Microsoft 365

Group-based licensing in Microsoft 365: setup, conflicts and error fixes

Assign Microsoft 365 licences through groups, disable service plans per group, move users off direct assignment and fix CountViolation, MutuallyExclusive and usage location errors.

11 min read
On this page

To set up group-based licensing in Microsoft 365, put users in a security group, mail-enabled security group or Microsoft 365 group, then go to Billing > Licenses in the Microsoft 365 admin center, select Assign licenses, choose the group and the subscription, and turn off any apps you don't want. Members then get the licence automatically and lose it when they leave the group. When something goes wrong, open the product's Errors & issues tab, fix the cause (not enough licences, conflicting or dependent service plans, missing usage location or a duplicate proxy address) and reprocess the affected users.

Who this is for and what you will have

This guide is for Microsoft 365 and Entra ID administrators who still assign licences user by user, or who have group-based licensing in place but keep finding users in an error state. At the end you will have:

  • A group design that maps one group to one licence configuration.
  • Licences assigned to groups in the admin center and with Set-MgGroupLicense, including disabled service plans.
  • A safe sequence for moving users from direct assignment to group assignment.
  • Scripts that list every user with a group licensing error and why.
  • A fix for each documented error type.

Group-based licensing is also the cleanest way to licence users in bulk ahead of a migration, such as a Google Workspace to Microsoft 365 move or a tenant-to-tenant consolidation.

How group-based licensing behaves

Microsoft's documentation describes these rules, and most errors come from forgetting one of them:

  • Supported groups. You can assign licences to security groups, mail-enabled security groups and Microsoft 365 groups. Groups synced from on-premises Active Directory work too.
  • Membership drives the licence. New members get the group's licences and members who leave lose them. Changes are typically effective within minutes, but large groups can take much longer.
  • No nested groups. Only direct members of the licensed group receive licences.
  • Licences combine. A user can hold licences from several groups plus direct assignments. The result is the combination of all of them, and a licence assigned from multiple sources is consumed once.
  • All or nothing per group. If a group carries several products and one of them fails for a user (for example, not enough licences), the other products from that group aren't assigned to that user either.
  • No automatic conflict resolution. When two products conflict, Microsoft Entra ID records an error. The admin decides how to resolve it.
  • Usage location fallback. Users without a usage location inherit the tenant's location when a group assigns the licence. Set the correct value at user creation if you have users in several countries.

Microsoft's Entra documentation for group-based licensing listed the licensing prerequisite as a paid or trial Microsoft Entra ID P1 (or higher) subscription, or a paid or trial edition of Microsoft 365 Business Premium, Office 365 Enterprise E3 or Office 365 A3 (or higher), for every user who benefits from group-based licensing. Check your agreement if you plan to licence users who only hold Business Basic or Standard.

Prerequisites

  • An admin account with at least the Groups Administrator, License Administrator or User Administrator role. Reprocessing through the Graph API requires License Administrator, User Administrator or Directory Writers.
  • Microsoft Graph PowerShell for the scripted steps.
  • A usage location on every user, especially in multi-country tenants.
  • A decision on which apps each population should get. Write it down as a table before you create groups.

A simple design that scales:

GroupProductDisabled service plansMembership
LIC-O365-E3-StandardOffice 365 E3NoneAssigned or dynamic
LIC-O365-E3-NoTeams-PilotOffice 365 E3Microsoft TeamsAssigned
LIC-AddOn-TeamsPhoneTeams Phone StandardNoneAssigned

Keep one product configuration per group. Mixing many products in one group makes the all-or-nothing behaviour harder to troubleshoot.

Step 1: Assign licences to a group in the admin center

  1. Sign in to the Microsoft 365 admin center as at least a License Administrator.
  2. Go to Billing > Licenses.
  3. Select Assign licenses.
  4. In the side panel, search for the group and select it from the list.
  5. Select the subscription that the licences should come from.
  6. To turn individual apps off, select Turn apps and services on or off.
  7. Select Assign licenses.

The admin center can assign licences to a maximum of 20 groups at a time. To remove a group assignment, open the product on the Licenses page, find the group, select the three dots on its row, then Unassign.

Step 2: Assign licences with Microsoft Graph PowerShell

Set-MgGroupLicense adds or removes licences on a group and supports disabled plans per SKU. First find the SKU ID and the service plan IDs you want to disable:

Connect-MgGraph -Scopes 'LicenseAssignment.ReadWrite.All','Group.Read.All','Organization.Read.All'
 
$sku = Get-MgSubscribedSku -All | Where-Object SkuPartNumber -eq 'ENTERPRISEPACK'
$sku.ServicePlans | Select-Object ServicePlanName, ServicePlanId | Sort-Object ServicePlanName

ENTERPRISEPACK is the part number Microsoft's examples show for Office 365 E3; replace it with the part number of your product. Then assign it to the group with the plans you want switched off:

$groupId = (Get-MgGroup -Filter "displayName eq 'LIC-O365-E3-NoTeams-Pilot'").Id
$teamsPlan = ($sku.ServicePlans | Where-Object ServicePlanName -eq 'TEAMS1').ServicePlanId
 
$params = @{
    AddLicenses = @(
        @{
            SkuId         = $sku.SkuId
            DisabledPlans = @($teamsPlan)
        }
    )
    RemoveLicenses = @()
}
 
Set-MgGroupLicense -GroupId $groupId -BodyParameter $params

TEAMS1 is the service plan name Microsoft documents for Microsoft Teams. The same pattern works for any plan in the SKU's ServicePlans list.

