbox rights for benefiting scenarios. Microsoft does not publish the same numerical counting formula used for Customer Key. |
| Conditional Access | Central access policies with definable user scopes | Users benefiting from Conditional Access require Microsoft Entra ID P1; risk-based policies require P2. Business Premium includes P1. |
| Purview DLP / Insider Risk | Policies covering messages, files, devices, Copilot, or user activity | Users within the protection or monitoring scope require the entitlement for the specific capability; DLP variants differ. |
| Audit (Premium) | Advanced auditing available at tenant level | One-year retention and premium audit events apply to appropriately licensed users; ten-year retention requires an additional specialised add-on. |
| Defender Safe Links / Safe Attachments | Preset protection policies can apply very broadly | The technical effect triggered by an existing Defender licence does not replace a licensing review of users and mailboxes receiving the protection. |
05 · Customer Key
Customer Key has explicit Microsoft counting rules
Customer Key adds customer-controlled keys to the encryption already present in Microsoft 365. The required calculation depends on the type of data encryption policy.
Exchange or Teams: use the larger number
Example: 400 users have an Exchange licence and 360 have a Teams licence. A multi-workload policy requires at least 400 eligible Customer Key entitlements.
Assess SharePoint separately
If 450 users are licensed for SharePoint, Customer Key for SharePoint requires at least 450 eligible assigned entitlements. A multi-workload policy does not automatically protect SharePoint and OneDrive.
Review individual mailboxes separately
For an Exchange mailbox encryption policy, the protected user mailbox must maintain an eligible licence persistently.
The workload checks are separate, but user populations may overlap. Where the same appropriately licensed users access both workloads and their SKU covers both scenarios, existing entitlements should not be counted twice automatically. Validate actual user assignment, workload access, and policy scope.
Microsoft identifies, among others, Office 365 E5, Microsoft 365 E5, eligible Microsoft Purview Suite and Frontline variants, and relevant E5 or F5 Information Protection and Governance add-ons. For Business Premium add-ons and standalone SKUs, verify the precise included entitlement against current documentation.
06 · Customer Lockbox
A tenant-wide switch is not a universal one-licence rule
Customer Lockbox requires explicit approval before Microsoft support can access customer content in particular cases. The control is enabled tenant-wide and covers services including Exchange Online, SharePoint, OneDrive, Teams, and Windows 365.
Available only in eligible products
Microsoft identifies options including Office 365 E5, Microsoft 365 E5, eligible Purview Suites, appropriate Frontline suites, and certain Insider Risk add-ons.
No published Customer Key-style formula
The official Customer Lockbox description does not provide a counting formula comparable to the Exchange, Teams, or SharePoint rules for Customer Key. Such a rule must not be invented or copied across.
Assess the benefiting population
Even without a published numerical formula, Product Terms and Microsoft's principle that benefiting users require suitable licences still apply. Neither ‘one E5 covers everyone’ nor ‘every Entra account must have E5’ is a defensible blanket statement.
07 · Base licences and add-ons
Not every add-on suite fits every starting licence
An organisation-wide strategy may require advanced security or compliance for every protected user. Before purchasing, assess whether each group's existing base licence supports the intended add-on.
| Existing base | Intended add-on | Licensing assessment |
|---|---|---|
| Office 365 E1 / Exchange Online | Microsoft Purview Suite / Microsoft Defender Suite | E1 or an individual mailbox is not an eligible base for these Enterprise suites. Individual standalone products may follow different prerequisites. |
| Office 365 E3 | Microsoft Purview Suite / Microsoft Defender Suite | Enterprise Mobility + Security E3 is additionally required. |
| Microsoft 365 E3 | Microsoft Purview Suite / Microsoft Defender Suite | The required Enterprise foundation is already present. |
| Microsoft 365 F1 / F3 | Microsoft Purview Suite FLW / Defender Suite FLW | Eligible Frontline base; the actual user role must also satisfy the Frontline eligibility conditions. |
| Office 365 F3 | Appropriate Frontline add-on suite | Enterprise Mobility + Security E3 (K) is additionally required. |
| Business Basic / Business Standard | Purview or Defender Suite for Business Premium | Not eligible: these specific add-on suites require Business Premium. |
| Microsoft 365 Business Premium | Purview / Defender Suite for Microsoft 365 Business Premium | The specific Business Premium base is present; verify included capabilities and the shared 300-seat limit. |
Office 365 E1 or Exchange Online may be sufficient for email alone. If that person also benefits from an organisation-wide premium compliance capability, the necessary additional entitlement must exist. The Enterprise Purview Suite cannot simply be added compliantly on top of E1.