To remove a product from a group, pass its SKU ID in RemoveLicenses with an empty AddLicenses array.

Step 3: Move users from direct to group assignment

Users who already have a direct licence keep it when you add them to a licensed group. The same product assigned directly and through a group consumes only one licence, but if you leave the direct assignment in place, users keep that licence when they later leave the group, which defeats the point of group-based licensing. Clean them up in this order:

  1. Add the users to the licensed group.
  2. Wait until the group's processing finishes and confirm the users show the licence as inherited from the group.
  3. Remove the direct assignment only for SKUs that the group also assigns.

Microsoft publishes a script for step 3 in its group-based licensing PowerShell examples. It compares each member's directly assigned SKUs with the group's SKUs and calls Set-MgUserLicense -RemoveLicenses for the overlap. Microsoft's own caution applies: confirm the direct licence doesn't enable more service plans than the inherited one, because PowerShell can't currently tell you which services come from which assignment, and removing a richer direct licence can switch a service off.

The same ordering applies when you move a user between two licensed groups. Add the user to the destination group, confirm the new licence on the user's Licenses page, then remove them from the old group. If you remove first, the user is unlicensed until processing of the new group completes, which can be a long time in a large tenant.

Step 4: Verify

In the admin center, open Billing > Licenses, select the product, and check the group's status. Microsoft documents three values: All licenses assigned, In progress and Errors and issues.

With PowerShell, check the group's processing state:

Get-MgGroup -GroupId $groupId -Property DisplayName, LicenseProcessingState |
    Select-Object DisplayName -ExpandProperty LicenseProcessingState

Wait for ProcessingComplete before you judge the result. Then check how a user got each licence. The licenseAssignmentStates property shows assignedByGroup (null for direct assignments, the group ID for inherited ones), disabledPlans, state and error:

$user = Get-MgUser -UserId 'adele.vance@contoso.com' -Property DisplayName, LicenseAssignmentStates
$user.LicenseAssignmentStates | Format-Table SkuId, AssignedByGroup, State, Error, LastUpdatedDateTime

state can be Active, ActiveWithError, Disabled or Error.

Find every user with a group licensing error

Errors from group-based licensing happen in the background, so nothing pops up when they occur. They are recorded on the user object. In the admin center, select the product and open the Errors & issues tab. For a whole tenant, script it:

Connect-MgGraph -Scopes 'Group.Read.All','User.Read.All'
 
$licensedGroups = Get-MgGroup -All -Property Id, DisplayName, AssignedLicenses |
    Where-Object { $_.AssignedLicenses }
 
$report = foreach ($group in $licensedGroups) {
    $members = Get-MgGroupMemberWithLicenseError -GroupId $group.Id -All
    foreach ($member in $members) {
        $user = Get-MgUser -UserId $member.Id -Property UserPrincipalName, LicenseAssignmentStates
        $user.LicenseAssignmentStates |
            Where-Object { $_.AssignedByGroup -eq $group.Id -and $_.Error -and $_.Error -ne 'None' } |
            ForEach-Object {
                [pscustomobject]@{
                    Group = $group.DisplayName
                    User  = $user.UserPrincipalName
                    SkuId = $_.SkuId
                    State = $_.State
                    Error = $_.Error
                }
            }
    }
}
 
$report | Export-Csv -Path 'C:\Temp\GroupLicenseErrors.csv' -NoTypeInformation

Get-MgGroupMemberWithLicenseError returns the members of a group that have licence errors, and filtering on AssignedByGroup keeps errors from other groups out of each row.

Troubleshooting licence assignment errors

The error property uses a fixed set of values: CountViolation, MutuallyExclusiveViolation, DependencyViolation, ProhibitedInUsageLocationViolation, UniquenessViolation and Other.

CountViolation: not enough licences

There aren't enough available licences for one of the products on the group. Buy more, or free licences held by users or groups that no longer need them. Because of the all-or-nothing rule, this also blocks every other product on the same group for the affected users.

MutuallyExclusiveViolation: conflicting service plans

A product on the group contains a service plan that can't coexist with a plan the user already has from another product. The audit log records "License assignment failed because service plans [...] are mutually exclusive." Microsoft's example is a user with Office 365 E1 assigned directly who is added to a group with Office 365 E3. Fix it by disabling the conflicting plan on one side, or by removing the redundant product from the user.

DependencyViolation: missing dependent plan

A service plan needs another plan, in another product, to stay enabled. This typically appears when a user is removed from a group and the removal would take away a plan that a different licence depends on. The audit message reads "License assignment failed because service plan [...] depends on the service plan(s) [...]". Make sure the required plan stays assigned some other way, or disable the dependent service for the user, then reprocess.

Add-on products have the same constraint on the way in: an add-on can only be assigned to a group that also carries its prerequisite plan. If you want to licence an add-on for a subset of users, create a group that carries the add-on plus the prerequisite product with only the required plan enabled. Those users consume a licence of each, and still consume only one licence of the base product if another group gives them the full version.

ProhibitedInUsageLocationViolation: service not allowed in that location

Some services aren't available in every country. If a user's usage location doesn't allow a product, assignment fails. Correct the usage location if it is wrong, or take the user out of that licensed group.

Proxy address is already being used

In Exchange Online, two recipients can end up with the same proxy address, and licence assignment fails with "Proxy address is already being used". Find the duplicate in Exchange Online PowerShell:

Get-Recipient -Filter "EmailAddresses -eq 'adele.vance@contoso.com'" |
    Format-List DisplayName, RecipientType, EmailAddresses

Remove the address from the wrong object, then reprocess the user.

LicenseAssignmentAttributeConcurrencyException

This usually appears when a user is in more than one group with the same licence. The service retries automatically and no action is needed.

Other

Other errors are usually caused by a failure on another licence assigned by the same group. Check the user's licences and the audit log. Failed group licence operations appear with Activity type "Change user license", Status "failure" and the initiator Microsoft Entra ID Group-Based Licensing.

Reprocess after you fix the cause

Some fixes, such as resolving a dependency, need a manual trigger. In the admin center, go to Billing > Licenses, select the product and the group, select the users and choose Reprocess (up to 20 users at a time). In PowerShell:

Connect-MgGraph -Scopes 'User.ReadWrite.All'
 
Import-Csv 'C:\Temp\GroupLicenseErrors.csv' |
    Select-Object -ExpandProperty User -Unique |
    ForEach-Object { Invoke-MgLicenseUser -UserId $_ }

Deleting a licensed group

You must remove all licences from a group before you can delete it. Removal can fail for users with dependent licences or proxy address conflicts, and those users stay in an error state for every licence from that group until the dependency is resolved and they are reprocessed. Clear errors first, then unassign, then delete.

Checklist

  • Usage location set on every user before they join a licensed group.
  • One licence configuration per group, documented with its disabled plans.
  • No nested groups used for licensing.
  • Licences assigned in the admin center or with Set-MgGroupLicense.
  • Users moved from direct to group assignment in the order add, confirm, remove.
  • Group LicenseProcessingState shows ProcessingComplete.
  • A scheduled report of users with group licensing errors, with each error resolved and the user reprocessed.
  • Licences removed from a group before the group is deleted.

If you are still choosing which suite to assign, the Business Premium vs E3 vs E5 comparison covers what each plan includes after the July 2026 changes.

References

Questions people ask

Does group-based licensing work with nested groups?

No. Microsoft states that group-based licensing doesn't currently support nested groups. If you assign licences to a group that contains other groups, only users who are direct members of the first-level group receive licences.

What happens if a user gets the same licence from two groups?

The user's licence state is the combination of every group and direct assignment, and a licence assigned from multiple sources is consumed only once. Microsoft also documents a transient LicenseAssignmentAttributeConcurrencyException in this situation, which the service retries on its own without admin action.

How do I reprocess a user stuck in a licence error?

In the Microsoft 365 admin center, go to Billing > Licenses, open the product and the group, select the affected users and choose Reprocess, which handles up to 20 users at a time. With Microsoft Graph PowerShell, run Invoke-MgLicenseUser -UserId for each user, which calls the reprocessLicenseAssignment API.

Where did the group licensing page in the Entra admin center go?

Starting September 1, 2024, the Microsoft Entra admin center and the Azure portal no longer support license assignment through their user interfaces. Administrators assign licences to users and groups in the Microsoft 365 admin center instead. The change is limited to the user interface, so the Graph API and Microsoft Graph PowerShell still work.

Microsoft 365 licensingEntra IDMicrosoft 365 admin centerMicrosoft Graph PowerShell
  1. Microsoft 365 suites with and without Teams: licensing options explained

    How Microsoft 365 and Office 365 suites with and without Teams work after the November 2025 reversal and July 2026 prices, when to add Teams Enterprise, and how to check who is licensed for Teams.

    Microsoft 36510 min read
  2. Microsoft Graph PowerShell recipes for user, licence and sign-in reports

    Replace retired MSOnline scripts with Microsoft Graph PowerShell recipes for user inventories, licence counts, unlicensed and inactive users, and recent failed sign-ins.

    Microsoft 36511 min read
  3. Move MSOnline and AzureAD scripts to Microsoft Graph PowerShell

    MSOnline and AzureAD PowerShell are retired. Inventory what still calls them, map each cmdlet to Microsoft Graph PowerShell and fix the patterns that break.

    Microsoft 36511 min read