09 · Organisation-wide strategy
Build a licensing architecture that avoids unexpected gaps
A mixed-licence tenant can still be economical. Every protected user group must, however, hold the right entitlement and an eligible licence combination.
180 × Microsoft 365 E3
These users may receive an eligible Enterprise Purview Suite add-on when advanced compliance capabilities are required.
60 × Microsoft 365 F3
Frontline workers may receive the appropriate Purview Suite FLW when role eligibility and required capabilities are satisfied.
120 × Office 365 E1
E1 may be sufficient for email. However, the Enterprise Purview Suite requires Microsoft 365 E3 or Office 365 E3 plus EMS E3, so affected E1 users need a different eligible licensing design.
Not automatically 360 × E5
The right answer depends on which capabilities apply to which users and workloads. It may combine eligible E5 products, E3 plus add-on suites, and qualifying Frontline combinations.
10 · Verification checklist
Seven questions before enabling a tenant-wide capability
This sequence connects organisational strategy, technical configuration, and defensible licensing compliance.
- 01Which exact capability is being enabled, and which Product Terms apply to the purchased SKU?
- 02Does it affect the whole tenant, selected user groups, mailboxes, Teams, or SharePoint sites?
- 03Which users, owners, members, administrators, or resources actually benefit?
- 04Does a specific counting rule apply, as with Customer Key for Exchange, Teams, or SharePoint?
- 05Does every affected person have an eligible base licence and, where necessary, the correct add-on?
- 06Are there specific rules for shared mailboxes, Frontline users, guests, agents, or consumption-based charges?
- 07Are policy scope, licence assignments, contractual basis, and recurring verification documented?
Key takeaway
Tenant-wide impact is an architecture question—not permission for arbitrary licensing.
Not every person automatically needs E5. However, every benefiting person and affected resource needs the appropriate entitlement. A sound decision connects capability, scope, user population, base licence, add-on prerequisites, and organisational strategy.
Primary and official sources
Verified against current original Microsoft documentation.
The information was verified against official Microsoft sources available on 22 August 2026. Licensing availability, functionality, and product names may change. The exact SKU, agreement, acquisition date, and applicable Product Terms remain authoritative.
- 01Microsoft Learn — Microsoft 365 tenant-level security and compliance licensing↗Open source
- 02Microsoft Learn — Microsoft Purview service description and user licensing↗Open source
- 03Microsoft Learn — Customer Key and workload-specific encryption↗Open source
- 04Microsoft Learn — Customer Lockbox requests and tenant-wide activation↗Open source
- 05Microsoft Learn — Microsoft Entra licensing and Conditional Access↗Open source
- 06Microsoft Learn — Microsoft Defender tenant-level service description↗Open source
- 07Microsoft Learn — Microsoft Entra tenant-level service description↗Open source
- 08Microsoft Learn — Microsoft Intune licensing↗Open source
- 09Microsoft Learn — Microsoft Intune advanced capabilities↗Open source
- 10Microsoft Learn — Microsoft Priva tenant-level service description↗Open source
- 11Microsoft Learn — SharePoint Advanced Management prerequisites↗Open source
- 12Microsoft Learn — SharePoint Advanced Management features in Copilot licenses↗Open source
- 13Microsoft Learn — Microsoft Teams Premium licensing↗Open source
- 14Microsoft Learn — Microsoft 365 pay-as-you-go services↗Open source
- 15Microsoft Learn — Microsoft Purview billing models↗Open source
- 16Microsoft Learn — Microsoft Agent 365 licensing prerequisites↗Open source
- 17Microsoft — Subscription suites and add-on prerequisites↗Open source
- 18Microsoft Learn — Shared mailboxes and advanced feature licensing↗Open source
- 19Microsoft Learn — Microsoft Defender for Office 365 service description↗Open source
- 20Microsoft Learn — Safe Links and built-in tenant-wide protection↗Open source
- 21Microsoft — Product Terms↗Open source
Note: This article provides professional orientation and does not replace assessment of an organisation's specific agreement, products, and circumstances. Technical availability, user assignment, partner offer, and contractual usage rights should be evaluated separately.